|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L4 Transport ยท Build flags: PROTOCORE_ENABLE_PER_IP_THROTTLE
The global accept throttle caps total accepts but cannot tell one noisy client from many legitimate ones. This per-IP throttle closes that gap: the accept callback rejects a new connection once a single source IPv4 has opened more than PROTOCORE_PER_IP_THROTTLE_MAX connections within PROTOCORE_PER_IP_THROTTLE_WINDOW_MS, so one abusive host is throttled without affecting everyone else.
Bounded memory, no heap. A fixed BSS table of PROTOCORE_PER_IP_THROTTLE_SLOTS buckets tracks the busiest recent addresses (an LRU-ish set, not one slot per possible IP), so the defense itself stays deterministic.
Build-time only. Like the global throttle, there is no runtime API - the handler is plain; enabling the flag activates the defense in the accept path:
Tuning + pairing. Set the knobs as build flags (cap, window, table size), and pair it with the global accept throttle for layered defense:
From one host, open many rapid connections and watch that host get refused while another host still connects.
The complete sketch (PerIpThrottle.ino), reproduced verbatim with added explanatory comments: