
高度なマルチテクノロジーストレステストフレームワーク 高性能ネットワークテストのための教育用サイバーセキュリティツール
高度なマルチテクノロジーストレステストフレームワーク
高性能ネットワークテストのための教育用サイバーセキュリティツール
Xerxes-Ultimate は、教育用サイバーセキュリティラボ向けに特別に設計された、次世代のネットワークストレステストツールです。元のXerxes DoSツールの基盤の上に構築されたこの実装は、最先端のハードウェアアクセラレーション技術を活用し、教育上の透明性を維持しながら、前例のないパフォーマンスレベルを達成します。
graph LR
A[Original Xerxes
50K PPS] --> B[BASIC Tier
100K PPS
2x improvement]
B --> C[IO_URING Tier
1M PPS
20x improvement]
C --> D[GPU Tier
10M PPS
200x improvement]
D --> E[DPDK Tier
30M PPS
600x improvement]
E --> F[ULTIMATE Tier
60M+ PPS
1,200x improvement]
---
## 🛠️ 技術スタック
### コアテクノロジー
#### 🎮 **CUDA マルチGPUアクセラレーション**```c
// Parallel payload generation across 4 GPUs
__global__ void generate_ultimate_payloads(char *payloads, int *sizes,
int payload_count, uint64_t seed) {
int idx = blockIdx.x * blockDim.x + threadIdx.x;
// 512 blocks × 1024 threads × 4 GPUs = 2,097,152 parallel generators
}
利点:
// Asynchronous submission queue struct io_uring ring; io_uring_queue_init(8192, &ring, IORING_SETUP_SQPOLL);
// Direct GPU->NIC transfer without CPU copies io_uring_prep_send_zc(sqe, socket_fd, gpu_buffer, size, 0);
**利点:**
- **I/Oパフォーマンスが400%向上**
- **GPUからNICへのゼロコピー転送**
- **コンテキストスイッチのオーバーヘッドを排除**
- **100,000以上の同時操作に対応**
#### 🌐 **DPDKユーザースペースネットワーキング**```c
// Bypass kernel network stack entirely
struct rte_mbuf *pkts[BURST_SIZE];
uint16_t nb_tx = rte_eth_tx_burst(port_id, queue_id, pkts, nb_pkts);
利点:
SEC("xdp_ultimate") int xdp_stress_program(struct xdp_md *ctx) { // Kernel-level packet manipulation return XDP_TX; // Retransmit at wire speed }
**利点:**
- **ユーザースペース比200%の効率向上**
- **カーネルレベルのパケット生成**
- **プログラム可能なパケット処理**
- **ハードウェアオフロードとの統合**
---
## 📊 アーキテクチャ
### システムアーキテクチャ概要```mermaid
graph TB
subgraph "User Space"
A[Control Thread] --> B[Thread Pool Manager]
B --> C[GPU Generator Threads]
B --> D[Network Transmit Threads]
B --> E[Statistics Monitor]
end
subgraph "GPU Cluster"
F[RTX 4070 Ti #1<br/>2,560 cores]
G[RTX 4070 Ti #2<br/>2,560 cores]
H[RTX 4070 Ti #3<br/>2,560 cores]
I[RTX 4070 Ti #4<br/>2,560 cores]
F --> J[GPU Memory Pool<br/>48GB Total]
G --> J
H --> J
I --> J
end
subgraph "I/O Subsystem"
K[io_uring Ring<br/>8192 entries]
L[DPDK PMD Drivers]
M[Zero-Copy Buffers]
end
subgraph "Kernel Space"
N[XDP Hook]
O[eBPF Programs]
P[Network Interface]
end
C --> F
C --> G
C --> H
C --> I
D --> K
D --> L
K --> M
L --> M
M --> N
N --> O
O --> P
P --> Q[Target Network<br/>60+ Gbps]
graph LR
subgraph "GPU Memory (16GB)"
A[Payload Buffers
8GB]
B[Size Arrays
2GB]
C[Random States
4GB]
D[Working Space
2GB]
end
subgraph "Host Memory (32GB)"
E[Pinned Buffers<br/>16GB]
F[Ring Buffers<br/>8GB]
G[Connection Pool<br/>4GB]
H[Statistics<br/>4GB]
end
subgraph "NIC Memory (1GB)"
I[DMA Buffers<br/>512MB]
J[Descriptor Rings<br/>256MB]
K[Hardware Queues<br/>256MB]
end
A -.->|PCIe 4.0<br/>64 GB/s| E
E -.->|Zero-Copy| F
F -.->|DMA| I
---
## 🚀 クイックスタート
### 前提条件の確認```bash
# Run the capability detector
./scripts/check-capabilities.sh
[✓] CUDA: 4 GPUs detected
[✓] DPDK: Compatible NIC detected
[✓] io_uring: Kernel support available
[✓] XDP/eBPF: Root privileges available
### 基本起動```bash
# Simple unlimited attack
./artaxerxes-ultimate 192.168.1.100 80
# Controlled burst testing
./artaxerxes-ultimate 192.168.1.100 80 10M_pps
# Bandwidth-limited testing
./artaxerxes-ultimate 192.168.1.100 80 5Gbps
# Time-limited demonstration
./artaxerxes-ultimate 192.168.1.100 80 300s
