From 52eb471e8901cc75525c3b5b7640fd4703ab699b Mon Sep 17 00:00:00 2001 From: Kyren223 Date: Tue, 15 Jul 2025 21:05:31 +0300 Subject: Implemented connection-level rate limiting (to avoid reconnection abuse), added a file for testing that, still needs to add observability for this --- tools/test_rate_limit.go | 60 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 tools/test_rate_limit.go (limited to 'tools/test_rate_limit.go') diff --git a/tools/test_rate_limit.go b/tools/test_rate_limit.go new file mode 100644 index 0000000..7c25d20 --- /dev/null +++ b/tools/test_rate_limit.go @@ -0,0 +1,60 @@ +package main + +import ( + "crypto/tls" + "fmt" + "log" + "net" + "time" +) + +const addr = "localhost:7223" + +var tlsConfig = &tls.Config{ + InsecureSkipVerify: true, // skip cert verification +} + +func connect(n int, label string) { + fmt.Println("----", label) + conns := make([]net.Conn, 0, n) + for i := 0; i < n; i++ { + conn, err := tls.Dial("tcp", addr, tlsConfig) + if err != nil { + log.Printf("connect %d failed: %v", i, err) + continue + } + conns = append(conns, conn) + } + time.Sleep(300 * time.Millisecond) + for _, c := range conns { + c.Close() + } + time.Sleep(200 * time.Millisecond) +} + +func wait() { + time.Sleep(1100 * time.Millisecond) // ensure we roll over fixed 1s window +} + +func main() { + // 1. Single connection, then disconnect, should not rate limit + connect(1, "single connection") + wait() + + // 2. Two connections (under threshold), should show info + connect(2, "two connections") + wait() + connect(2, "two connections again") + wait() + + // 3. Hit 5 times to trigger suspicious threshold once + connect(5, "5 suspicious connections") + wait() + connect(5, "5 more suspicious") + wait() + + // 4. Hit 15 times to trigger malicious + connect(15, "15 malicious connections") + wait() + connect(15, "15 more malicious connections") +} -- cgit v1.3.1