2021-03-02 11:09:29 +05:30
|
|
|
/*
|
|
|
|
* mCaptcha - A proof of work based DoS protection system
|
|
|
|
* Copyright © 2021 Aravinth Manivannan <realravinth@batsense.net>
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU Affero General Public License as
|
|
|
|
* published by the Free Software Foundation, either version 3 of the
|
|
|
|
* License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU Affero General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
//! MCaptcha actor module that manages defense levels
|
|
|
|
//!
|
|
|
|
//! ## Usage:
|
|
|
|
//! ```rust
|
2021-03-05 21:52:41 +05:30
|
|
|
//! use m_captcha::{message::Visitor, MCaptchaBuilder, cache::HashCache, LevelBuilder, DefenseBuilder};
|
2021-03-02 11:09:29 +05:30
|
|
|
//! // traits from actix needs to be in scope for starting actor
|
|
|
|
//! use actix::prelude::*;
|
|
|
|
//!
|
|
|
|
//! #[actix_rt::main]
|
|
|
|
//! async fn main() -> std::io::Result<()> {
|
|
|
|
//! // configure defense
|
|
|
|
//! let defense = DefenseBuilder::default()
|
|
|
|
//! // add as many levels as you see fit
|
|
|
|
//! .add_level(
|
|
|
|
//! LevelBuilder::default()
|
|
|
|
//! // visitor_threshold is the threshold/limit at which
|
|
|
|
//! // mCaptcha will adjust difficulty levels
|
|
|
|
//! // it is advisable to set small values for the first
|
|
|
|
//! // levels visitor_threshold and difficulty_factor
|
|
|
|
//! // as this will be the work that clients will be
|
|
|
|
//! // computing when there's no load
|
|
|
|
//! .visitor_threshold(50)
|
|
|
|
//! .difficulty_factor(500)
|
|
|
|
//! .unwrap()
|
|
|
|
//! .build()
|
|
|
|
//! .unwrap(),
|
|
|
|
//! )
|
|
|
|
//! .unwrap()
|
|
|
|
//! .add_level(
|
|
|
|
//! LevelBuilder::default()
|
|
|
|
//! .visitor_threshold(5000)
|
|
|
|
//! .difficulty_factor(50000)
|
|
|
|
//! .unwrap()
|
|
|
|
//! .build()
|
|
|
|
//! .unwrap(),
|
|
|
|
//! )
|
|
|
|
//! .unwrap()
|
|
|
|
//! .build()
|
|
|
|
//! .unwrap();
|
|
|
|
//!
|
|
|
|
//! // create and start MCaptcha actor
|
2021-03-07 19:54:41 +05:30
|
|
|
//! //let cache = HashCache::default().start();
|
2021-03-02 11:09:29 +05:30
|
|
|
//! let mcaptcha = MCaptchaBuilder::default()
|
|
|
|
//! .defense(defense)
|
|
|
|
//! // leaky bucket algorithm's emission interval
|
|
|
|
//! .duration(30)
|
|
|
|
//! .build()
|
|
|
|
//! .unwrap()
|
|
|
|
//! .start();
|
|
|
|
//!
|
|
|
|
//! // increment count when user visits protected routes
|
|
|
|
//! mcaptcha.send(Visitor).await.unwrap();
|
|
|
|
//!
|
|
|
|
//! Ok(())
|
|
|
|
//! }
|
|
|
|
//! ```
|
|
|
|
|
2021-02-28 15:05:39 +05:30
|
|
|
use std::time::Duration;
|
|
|
|
|
2021-03-05 21:52:41 +05:30
|
|
|
use actix::dev::*;
|
2021-02-28 15:05:39 +05:30
|
|
|
use derive_builder::Builder;
|
2021-03-05 21:52:41 +05:30
|
|
|
use pow_sha256::PoW as ShaPoW;
|
2021-03-07 19:54:41 +05:30
|
|
|
use serde::Deserialize;
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-03-02 11:09:29 +05:30
|
|
|
use crate::defense::Defense;
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-03-02 11:09:29 +05:30
|
|
|
/// This struct represents the mCaptcha state and is used
|
|
|
|
/// to configure leaky-bucket lifetime and manage defense
|
2021-03-08 19:43:26 +05:30
|
|
|
#[derive(Clone, Debug, Builder)]
|
2021-03-07 19:54:41 +05:30
|
|
|
pub struct MCaptcha {
|
2021-02-28 23:26:32 +05:30
|
|
|
#[builder(default = "0", setter(skip))]
|
2021-03-02 11:09:29 +05:30
|
|
|
visitor_threshold: u32,
