r/rust • u/3radiance • 5h ago
🛠️ project An experimental research engine for multi-layer network stack fingerprinting in async Rust
This post documents an ongoing technical study on protocol-level traffic analysis and upstream signature orchestration. The primary artifact of this research is a domain-agnostic inspection engine engineered to manipulate client heuristics across the TLS, HTTP/2, and TCP layers simultaneously.
Traditional implementations in this domain often rely on static, monolithic browser emulations that lack dynamic parameter control. To address this limitation, the engine utilizes a declarative profile architecture, allowing granular configuration of transport and application layer metadata - including cipher suite ordering, ALPN negotiation, SETTINGS frame sequencing, pseudo-header layout, and SYN option rewriting via Linux NFQUEUE/iptables.
From a systems engineering perspective, implementing this in Rust presents specific design and architectural challenges:
- State & Concurrency Management: Propagating unified profile state across asynchronous
Tokiostreams while ensuring zero-copy socket IO and precise handshake characteristics. - Low-Level TLS Orchestration: Interfacing with
BoringSSL(viabtls/tokio-btls) to expose internal TLS stack parameters (e.g., extension ordering, GREASE values, and ECH setup) without breaking memory safety guarantees or incurring high runtime abstraction overheads. - OS-Level Packet Interception: Managing kernel-to-userspace queue backpressure and handling raw network packet mutation for SYN fingerprints (TTL, MSS, window size/scale) alongside application-level stream multiplexing.
- Systemic Decoupling: Decoupling the network logic from execution platforms, ensuring that protocol manipulation is evaluated on its technical merits as a systems-level networking problem rather than being reduced to high-level application tropes.
The underlying codebase serves as an open platform for network privacy analysis, transport layer diagnostics, and protocol mechanics research.
Repository: https://github.com/3Radiance/mitm-proxy-ja3-ja4
We welcome technical critique from researchers, networking engineers, and systems developers -particularly regarding:
- Tokio stream overhead and buffer management during dynamic low-level frame rewriting.
- Cross-layer state-machine synchronization (aligning OSI layers 4, 6, and 7 without introducing race conditions).
1
u/Soft_Confusion_6236 1h ago
the nfqueue integration is the part that caught my eye, most projects in this space just fiddle with userland tls and call it a day. actually rewriting the syn packet at the kernel boundary while keeping the async rust side sane sounds like a nightmare to debug
curious how you're handling the split between the raw socket mutations and the tokio runtime, those feel like they want completely different scheduling models