Traffic Intel (was dead code, now wired): - TrafficHook in listener accept path: cps/pps windows -> AttackDetector - auto-ban IPs below reputation threshold under attack ([detect.autoban]) - AlertDispatcher: webhook on attack state transition only (dedup), metrics AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url XDP SYN RST-challenge (Oubliette pattern, off by default): - G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX, spoofed sources stay silent, live clients answer RST with secret echo -> challenge_verified (LRU, sliding TTL); brute-force of marker impossible - maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic in xdp/core/syn_challenge.h (221 lines) XDP diagnostics (src/xdp/diagnostics.rs): - EnvironmentReport: kernel version/BTF/driver->AttachMode verdict, fail-fast before load on unsupported kernels; wired into CLI - SystemProbe trait for kernel-less testing fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
29 lines
1.3 KiB
C
29 lines
1.3 KiB
C
#ifndef RAMPART_STATS_H
|
|
#define RAMPART_STATS_H
|
|
|
|
#include "common.h"
|
|
#include "maps.h"
|
|
|
|
// ── Per-CPU stat increment ──
|
|
static __always_inline void inc_stat(__u32 idx)
|
|
{
|
|
__u64 *val = bpf_map_lookup_elem(&stats_map, &idx);
|
|
if (val)
|
|
__sync_fetch_and_add(val, 1);
|
|
}
|
|
|
|
// ── Convenience wrappers ──
|
|
static __always_inline void inc_total(void) { inc_stat(STAT_TOTAL); }
|
|
static __always_inline void inc_tcp(void) { inc_stat(STAT_TCP); }
|
|
static __always_inline void inc_udp(void) { inc_stat(STAT_UDP); }
|
|
static __always_inline void inc_whitelist(void) { inc_stat(STAT_WHITELIST); }
|
|
static __always_inline void inc_blacklist(void) { inc_stat(STAT_BLACKLIST); }
|
|
static __always_inline void inc_syn_throttle(void) { inc_stat(STAT_SYN_THROTTLE); }
|
|
static __always_inline void inc_rate_limit(void) { inc_stat(STAT_RATE_LIMIT); }
|
|
static __always_inline void inc_chal_sent(void) { inc_stat(STAT_CHALLENGE_SENT); }
|
|
static __always_inline void inc_chal_verified(void) { inc_stat(STAT_CHALLENGE_VERIFIED); }
|
|
static __always_inline void inc_chal_failed(void) { inc_stat(STAT_CHALLENGE_FAILED); }
|
|
static __always_inline void inc_pass(void) { inc_stat(STAT_PASS); }
|
|
static __always_inline void inc_drop(void) { inc_stat(STAT_DROP); }
|
|
|
|
#endif /* RAMPART_STATS_H */
|