git clone https://gitlab.com/toxy4ny/ARTAXERXES.git cd ARTAXERXES
sudo quick-deploy.sh
### 手動インストール
#### 1. 依存関係のインストール
**Ubuntu/Debian:**```bash
# System packages
sudo apt-get update
sudo apt-get install -y build-essential cmake pkg-config \
libnuma-dev libpcap-dev python3-pyelftools \
libbpf-dev libelf-dev zlib1g-dev liburing-dev
# CUDA Toolkit (if not installed)
wget https://developer.download.nvidia.com/compute/cuda/12.3.0/local_installers/cuda_12.3.0_545.23.06_linux.run
sudo sh cuda_12.3.0_545.23.06_linux.run
# DPDK
wget http://fast.dpdk.org/rel/dpdk-22.11.1.tar.xz
tar xf dpdk-22.11.1.tar.xz
cd dpdk-22.11.1
meson setup build
cd build && ninja && sudo ninja install
CentOS/RHEL:```bash
sudo dnf install epel-release sudo dnf config-manager --set-enabled powertools
sudo dnf groupinstall "Development Tools"
sudo dnf install cmake pkgconfig numactl-devel libpcap-devel
python3-pyelftools libbpf-devel elfutils-libelf-devel
zlib-devel liburing-devel
#### 2. 機能検出でビルドする```bash
# Build with all available features
make
# Build specific configuration
make CUDA_AVAILABLE=1 DPDK_AVAILABLE=1 IO_URING_AVAILABLE=1
sudo make install
### Dockerのインストール```bash
# Build container with all dependencies
docker build -t xerxes-ultimate .
# Run with GPU support
docker run --gpus all --privileged --net=host \
xerxes-ultimate 192.168.1.100 80 1Gbps
./artaxerxes 192.168.1.100 80 100K_pps
./artaxerxes 192.168.1.100 80 1M_pps ./artaxerxes 192.168.1.100 80 10M_pps ./artaxerxes 192.168.1.100 80 50M_pps
**期待される学習成果:**
- パケット毎秒(pps)スケーリングの理解
- ハードウェアアクセラレーションの影響
- ネットワークボトルネックの特定
#### シナリオ2: テクノロジーティアの比較```bash
# Force different performance tiers
TIER=BASIC ./artaxerxes 192.168.1.100 80 30s
TIER=GPU ./artaxerxes 192.168.1.100 80 30s
TIER=DPDK ./artaxerxes 192.168.1.100 80 30s
TIER=ULTIMATE ./artaxerxes 192.168.1.100 80 30s
期待される学習成果:
./artaxerxes 192.168.1.100 80 1M_pps --randomize-source
./artaxerxes 192.168.1.100 80 --max-connections=100000
./artaxerxes 192.168.1.100 80 --ml-patterns --evasion-mode
### 高度な使用パターン
#### マルチターゲット負荷分散```bash
# Distribute load across multiple targets
./artaxerxes --config distributed.json
# Content of distributed.json:
{
"targets": [
{"host": "192.168.1.100", "port": 80, "weight": 0.4},
{"host": "192.168.1.101", "port": 80, "weight": 0.3},
{"host": "192.168.1.102", "port": 80, "weight": 0.3}
],
"total_rate": "10M_pps",
"duration": "300s"
}
./artaxerxese 192.168.1.100 443 --protocol=https --ssl-handshake
./artaxerxes 192.168.1.100 80 --protocol=tcp-syn --randomize-ports
./artaxerxes 192.168.1.100 53 --protocol=udp --amplification-payload
#### リアルタイムトラフィックシェーピング```bash
# Graduated load increase
./artaxerxes 192.168.1.100 80 --ramp-up="0-10M_pps,300s"
# Bursty traffic patterns
./artaxerxes 192.168.1.100 80 --burst-pattern="1M_pps,5s,100K_pps,10s"
# Bandwidth-aware testing
./artaxerxes 192.168.1.100 80 --target-bandwidth=5Gbps --max-bandwidth=10Gbps
echo "isolcpus=4-15" >> /boot/grub/grub.cfg
echo 2048 > /proc/sys/vm/nr_hugepages
echo 134217728 > /proc/sys/net/core/rmem_max echo 134217728 > /proc/sys/net/core/wmem_max
echo 2 > /proc/irq/24/smp_affinity # Isolate NIC interrupts
#### GPU 設定```bash
# Set GPU performance modes
nvidia-smi -pm 1 # Persistence mode
nvidia-smi -ac 1215,2100 # Max memory and GPU clocks
# Configure GPU memory mapping
export CUDA_VISIBLE_DEVICES=0,1,2,3