|
2021-02-28 23:26:32 +05:30
|
|
|
defense: Defense,
|
2021-02-28 15:05:39 +05:30
|
|
|
duration: u64,
|
|
|
|
}
|
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
impl MCaptcha {
|
2021-02-28 23:26:32 +05:30
|
|
|
/// incerment visiotr count by one
|
|
|
|
pub fn add_visitor(&mut self) {
|
2021-03-02 11:09:29 +05:30
|
|
|
self.visitor_threshold += 1;
|
|
|
|
if self.visitor_threshold > self.defense.visitor_threshold() {
|
2021-02-28 23:26:32 +05:30
|
|
|
self.defense.tighten_up();
|
|
|
|
} else {
|
|
|
|
self.defense.loosen_up();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/// deccerment visiotr count by one
|
|
|
|
pub fn decrement_visiotr(&mut self) {
|
2021-03-02 11:09:29 +05:30
|
|
|
if self.visitor_threshold > 0 {
|
|
|
|
self.visitor_threshold -= 1;
|
2021-02-28 15:05:39 +05:30
|
|
|
}
|
|
|
|
}
|
2021-02-28 23:26:32 +05:30
|
|
|
|
|
|
|
/// get current difficulty factor
|
|
|
|
pub fn get_difficulty(&self) -> u32 {
|
|
|
|
self.defense.get_difficulty()
|
|
|
|
}
|
2021-03-05 21:52:41 +05:30
|
|
|
}
|
2021-03-07 19:54:41 +05:30
|
|
|
impl Actor for MCaptcha {
|
2021-02-28 15:05:39 +05:30
|
|
|
type Context = Context<Self>;
|
|
|
|
}
|
|
|
|
|
2021-03-05 21:52:41 +05:30
|
|
|
/// Message to decrement the visitor count
|
|
|
|
#[derive(Message)]
|
|
|
|
#[rtype(result = "()")]
|
|
|
|
struct DeleteVisitor;
|
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
impl Handler<DeleteVisitor> for MCaptcha {
|
2021-03-05 21:52:41 +05:30
|
|
|
type Result = ();
|
|
|
|
fn handle(&mut self, _msg: DeleteVisitor, _ctx: &mut Self::Context) -> Self::Result {
|
|
|
|
self.decrement_visiotr();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Message to increment the visitor count
|
|
|
|
#[derive(Message)]
|
2021-03-07 19:54:41 +05:30
|
|
|
#[rtype(result = "u32")]
|
2021-03-05 21:52:41 +05:30
|
|
|
pub struct Visitor;
|
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
impl Handler<Visitor> for MCaptcha {
|
|
|
|
type Result = u32;
|
2021-03-07 11:49:52 +05:30
|
|
|
|
2021-02-28 15:05:39 +05:30
|
|
|
fn handle(&mut self, _: Visitor, ctx: &mut Self::Context) -> Self::Result {
|
|
|
|
use actix::clock::delay_for;
|
|
|
|
|
|
|
|
let addr = ctx.address();
|
|
|
|
|
|
|
|
let duration: Duration = Duration::new(self.duration.clone(), 0);
|
|
|
|
let wait_for = async move {
|
|
|
|
delay_for(duration).await;
|
|
|
|
addr.send(DeleteVisitor).await.unwrap();
|
|
|
|
}
|
|
|
|
.into_actor(self);
|
|
|
|
ctx.spawn(wait_for);
|
|
|
|
|
2021-02-28 23:26:32 +05:30
|
|
|
self.add_visitor();
|
2021-03-07 19:54:41 +05:30
|
|
|
self.get_difficulty()
|
2021-02-28 15:05:39 +05:30
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-03-05 21:52:41 +05:30
|
|
|
/// Message to decrement the visitor count
|
|
|
|
#[derive(Message, Deserialize)]
|
|
|
|
#[rtype(result = "()")]
|
|
|
|
pub struct VerifyPoW {
|
|
|
|
pow: ShaPoW<Vec<u8>>,
|
|
|
|
id: String,
|
|
|
|
}
|
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
impl Handler<VerifyPoW> for MCaptcha {
|
2021-02-28 15:05:39 +05:30
|
|
|
type Result = ();
|
2021-03-07 19:54:41 +05:30
|
|
|
fn handle(&mut self, _: VerifyPoW, _ctx: &mut Self::Context) -> Self::Result {
|
2021-02-28 23:26:32 +05:30
|
|
|
self.decrement_visiotr();
|
2021-02-28 15:05:39 +05:30
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#[cfg(test)]
|
2021-03-08 17:02:36 +05:30
|
|
|
pub mod tests {
|
2021-02-28 15:05:39 +05:30
|
|
|
use super::*;
