Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/config/constants.js
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,10 @@ const BROADCAST_THROTTLE = 1000;
const DIAGNOSTICS_INTERVAL = 10000;
const PORT = process.env.PORT || 3000;

// Rate Limiting: Semi effective mitigation to limit abuse from malicious peers / Sybil attack leveraging weak PoW. 100 new peers per 5 seconds per connection.
const RATE_LIMIT_WINDOW = 5000;
const RATE_LIMIT_MAX_NEW_PEERS = 1000;

module.exports = {
TOPIC_NAME,
TOPIC,
Expand All @@ -39,4 +43,6 @@ module.exports = {
BROADCAST_THROTTLE,
DIAGNOSTICS_INTERVAL,
PORT,
RATE_LIMIT_WINDOW,
RATE_LIMIT_MAX_NEW_PEERS,
};
28 changes: 22 additions & 6 deletions src/p2p/messaging.js
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
const { verifyPoW, verifySignature, createPublicKey } = require("../core/security");
const { MAX_RELAY_HOPS } = require("../config/constants");
const { MAX_RELAY_HOPS, RATE_LIMIT_WINDOW, RATE_LIMIT_MAX_NEW_PEERS } = require("../config/constants");
const { BloomFilterManager } = require("../state/bloom");

class MessageHandler {
Expand Down Expand Up @@ -62,10 +62,21 @@ class MessageHandler {
if (wasNew) {
this.diagnostics.increment("newPeersAdded");
this.broadcastCallback();
if (hops === 0) {
const now = Date.now();
if (!sourceSocket.rateLimiter || now > sourceSocket.rateLimiter.resetTime) {
sourceSocket.rateLimiter = { count: 0, resetTime: now + RATE_LIMIT_WINDOW };
}
if (++sourceSocket.rateLimiter.count >= RATE_LIMIT_MAX_NEW_PEERS) {
this.diagnostics.increment("rateLimitedConnections");
sourceSocket.destroy();
return;
}
}
}

// Only relay if we haven't already relayed this message (bloom filter check)
if (hops < MAX_RELAY_HOPS && !this.bloomFilter.hasRelayed(id, seq)) {
if (hops >= 0 && hops < MAX_RELAY_HOPS && !this.bloomFilter.hasRelayed(id, seq)) {
this.bloomFilter.markRelayed(id, seq);
this.diagnostics.increment("heartbeatsRelayed");
this.relayCallback({ ...msg, hops: hops + 1 }, sourceSocket);
Expand Down Expand Up @@ -97,7 +108,7 @@ class MessageHandler {
this.broadcastCallback();

// Use id:leave as key for LEAVE messages
if (hops < MAX_RELAY_HOPS && !this.bloomFilter.hasRelayed(id, "leave")) {
if (hops >= 0 && hops < MAX_RELAY_HOPS && !this.bloomFilter.hasRelayed(id, "leave")) {
this.bloomFilter.markRelayed(id, "leave");
this.relayCallback({ ...msg, hops: hops + 1 }, sourceSocket);
}
Expand All @@ -116,15 +127,20 @@ const validateMessage = (msg) => {
const allowedFields = ['type', 'id', 'seq', 'hops', 'nonce', 'sig'];
const fields = Object.keys(msg);
return fields.every(f => allowedFields.includes(f)) &&
msg.id && typeof msg.seq === 'number' &&
typeof msg.hops === 'number' && msg.nonce && msg.sig;
typeof msg.id === 'string' && msg.id.length > 0 &&
typeof msg.seq === 'number' && Number.isInteger(msg.seq) && msg.seq >= 0 &&
typeof msg.hops === 'number' && Number.isInteger(msg.hops) && msg.hops >= 0 &&
typeof msg.nonce === 'number' && Number.isInteger(msg.nonce) && msg.nonce >= 0 &&
typeof msg.sig === 'string' && msg.sig.length > 0;
}

if (msg.type === "LEAVE") {
const allowedFields = ['type', 'id', 'hops', 'sig'];
const fields = Object.keys(msg);
return fields.every(f => allowedFields.includes(f)) &&
msg.id && typeof msg.hops === 'number' && msg.sig;
typeof msg.id === 'string' && msg.id.length > 0 &&
typeof msg.hops === 'number' && Number.isInteger(msg.hops) && msg.hops >= 0 &&
typeof msg.sig === 'string' && msg.sig.length > 0;
}

return false;
Expand Down
1 change: 1 addition & 0 deletions src/state/diagnostics.js
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ class DiagnosticsManager {
bytesReceived: 0,
bytesRelayed: 0,
leaveMessages: 0,
rateLimitedConnections: 0,
};

this.interval = null;
Expand Down