export CUDA_CACHE_DISABLE=1
./dpdk-devbind.py --bind=vfio-pci 0000:01:00.0
mkdir -p /mnt/huge mount -t hugetlbfs nodev /mnt/huge echo 1024 > /sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages
### 設定ファイル形式```yaml
# xerxes-ultimate.yml
global:
performance_tier: "auto" # auto, basic, gpu, dpdk, ultimate
thread_affinity: true
statistics_interval: 1.0
gpu:
device_count: 4
memory_per_device: "12GB"
stream_count: 8
block_size: 512
thread_per_block: 1024
network:
dpdk:
enabled: true
pci_whitelist: ["0000:01:00.0"]
memory_channels: 4
io_uring:
enabled: true
ring_size: 8192
batch_submit: 64
xdp:
enabled: false # Requires confirmation
interface: "eth0"
program: "ultimate_xdp.o"
attack:
default_payload_size: 1460
connection_pool_size: 1000000
randomization:
source_ip: true
source_port: true
user_agent: true
payload_content: true
monitoring:
real_time_stats: true
export_format: ["console", "json", "prometheus"]
detailed_logging: false
graph LR
subgraph "Performance Scaling"
A[1 Thread
50K PPS] --> B[8 Threads
400K PPS]
B --> C[32 Threads
1.2M PPS]
C --> D[+GPU
12M PPS]
D --> E[+DPDK
34M PPS]
E --> F[+XDP
61M PPS]
end
#### リソース使用率
| リソース | Xerxes Original | Xerxes-Ultimate | 効率向上 |
|----------|----------------|------------------|-----------------|
| **CPUコア** | 16コア @ 100% | 4コア @ 12% | **92%削減** |
| **メモリ帯域幅** | 12 GB/s | 156 GB/s | **13倍改善** |
| **PCIe帯域幅** | 0.1 GB/s | 48 GB/s | **480倍改善** |
| **ネットワーク使用率** | 0.1% | 64% | **640倍改善** |
### 比較分析
#### レイテンシ分布```
Original Xerxes:
├─ Min: 0.8ms
├─ Avg: 2.4ms
├─ P95: 4.1ms
└─ Max: 12.3ms
Xerxes-Ultimate:
├─ Min: 0.06ms
├─ Avg: 0.09ms
├─ P95: 0.12ms
└─ Max: 0.31ms
CPU: Intel i5-12400 or AMD Ryzen 5 5600X GPU: 1x RTX 3060 (12GB VRAM) RAM: 16GB DDR4-3200 Network: 1GbE with DPDK support Storage: 500GB NVMe SSD
#### 推奨セットアップ```yaml
CPU: Intel i7-13700 or AMD Ryzen 7 7700X
GPU: 2x RTX 4070 Ti (24GB total VRAM)
RAM: 32GB DDR5-5600
Network: 10GbE with SR-IOV support
Storage: 1TB NVMe SSD Gen4
CPU: Intel i9-13900K or AMD Ryzen 9 7900X GPU: 4x RTX 4090 (96GB total VRAM) RAM: 64GB DDR5-6000 Network: 100GbE Mellanox ConnectX-6 Storage: 2TB NVMe SSD Gen4 RAID-0
### ネットワークトポロジの例
#### 基本的なラボセットアップ```mermaid
graph TB
A[artaxerxes<br/>Attack Machine] --> B[1GbE Switch]
B --> C[Target Server #1<br/>Web Application]
B --> D[Target Server #2<br/>Database]
B --> E[Monitoring Server<br/>Traffic Analysis]
graph TB
subgraph "Attack Infrastructure"
A[artaxerxes #1
4x RTX 4090]
B[artaxerxes #2
4x RTX 4090]
C[artaxerxes #3
4x RTX 4090]
end
subgraph "Network Infrastructure"
D[100GbE Core Switch<br/>Mellanox Spectrum]
E[10GbE Distribution<br/>Access Layer]
F[1GbE Access<br/>End Devices]
end
subgraph "Target Environment"
G[Web Farm<br/>20x Servers]
H[Database Cluster<br/>5x Nodes]
I[Load Balencer<br/>F5 BIG-IP]
end
subgraph "Defense Testing"
J[DDoS Protection<br/>CloudFlare/Akamai]
K[WAF<br/>ModSecurity]
L[IDS/IPS<br/>Suricata]
end
A --> D
B --> D
C --> D
D --> E
E --> F
D --> I
I --> G
I --> H
J --> I
K --> G
L --> E
### Student Lab Exercises
#### Exercise 1: Performance Baseline```bash
# Students measure original Xerxes performance
time timeout 60s artaxerxes 192.168.1.100 80
# Then compare with artaxerxes basic tier
time timeout 60s ./artaxerxes 192.168.1.100 80 60s
学習目標: 最新の最適化技術の影響を定量化する。
for tier in BASIC IO_URING GPU DPDK ULTIMATE; do
echo "Testing $tier tier..."
