d6bcae54c8
fix(xdp): two RST-challenge bugs found by live kernel testing
...
Found on real kernel 5.15 (netns+veth, challenge enabled):
1. truncated IP: after bpf_xdp_adjust_tail the IPv4 tot_len / IPv6
payload_len still claimed the original SYN size — peer silently
dropped the malformed SYN-ACK, challenge never seen
2. endianness: marker/bad_ack written as raw host-order halfwords into
network-order tcpw[] — client echoed swap16halves(bad_ack) in its
RST.seq, verification always failed (CHAL_FAILED == CHAL_SENT)
Post-fix e2e: SYN -> bad-ACK SYN-ACK (XDP_TX) -> client RST ->
verified -> retry connects transparently; counters SENT=1 VERIFIED=1
FAILED=0
2026-08-24 13:06:10 +02:00
8b35ac693c
fix: universal default protected port range (was Minecraft 25565-25570)
...
Verified on real kernel 5.15.0-186 (VDS, netns+veth, generic XDP):
- verifier accepts program, all maps created (BTF ok)
- legit TCP passes end-to-end; conntrack entry cleaned on close
- stats counters increment correctly; prefix_stats /24 key populated
- LPM blacklist ban blocks traffic with retransmit drops
2026-08-24 11:18:57 +02:00
aa787a558c
feat: traffic intel hot path, SYN RST-challenge, XDP environment diagnostics
...
Traffic Intel (was dead code, now wired):
- TrafficHook in listener accept path: cps/pps windows -> AttackDetector
- auto-ban IPs below reputation threshold under attack ([detect.autoban])
- AlertDispatcher: webhook on attack state transition only (dedup), metrics
AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url
XDP SYN RST-challenge (Oubliette pattern, off by default):
- G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX,
spoofed sources stay silent, live clients answer RST with secret echo ->
challenge_verified (LRU, sliding TTL); brute-force of marker impossible
- maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic
in xdp/core/syn_challenge.h (221 lines)
XDP diagnostics (src/xdp/diagnostics.rs):
- EnvironmentReport: kernel version/BTF/driver->AttachMode verdict,
fail-fast before load on unsupported kernels; wired into CLI
- SystemProbe trait for kernel-less testing
fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed
cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
2026-08-24 10:11:10 +02:00
40bfe956e2
feat: subnet-level attack detection (prefix_stats)
...
- XDP: prefix_stats LRU map, per-/24 (v4) and /64 (v6) SYN/packet counters,
incremented post-blacklist/throttle (xdp/core/prefix_stats.h)
- userspace: SubnetDetector escalation ladder Monitor->StrictLimit->Challenge->Block
with spoof-gate (Block requires >= min_unique_sources, CGNAT-safe)
- config: [detect.prefix] section (enabled=false by default)
- fallback without XDP: engine SubnetTracker aggregates connections per-prefix
- fix: PrefixStatsVal::from_bytes for xdp feature build; prefix_len 24 vs 64
cargo build/clippy(-D warnings, all features)/test green: 83 tests
2026-08-24 09:47:21 +02:00
15f474486a
feat!: universal redesign — drop Minecraft stack, single-crate architecture
...
- remove Java plugins (velocity/paper), dashboard, all MC-specific code
(handshake, death_code, varint, hostname-HMAC); available in history pre-v0.2
- merge crates/* into one package with src/bin/{rampart,rampart-manager,rampart-cli}
- ProtocolHandler trait + registry (no implementations yet), universal PoW kept
- XDP: universal L3/L4 filter (xdp/core/) + pluggable hook API (xdp/hooks/),
fix IPv6 saddr bug; clang build verified
- docs: bilingual knowledge base (docs/kb/: attacks x4, defense-levels,
practice x3), rewrite README/architecture for universal concept
- TODO.md v4.0: <=300-line module limit, competitor benchmark section (ref/)
- deploy/CI/docs cleanup: no MC references, new binary names
cargo build/clippy(-D warnings)/test green (55 tests)
2026-08-24 01:50:22 +02:00
269daa071f
v0.3: 6-layer architecture complete
...
Layers:
Layer 1: XDP/eBPF — TCP state machine, SYN throttle, blacklist, ringbuf
Layer 2: PoW Challenge — SHA-256 hashcash, dynamic difficulty, constant-time verify
Layer 3: Rust Core — HMAC handshake, rate limit, death code (existing)
Layer 4: Velocity — Physics check, CAPTCHA, protocol verification
Layer 5: Paper — Heartbeat, auto-registration (existing)
Layer 6: Traffic Intel — EWMA, 168h profiling, reputation, alerts
Infra: XDP→Prometheus metrics, ClickHouse + Grafana dashboard, Docker Compose
Testing: 100-IP DDoS simulation, MHDDoS ref analysis, load test report
Fixes: VarInt sign extension UB, pure ACK deadlock, RST/FIN cleanup
Ref: MHDDoS, Sonar, LimboFilter, AtomGuard, Infrarust, MC-XDP-eBPF, PowGo
2026-07-21 15:47:36 +02:00