Sign inSign up

frogsoftware/eclipse-fortify

By frogsoftware

•Updated over 2 years ago

Imperceptible Shuffle-Based Moving Target Defense for Budget-Friendly Web Service DDoS Protection

Image
0

291

frogsoftware/eclipse-fortify repository overview

⁠EclipseFortify

This repository provides the EclipseFortify web service DDoS defense method. It combines the principles of Moving Target Defense (MTD) with cost-effective measures to protect web services from Distributed Denial of Service (DDoS) attacks.

⁠Features

  • Moving Target Defense (MTD): EclipseFortify dynamically allocates valid reverse proxies to users, disrupting the correlation between users and proxies to effectively reject attack traffic.
  • Cost-effective: By reducing the cost of defense, EclipseFortify provides an affordable DDoS protection solution for organizations.
  • Suspicious rating system: EclipseFortify incorporates a dynamically updated rating system to counter advanced attackers who adapt their strategies.
  • Seamless switching: EclipseFortify ensures uninterrupted service by embedding scripts in reverse proxy forwarding, establishing a control link with user-side browsers.

⁠Environment

This is a Docker Compose file for the EclipseFortify system. It is a distributed system consisting of multiple components running in separate containers. The services included in this Docker Compose file are:

  • user
  • proxy1
  • proxy2
  • proxy3
  • proxy4
  • manager
  • scheduler
  • redis
  • speedtest

The services communicate with each other over a private network (ef-private) and expose ports for external access where needed.

⁠User Service

The user service runs a container with an image named netutils and exposes the IP address 172.126.1.10 on the ef-public network. It depends on the manager, scheduler, proxy1, proxy2, and proxy3 services to be up and running before starting. The command for the container is to sleep for 1 day.

⁠Proxy Services

There are three proxy services included in this Docker Compose file (proxy1, proxy2, and proxy3). They all use the same image (frogsoftware/ef-proxy) and depend on the redis service to be up and running before starting. They each expose port 8080 for external access and use the ef-public and ef-private networks. The containers for each proxy service are given the following IP addresses:

  • proxy1: 172.126.1.111 on ef-public and 172.126.2.111 on ef-private
  • proxy2: 172.126.1.112 on ef-public and 172.126.2.112 on ef-private
  • proxy3: 172.126.1.113 on ef-public and 172.126.2.113 on ef-private
  • proxy4: 172.126.1.114 on ef-public and 172.126.2.114 on ef-private

The command for each proxy service is a set of arguments for the frogsoftware/ef-proxy image, which includes the redis server address, the IP address for the container, and other configuration options. The volumes option maps local files to files in the container.

⁠Manager Service

The manager service runs a container with an image named frogsoftware/ef-manager and exposes port 8090 for external access. It depends on the redis service to be up and running before starting. The command for the container specifies the redis server address, the IP address for the container, and other configuration options.

⁠Scheduler Service

The scheduler service runs a container with an image named frogsoftware/ef-scheduler and exposes port 5525 for external access. It depends on the redis service to be up and running before starting. The command for the container specifies the redis server address and sets the log level to debug.

⁠Redis Service

The redis service runs a container with the official Redis image and exposes port 6379 for external access. It uses the ef-private network and is given the IP address 172.126.2.220.

⁠Networks

The Docker Compose file defines two networks:

  • ef-public: A public network with the subnet 172.126.1.0/24. The user and proxy services use this network.
  • ef-private: A private network with the subnet 172.126.2.0/24. The proxy, manager, scheduler, and redis services use this network.

⁠Usage

Use Docker Compose to start up the applications and then visit manager page ( http://manager-proxy1.tests.orb.local).

If you need to run the speedtest, you should firstly add this service into EF system via manager page.

version: "3.9"
services:
  user:
    image: frogsoftware/netutils
    depends_on:
      - proxy1
      - proxy2
      - proxy3
      - proxy4
    command:
      - "sleep"
      - "1d"
    container_name: user
    networks:
      ef-public:
        ipv4_address: 172.126.1.10

