Traffic Intel (was dead code, now wired): - TrafficHook in listener accept path: cps/pps windows -> AttackDetector - auto-ban IPs below reputation threshold under attack ([detect.autoban]) - AlertDispatcher: webhook on attack state transition only (dedup), metrics AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url XDP SYN RST-challenge (Oubliette pattern, off by default): - G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX, spoofed sources stay silent, live clients answer RST with secret echo -> challenge_verified (LRU, sliding TTL); brute-force of marker impossible - maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic in xdp/core/syn_challenge.h (221 lines) XDP diagnostics (src/xdp/diagnostics.rs): - EnvironmentReport: kernel version/BTF/driver->AttachMode verdict, fail-fast before load on unsupported kernels; wired into CLI - SystemProbe trait for kernel-less testing fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
93 lines
3 KiB
C
93 lines
3 KiB
C
#ifndef RAMPART_MAPS_H
|
|
#define RAMPART_MAPS_H
|
|
|
|
// 🔗 Blacklist (LPM_TRIE for CIDR support)
|
|
// Cleared by Rust userspace or per-entry expiry via ringbuf
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LPM_TRIE);
|
|
__uint(max_entries, 100000);
|
|
__type(key, struct lpm_key);
|
|
__type(value, __u64); // ban expiry (ktime_ns)
|
|
__uint(map_flags, BPF_F_NO_PREALLOC);
|
|
} blacklist_map SEC(".maps");
|
|
|
|
// 🔗 Whitelist (LPM_TRIE for CIDR) — checked before any filter
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LPM_TRIE);
|
|
__uint(max_entries, 1000);
|
|
__type(key, struct lpm_key);
|
|
__type(value, __u8);
|
|
__uint(map_flags, BPF_F_NO_PREALLOC);
|
|
} whitelist_map SEC(".maps");
|
|
|
|
// 🔗 Connection tracking (SYN_RECEIVED → ESTABLISHED)
|
|
// LRU — автоматическое вытеснение старых записей
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LRU_HASH);
|
|
__uint(max_entries, 16384);
|
|
__type(key, struct flow_key);
|
|
__type(value, struct conntrack_entry);
|
|
} conntrack_map SEC(".maps");
|
|
|
|
// 🔗 SYN throttle per-source-IP (LRU)
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LRU_HASH);
|
|
__uint(max_entries, 65535);
|
|
__type(key, __u32); // src_ip
|
|
__type(value, struct throttle_entry);
|
|
} connection_throttle SEC(".maps");
|
|
|
|
// 🔗 UDP rate limit per-source-IP (LRU) — policy from config.h
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LRU_HASH);
|
|
__uint(max_entries, 65535);
|
|
__type(key, __u32); // src_ip
|
|
__type(value, struct throttle_entry);
|
|
} udp_rate_limit SEC(".maps");
|
|
|
|
// ── RST-challenge pending state (challenge reflected, awaiting proof) ──
|
|
struct challenge_pending {
|
|
__u64 sent_at; // ktime_ns of the reflected SYN-ACK
|
|
__u32 marker; // our ISN (client may echo it as ack)
|
|
__u32 bad_ack; // bogus ack sent (live client echoes it as RST seq)
|
|
};
|
|
|
|
// 🔗 RST-challenge: verified sources (liveness proven) — sliding TTL via
|
|
// last_seen, LRU eviction as the hard cap
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LRU_HASH);
|
|
__uint(max_entries, 65536);
|
|
__type(key, __u32); // src_ip
|
|
__type(value, __u64); // last_seen (ktime_ns)
|
|
} challenge_verified SEC(".maps");
|
|
|
|
// 🔗 RST-challenge: outstanding challenges keyed by flow 4-tuple
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_LRU_HASH);
|
|
__uint(max_entries, 16384);
|
|
__type(key, struct flow_key);
|
|
__type(value, struct challenge_pending);
|
|
} challenge_pending SEC(".maps");
|
|
|
|
// 🔗 Statistics (per-CPU, атомарные инкременты)
|
|
#define STAT_TOTAL 0
|
|
#define STAT_TCP 1
|
|
#define STAT_WHITELIST 2
|
|
#define STAT_BLACKLIST 3
|
|
#define STAT_SYN_THROTTLE 4
|
|
#define STAT_PASS 5
|
|
#define STAT_DROP 6
|
|
#define STAT_UDP 7
|
|
#define STAT_RATE_LIMIT 8
|
|
#define STAT_CHALLENGE_SENT 9
|
|
#define STAT_CHALLENGE_VERIFIED 10
|
|
#define STAT_CHALLENGE_FAILED 11
|
|
|
|
struct {
|
|
__uint(type, BPF_MAP_TYPE_PERCPU_ARRAY);
|
|
__uint(max_entries, 16);
|
|
__type(key, __u32);
|
|
__type(value, __u64);
|
|
} stats_map SEC(".maps");
|
|
|
|
#endif /* RAMPART_MAPS_H */
|