Security Architecture & Cryptographic Model
AmarDNS is engineered in bare-metal Rust with zero garbage collection, cryptographic DNSSEC verification, and in-memory Bloom filter hardware bit arrays.
1. Cryptographic DNSSEC Engine (RFC 4034, 4035, 5155, 9276)
- Direct IANA Root Trust Anchor Sync: Authenticated against official root-anchors.xml with S/MIME PKCS#7 signature verification.
- Zero Upstream Trust: Cryptographic RRSIG signatures (ECDSA P-256, Ed25519, RSA/SHA-256) are validated locally on-node before setting Authenticated Data (AD=1).
- NSEC / NSEC3 Denial-of-Existence Proofs: Validates cryptographic non-existence hashes with salt and iteration limits (RFC 5155).
- RFC 9276 DoS Iteration Guard: Enforces a strict ceiling of ≤ 150 iterations to eliminate CPU exhaustion attacks.
2. Multi-Layer Threat Mitigation Pipeline
Bloom Filter Hardware Bitsets
Zero-allocation in-memory membership filter holding 1.5M+ threat signatures in 4MB RAM with power-of-two bitwise masking and coprime double-hashing.
Perpetual AI Neural Engine
8-dimensional feature vector extraction and Markov transition bigram anomaly scoring to detect zero-day DGA malware before blocklists update.
DNS Rebinding Interceptor
Blocks malicious public domain resolutions attempting to return RFC 1918 private IPv4 or loopback subnets.
Brand Typosquatting Defense
Levenshtein distance and homoglyph inspection protecting users from phishing traps targeting banking and cloud portals.
3. Memory Governor & Rate Limiter Architecture
- Dynamic Memory Governor: Operates under a 200MB hard RSS ceiling. At 140MB, proactive eviction runs; at 175MB, emergency cache shedding instantly resets memory to ~30MB.
- Token-Bucket Rate Limiter: Enforces per-IP and per-device burst limits with automatic CIDR exemptions for private RFC 1918 networks and Carrier-Grade NAT.
- Singleflight Concurrency Coalescing: Merges identical concurrent queries into a single upstream request, eliminating thundering-herd surges.