  proxy1:
    image: frogsoftware/ef-proxy
    container_name: proxy1
    depends_on:
      - scheduler
    expose:
      - 8080
    privileged: true
    command:
      - "--redis=redis:6379"
      - "--name=proxy1"
      - "--public-domain-name=tests.orb.local"
      - "--private-ip=172.126.2.111"
      - "--ws-port=5525"
      - "--proxy-level=0"
      - "--scheduler-addr=172.126.2.202"
      - "--log-level=debug"
      - "--insecure-skip-verify"
    networks:
      ef-public:
        ipv4_address: 172.126.1.111
        aliases:
          - proxy1.tests.orb.local
          - manager-proxy1.tests.orb.local
          - localstorage-proxy1.tests.orb.local
          - proxy1
      ef-private:
        ipv4_address: 172.126.2.111
  proxy2:
    image: frogsoftware/ef-proxy
    container_name: proxy2
    depends_on:
      - scheduler
    privileged: true
    command:
      - "--redis=redis:6379"
      - "--name=proxy2"
      - "--public-domain-name=tests.orb.local"
      - "--private-ip=172.126.2.112"
      - "--ws-port=5525"
      - "--proxy-level=1"
      - "--scheduler-addr=172.126.2.202"
      - "--log-level=debug"
      - "--insecure-skip-verify"
    networks:
      ef-public:
        ipv4_address: 172.126.1.112
        aliases:
          - proxy2.tests.orb.local
          - manager-proxy2.tests.orb.local
          - localstorage-proxy2.tests.orb.local
          - proxy2
      ef-private:
        ipv4_address: 172.126.2.112
  proxy3:
    image: frogsoftware/ef-proxy
    container_name: proxy3
    depends_on:
      - scheduler
    privileged: true
    command:
      - "--redis=redis:6379"
      - "--name=proxy3"
      - "--public-domain-name=tests.orb.local"
      - "--private-ip=172.126.2.113"
      - "--ws-port=5525"
      - "--proxy-level=1"
      - "--scheduler-addr=172.126.2.202"
      - "--log-level=debug"
      - "--insecure-skip-verify"
    networks:
      ef-public:
        ipv4_address: 172.126.1.113
        aliases:
          - proxy3.tests.orb.local
          - manager-proxy3.tests.orb.local
          - localstorage-proxy3.tests.orb.local
          - proxy3
      ef-private:
        ipv4_address: 172.126.2.113
  proxy4:
    image: frogsoftware/ef-proxy
    container_name: proxy4
    depends_on:
      - scheduler
    privileged: true
    command:
      - "--redis=redis:6379"
      - "--name=proxy4"
      - "--public-domain-name=tests.orb.local"
      - "--private-ip=172.126.2.114"
      - "--ws-port=5525"
      - "--proxy-level=1"
      - "--scheduler-addr=172.126.2.202"
      - "--log-level=debug"
      - "--insecure-skip-verify"
    networks:
      ef-public:
        ipv4_address: 172.126.1.114
        aliases:
          - proxy4.tests.orb.local
          - manager-proxy4.tests.orb.local
          - localstorage-proxy4.tests.orb.local
          - proxy4
      ef-private:
        ipv4_address: 172.126.2.114

  manager:
    image: frogsoftware/ef-manager
    container_name: manager
    ports:
      - "8090:8090"
    depends_on:
        - redis
        - localstorage
    command:
        - "--redis=redis:6379"
        - "--http=0.0.0.0:8090"
        - "--type=http"
        - "--public-ip=172.126.2.201"
        - "--localstorage=172.126.2.203:8189"
        - "serve"
    networks:
      ef-private:
        ipv4_address: 172.126.2.201

  scheduler:
    image: frogsoftware/ef-scheduler
    container_name: scheduler
    ports:
      - "5525:5525"
    depends_on:
      - redis
      - manager
      - localstorage
    command:
      - "--redis=redis:6379"
      - "--log-level=debug"
    extra_hosts:
      - "manager-proxy1.tests.orb.local:172.126.1.111"
      - "manager-proxy2.tests.orb.local:172.126.1.112"
      - "manager-proxy3.tests.orb.local:172.126.1.113"
      - "manager-proxy4.tests.orb.local:172.126.1.114"
      - "proxy1.tests.orb.local:172.126.2.111"
      - "proxy2.tests.orb.local:172.126.2.112"
      - "proxy3.tests.orb.local:172.126.2.113"
      - "proxy4.tests.orb.local:172.126.2.114"
    networks:
      ef-private:
        ipv4_address: 172.126.2.202

  localstorage:
    image: frogsoftware/ef-localstorage
    container_name: localstorage
    command:
      - "--log-level=debug"
    ports:
      - "8189:8189"
    networks:
      ef-private:
        ipv4_address: 172.126.2.203

  speedtest:
    image: frogsoftware/speedtest
    container_name: speedtest
    networks:
      ef-private:
        ipv4_address: 172.126.2.204

  redis:
    image: redis
    container_name: redis
    ports:
      - "6379:6379"
    networks:
      ef-private:
        ipv4_address: 172.126.2.220

networks:
  ef-public:
    name: ef-public
    driver: bridge
    ipam:
      config:
        - subnet: 172.126.1.0/24
  ef-private:
    driver: bridge
    ipam:
      config:
        - subnet: 172.126.2.0/24

Tag summary

Content type

Image

Digest

sha256:1489492ad…

Size

71.7 MB

Last updated

over 2 years ago

docker pull frogsoftware/eclipse-fortify