|
2021-03-02 11:09:29 +05:30
|
|
|
use crate::defense::*;
|
2021-02-28 23:26:32 +05:30
|
|
|
|
2021-03-02 11:09:29 +05:30
|
|
|
// constants for testing
|
2021-02-28 23:26:32 +05:30
|
|
|
// (visitor count, level)
|
2021-03-08 17:02:36 +05:30
|
|
|
pub const LEVEL_1: (u32, u32) = (50, 50);
|
|
|
|
pub const LEVEL_2: (u32, u32) = (500, 500);
|
|
|
|
pub const DURATION: u64 = 10;
|
2021-02-28 23:26:32 +05:30
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
type MyActor = Addr<MCaptcha>;
|
2021-03-05 21:52:41 +05:30
|
|
|
|
2021-03-08 17:02:36 +05:30
|
|
|
pub fn get_defense() -> Defense {
|
2021-02-28 23:26:32 +05:30
|
|
|
DefenseBuilder::default()
|
|
|
|
.add_level(
|
|
|
|
LevelBuilder::default()
|
2021-03-02 11:09:29 +05:30
|
|
|
.visitor_threshold(LEVEL_1.0)
|
2021-02-28 23:26:32 +05:30
|
|
|
.difficulty_factor(LEVEL_1.1)
|
|
|
|
.unwrap()
|
|
|
|
.build()
|
|
|
|
.unwrap(),
|
|
|
|
)
|
|
|
|
.unwrap()
|
|
|
|
.add_level(
|
|
|
|
LevelBuilder::default()
|
2021-03-02 11:09:29 +05:30
|
|
|
.visitor_threshold(LEVEL_2.0)
|
2021-02-28 23:26:32 +05:30
|
|
|
.difficulty_factor(LEVEL_2.1)
|
|
|
|
.unwrap()
|
|
|
|
.build()
|
|
|
|
.unwrap(),
|
|
|
|
)
|
|
|
|
.unwrap()
|
|
|
|
.build()
|
|
|
|
.unwrap()
|
|
|
|
}
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
async fn race(addr: Addr<MCaptcha>, count: (u32, u32)) {
|
2021-02-28 23:26:32 +05:30
|
|
|
for _ in 0..count.0 as usize - 1 {
|
2021-02-28 15:05:39 +05:30
|
|
|
let _ = addr.send(Visitor).await.unwrap();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-03-08 17:02:36 +05:30
|
|
|
pub fn get_counter() -> MCaptcha {
|
2021-03-02 11:09:29 +05:30
|
|
|
MCaptchaBuilder::default()
|
2021-02-28 23:26:32 +05:30
|
|
|
.defense(get_defense())
|
|
|
|
.duration(DURATION)
|
|
|
|
.build()
|
|
|
|
.unwrap()
|
|
|
|
}
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-02-28 23:26:32 +05:30
|
|
|
#[actix_rt::test]
|
|
|
|
async fn counter_defense_tightenup_works() {
|
2021-03-05 21:52:41 +05:30
|
|
|
let addr: MyActor = get_counter().start();
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
let mut difficulty_factor = addr.send(Visitor).await.unwrap();
|
|
|
|
assert_eq!(difficulty_factor, LEVEL_1.0);
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-02-28 23:26:32 +05:30
|
|
|
race(addr.clone(), LEVEL_2).await;
|
2021-03-07 19:54:41 +05:30
|
|
|
difficulty_factor = addr.send(Visitor).await.unwrap();
|
|
|
|
assert_eq!(difficulty_factor, LEVEL_2.1);
|
2021-02-28 15:05:39 +05:30
|
|
|
}
|
|
|
|
|
|
|
|
#[actix_rt::test]
|
2021-02-28 23:26:32 +05:30
|
|
|
async fn counter_defense_loosenup_works() {
|
2021-02-28 15:05:39 +05:30
|
|
|
use actix::clock::delay_for;
|
2021-03-05 21:52:41 +05:30
|
|
|
let addr: MyActor = get_counter().start();
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-02-28 23:26:32 +05:30
|
|
|
race(addr.clone(), LEVEL_2).await;
|
|
|
|
race(addr.clone(), LEVEL_2).await;
|
2021-03-07 19:54:41 +05:30
|
|
|
let mut difficulty_factor = addr.send(Visitor).await.unwrap();
|
|
|
|
assert_eq!(difficulty_factor, LEVEL_2.1);
|
2021-02-28 15:05:39 +05:30
|
|
|
|
2021-02-28 23:26:32 +05:30
|
|
|
let duration = Duration::new(DURATION, 0);
|
2021-02-28 15:05:39 +05:30
|
|
|
delay_for(duration).await;
|
|
|
|
|
2021-03-07 19:54:41 +05:30
|
|
|
difficulty_factor = addr.send(Visitor).await.unwrap();
|
|
|
|
assert_eq!(difficulty_factor, LEVEL_1.1);
|
2021-02-28 15:05:39 +05:30
|
|
|
}
|
|
|
|
}
|