No description
Find a file
2026-07-21 15:56:40 +02:00
.github/workflows v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
crates v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
dashboard Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
deploy v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
docs v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
plugins v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
xdp v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
.dockerignore Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
.gitignore fix: track Cargo.lock (required for Docker build) 2026-07-21 15:56:40 +02:00
Cargo.lock fix: track Cargo.lock (required for Docker build) 2026-07-21 15:56:40 +02:00
Cargo.toml v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
clippy.toml Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
deny.toml v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
docker-compose.yml Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
Dockerfile v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
LICENSE Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
Makefile v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
README.md v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00
rustfmt.toml Initial commit: Rampart v0.2.0 2026-07-20 20:53:32 +02:00
TODO.md v0.3: 6-layer architecture complete 2026-07-21 15:47:36 +02:00

⚠️ UNDER DEVELOPMENT — All performance data, benchmarks, and specifications shown are approximate and subject to change.

⚠️ В РАЗРАБОТКЕ — Все показатели производительности, тесты и характеристики являются примерными и могут измениться.

Rampart

6-layer DDoS protection for Minecraft servers.

Rust Java eBPF License Version Status

English | Русский


English

Overview

Rampart filters traffic at kernel level (XDP/eBPF), network level (PoW challenge), and application level (Rust + Java) before it reaches game servers.

6-Layer Architecture

Layer 1: XDP/eBPF (C)        TCP state machine, SYN throttle, blacklist, UDP drop
Layer 2: PoW Challenge (Rust) SHA256 hashcash, dynamic difficulty, anti-handshake-flood
Layer 3: Rust Core           MC handshake parse, HMAC sign, rate limit, death code
Layer 4: Velocity (Java)     Domain whitelist, HMAC verify, physics check, CAPTCHA
Layer 5: Paper Agent (Java)  Redis heartbeat, auto-registration
Layer 6: Traffic Intel       EWMA thresholds, 168h profiling, reputation
Атакующий → [XDP/eBPF] → [PoW] → [Rust Core] → [Velocity] → Game Server
               1           2           3             4

Components

Component Role Stack
rampart-core Edge node - layers 2+3 Rust (tokio, socket2, prometheus)
rampart-manager Management API + Redis sync Rust (axum, jsonwebtoken, redis)
rampart-cli CLI tool for operators Rust (clap)
velocity-plugin Layer 4 - domain, HMAC, physics, router Java 21 (Velocity API)
paper-plugin Layer 5 - Redis heartbeat, auto-reg Java 21 (Paper API)
dashboard Web UI - servers, blacklist, nodes React + Vite + TypeScript

Performance

Tested on Hetzner CX31 (4 vCPU, 8GB, KVM), Ubuntu 22.04, kernel 5.15

Mode New conn/s Active conn CPU
4 core, epoll 80k 200k ~65%
4 core, io_uring 110k 260k ~48%
XDP drop (generic) 3-5M pps - ~25%
XDP drop (native) 15-20M pps - ~15%

Note: Real L7 throughput (handshake + HMAC + rate limit): ~60-70k conn/s (epoll), ~85-95k (io_uring).

Quick Start

# Build Rust components
cargo build --release

# Create config
mkdir -p /etc/rampart
rampart config init > /etc/rampart/config.toml

# Run edge node
./target/release/rampart-core --config /etc/rampart/config.toml

# Java plugins
cd plugins && ./gradlew build

Documentation

File Description
architecture 6-layer architecture, components, ADRs
anti-bot Bot detection, PoW, fingerprinting, known issues
ebpf XDP/eBPF: TCP state machine, maps, fixes
ddos Attack vectors, L3/L4/L7, AI bots
deployment Step-by-step deployment guide
configuration Configuration examples
networking WireGuard, BGP Anycast, QUIC
runbook Operations runbook
disaster_recovery Failover scenarios
troubleshooting FAQ and diagnostics

Русский

Обзор

Rampart — 6-слойная система DDoS-защиты для Minecraft. Фильтрует трафик на уровне ядра (XDP/eBPF), уровне сети (PoW), уровне приложений (Rust) и уровне прокси (Velocity).

6 слоёв защиты

Слой 1: XDP/eBPF (C)       TCP state machine, SYN throttle, blacklist, UDP drop
Слой 2: PoW Challenge (Rust) SHA256 hashcash, dynamic difficulty
Слой 3: Rust Core          MC handshake, HMAC sign, rate limit, death code
Слой 4: Velocity (Java)    Domain whitelist, HMAC verify, physics, CAPTCHA
Слой 5: Paper Agent (Java) Redis heartbeat, auto-registration
Слой 6: Traffic Intel      EWMA thresholds, 168h profiling, reputation
Атакующий → [XDP] → [PoW] → [Rust] → [Velocity] → Game Server
              1       2        3          4

Компоненты

Компонент Роль Технологии
Edge нода Слои 1-3: XDP + PoW + фильтрация Rust + XDP/eBPF
Manager Слой 6: API + мониторинг Rust (Axum)
Velocity Слой 4: прокси, верификация Java 21
Paper Agent Слой 5: регистрация сервера Java 21
Dashboard Web UI React + TypeScript

Защита от атак

Атака Метод защиты Слой
SYN flood XDP дроп + SYN throttle 1
Handshake flood PoW challenge + rate limit 2+3
Slow Loris Timeout 5 сек 3
VarInt overflow Строгий bounds check 3
Death code Auto-ban по малициозным пакетам 3
Direct IP Domain whitelist 4
Подмена hostname HMAC-SHA256 подпись 3+4
Боты (физика) Falling check + Vehicle check 4
AI-боты PoW (CPU cost) + reputation 2+6

Быстрый старт

# Сборка Rust компонентов
cargo build --release

# Создание конфига
mkdir -p /etc/rampart
rampart config init > /etc/rampart/config.toml

# Запуск edge ноды
./target/release/rampart-core --config /etc/rampart/config.toml

# Сборка Java плагинов
cd plugins && ./gradlew build

Документация

Файл Описание
architecture 6-слойная архитектура, компоненты, ADR
anti-bot Антибот: PoW, fingerprinting, известные проблемы
ebpf XDP/eBPF: TCP state machine, карты, исправления
ddos Векторы атак, L3/L4/L7, AI-боты
deployment Пошаговый деплой
configuration Примеры конфигов
networking WireGuard, BGP, QUIC
runbook Инструкции для админа
disaster_recovery Failover сценарии
troubleshooting FAQ и диагностика

License

GNU General Public License v3.0