v0.3: 6-layer architecture complete

Layers:
  Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
  Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
  Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
  Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
  Layer 5: Paper — Heartbeat, auto-registration (existing)
  Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts

Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
This commit is contained in:
loki5512344 2026-07-21 15:47:36 +02:00
parent 78fc6e00c7
commit 269daa071f
Signed by: boba
GPG key ID: 253067914055423B
66 changed files with 4529 additions and 1003 deletions

73
deploy/test/mclient.py Normal file
View file

@ -0,0 +1,73 @@
#!/usr/bin/env python3
"""Minecraft handshake client for testing Rampart."""
import argparse
import socket
import struct
import time
def pack_varint(value):
buf = []
while True:
byte = value & 0x7F
value >>= 7
if value:
byte |= 0x80
buf.append(byte)
if not value:
break
return bytes(buf)
def make_handshake(host, port, protocol=767):
packet = bytearray()
packet.extend(pack_varint(protocol))
packet.extend(pack_varint(len(host)))
packet.extend(host.encode())
packet.extend(struct.pack(">H", port))
packet.extend(pack_varint(2))
length = pack_varint(len(packet))
return length + bytes(packet)
def main():
parser = argparse.ArgumentParser()
parser.add_argument("--target", default="localhost:25565")
parser.add_argument("--username", default="test_bot")
args = parser.parse_args()
host, port_str = args.target.split(":")
port = int(port_str)
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.settimeout(10)
sock.connect((host, port))
sock.sendall(make_handshake(host, port))
data = sock.recv(4096)
if data:
print(f"Got response: {data.hex()}")
# If PoW challenge -> receive challenge, solve, send nonce
if b"challenge" in data:
print("PoW challenge received")
challenge = data.decode().strip()
for nonce in range(1000000):
import hashlib
h = hashlib.sha256(f"{challenge}{nonce}".encode()).hexdigest()
if h.startswith("0000"):
sock.sendall(str(nonce).encode())
resp = sock.recv(4096)
print(f"PoW ok, handshake: {resp.hex()}")
break
else:
print(f"Handshake response: {data.hex()}")
else:
print("No response (blocked)")
sock.close()
if __name__ == "__main__":
main()