DoS and DDoS protection library.
- Custom
tokioexecutor with task priorities - Connection count limits
- Bandwidth limits/priorities
- CPU limits/priorities
- RAM limits/priorities
- TLS handshake timeouts and concurrency limits
- TCP timeouts, pacing, delaying, and buffer limits/priorities
- HTTP timeouts and concurrency limits
- Logging (
log) - Metrics
-
nftablesfirewall configuration - OS network stack hardening
- HTTP/1 and HTTP/2 (
hyper/axum) - WebSocket (
axum-tws/tokio-websockets) - WebTransport (
wtransport/quinn) - TLS for all of the above (
rustls)
- Not optimized for multi-core runtimes
- ~15% max throughput reduction
Gradually migrating related functionality from other projects.
Licensed under either of
- Apache License, Version 2.0 (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.