Skip to content
DnsLister Forum

Where domain hunters compare notes

[Project J8s Update] Shifting from 1D Time Freeze to 2D Kinship Mapping | Dtrace-Powered Active Defense for FreeBSD: 25-Gen Process Lineage Tracking & 2,000-Fork Per-Session Envelope Control

Hi r/freebsd & others,

I've implemented a low-overhead active defense mechanism inside FreeBSD Jails to mitigate automated high-speed brute-force attacks.

Concept:

To prevent an intruder from spawning deeper process trees or using attack binaries (nc, bash, python), I developed a 2D Kinship Mapping system using Dtrace to monitor the process boundary at the kernel space edge.

How it works:

  1. The 2D matrix tracks both parent-child lineages vertically (up to 25 generations) and active forks per session horizontally (up to 2000), leaving the threat zero dimensions to evade.
  2. If a breach or blacklisted binary (nc, bash, python) is detected, the probe triggers chill(50ms) to freeze the target thread inside the kernel.
  3. Simultaneously, a host-side daemon reads the Dtrace consumer buffer, kills the pid, and fires an asynchronous zfs rollback to restore the pristine Jail snapshot.

WARNING: Don't try this at home. While developing this system, I broke the Jail's ZFS mounts countless times due to race conditions between the kernel-level arrest and host-level filesystem management. It is a highly volatile setup (though umount -f always comes to the rescue).

D Code:

Here is an excerpt of the Dtrace core engine handling the 2D matrix control. The full source includes custom zone-validation matrices and whitelist structures for host-initiated maintenance tasks, which I keep closed for obvious mitigation reasons.

#pragma D option quiet #pragma D option destructive #pragma D option cleanrate=1000hz /* Aggressive memory cleanup under heavy burst load */ inline int64_t SESSION_FORK_LIMIT = 2000; /* --- Vertical Bound: 25-Generation Lineage Depth Tracking --- */ proc:::exec-success /curpsinfo->pr_jailid != 0/ { /* Scan parent pointers inside FreeBSD kernel structures at lightspeed */ this->p1 = curthread->td_proc->p_pptr; this->p2 = (this->p1 != NULL) ? this->p1->p_pptr : NULL; this->p3 = (this->p2 != NULL) ? this->p2->p_pptr : NULL; /* ... [Static unrolling continued down to 25 generations] ... */ this->p25 = (this->p24 != NULL) ? this->p24->p_pptr : NULL; /* Instant verdict if nesting depth hits the 25-gen vertical limit */ if (this->p25 != NULL && this->p25->p_pptr != NULL) { chill(50000000); /* 50ms tactical window to hold the thread hostage */ raise(SIGKILL); } } /* --- Horizontal Bound: 2,000-Fork Session Aggregation --- */ proc:::create /curpsinfo->pr_jailid != 0/ { /* Extract the Session ID (SID) directly from the process group structure */ this->sid = (curthread->td_proc != NULL && curthread->td_proc->p_pgrp != NULL && curthread->td_proc->p_pgrp->pg_session != NULL) ? (int64_t)curthread->td_proc->p_pgrp->pg_session->s_sid : (int64_t)ppid; p_session_child_count[this->sid]++; /* Absolute closing of the matrix if cumulative session forks cross the threshold */ if (p_session_child_count[this->sid] >= SESSION_FORK_LIMIT && ppid != 1) { /* * 1. Tetragon-style Asynchronous Event Pipeline: * Instantly fire-and-forget a non-blocking notification to the host userland * daemon via consumer buffer write, requesting a parallel execution purge. */ /* [Hidden: Asynchronous lockless event notification channel] */ /* * 2. Freeze the culprit thread instantly inside the kernel edge for 50ms. * This holds the thread hostage to give the host daemon ample time * to sweep the entire jail before this mutated payload can make another move. */ chill(50000000); raise(SIGKILL); } } /* --- 3. Active Trapping / Unauthorized Binary Detection --- */ syscall::open:entry, syscall::openat:entry /curpsinfo->pr_jailid != 0/ { /* Intercept and kill high-risk reconnaissance/attack binaries instantly */ if (execname == "nc" || execname == "python" || execname == "python3" || execname == "bash") { /* [Hidden: Custom honeypot & front-line VNET zone validation matrix] */ chill(50000000); raise(SIGKILL); } } 

Notes:

– Host-side asynchronous OpenZFS rollback and VNET reconfiguration are executed via out-of-band kernel messaging inside proc:::exit. Full 25-generation visual tree generator is kept closed-source for offensive mitigation.

– The text was polished/translated with AI assistance, but the core Dtrace script is 100% handwritten and runs on my FreeBSD 15.1 machine.

https://www.reddit.com/gallery/1wm1b0n

Source: r/freebsd · by /u/Grouchy_County_4334

Leave a Reply

Your email address will not be published. Required fields are marked *