FORCE_TIER=$tier ./artaxerxes 192.168.1.100 80 30s |
tee results_${tier}.log
done
./scripts/analyze-performance.py results_*.log
**学習目標**: 各テクノロジーがパフォーマンスにどのように貢献するかを理解する。
#### 演習3: 防御メカニズムの評価```bash
# Test against rate limiting
./artaxerxes 192.168.1.100 80 1M_pps 2>&1 | \
grep -E "(blocked|limited|denied)"
# Test evasion techniques
./artaxerxes 192.168.1.100 80 --evasion-mode --randomize-all
# Monitor defense effectiveness
./scripts/defense-analysis.py --target=192.168.1.100 --duration=300
学習目標: 防御的対策の評価と改善。
Week 1: "Network Performance Fundamentals"
Week 8: "Modern I/O Techniques"
Week 12: "High-Performance Networking"
#### サイバーセキュリティコース```yaml
Module 1: "Attack Vector Analysis"
- Traditional vs modern DoS techniques
- Volume-based vs sophisticated attacks
- Attack tool evolution and capabilities
Module 3: "Defense Strategy Development"
- Rate limiting effectiveness testing
- Pattern recognition and evasion
- Adaptive defense mechanisms
Module 5: "Threat Intelligence"
- Performance profiling of attack tools
- Infrastructure requirements analysis
- Attribution through tool capabilities
artaxerxes は、管理された実験室環境における教育目的専用に設計されています。このツールは以下の用途を意図しています:
✅ サイバーセキュリティの概念を教える 認可された学術環境で
✅ パフォーマンス最適化の技術を実演する
✅ 所有するインフラ上で防御メカニズムをテストする
✅ 適切な許可を得て認可されたペネトレーションテストを実施する
❌ 所有していないシステムへの不正なネットワーク攻撃
❌ 明示的な書面による許可のないサービス妨害
❌ あらゆる種類の悪意のある活動
❌ 適切なライセンスのない商業的利用
Xerxes-Ultimate の作者および貢献者は:
このツールを導入する教育機関は以下を行うべきです:
サイバーセキュリティ教育コミュニティからの貢献を歓迎します:
学術研究で artaxerxes を使用する場合は、引用してください:```bibtex @software{artaxerxes_2024, title={artaxerxes: Advanced Multi-Technology Stress Testing Framework}, author={tox4ny}, year={2024}, url={https://gitlab.com/tox4ny/ARTAXERXES}, note={Educational cybersecurity tool for high-performance network testing} }
---
## 📈 ロードマップ
### バージョン 2.1 (2024年第2四半期)
- [ ] **Intel Arc GPU サポート**: NVIDIA ハードウェアを超えた対応
- [ ] **ARM64 互換性**: Apple Silicon および ARM サーバーへの対応
- [ ] **コンテナオーケストレーション**: Kubernetes デプロイメントテンプレート
- [ ] **高度な回避**: ML ベースのペイロード生成
### バージョン 2.2 (2024年第3四半期)
- [ ] **量子乱数生成**: ハードウェアエントロピーソース
- [ ] **IPv6 フルサポート**: 最新のプロトコルスタックテスト
- [ ] **クラウド統合**: AWS/Azure/GCP デプロイメント自動化
- [ ] **リアルタイム可視化**: Web ベースの監視ダッシュボード
### バージョン 3.0 (2024年第4四半期)
- [ ] **分散アーキテクチャ**: マルチノード調整
- [ ] **高度な分析**: AI 搭載のトラフィック分析
- [ ] **プロトコルファジング**: 自動化された脆弱性発見
- [ ] **防御統合**: アクティブな対策テスト
---
**🚀 Xerxes-Ultimate でサイバーセキュリティ教育の未来を体験しましょう!**
*サイバーセキュリティ教育コミュニティのために ❤️ を込めて作られました*
| 指標 | 元のXerxes | Xerxes-Ultimate | 改善 |
|---|
| パケット/秒 | ~50,000 PPS | 60,000,000+ PPS | 🚀 1,200倍高速 |
| 帯域幅 | ~100 Mbps | 60+ Gbps | 🔥 600倍増加 |
| 同時接続数 | ~1,000 | 1,000,000+ | ⚡ 1,000倍増加 |
| CPU効率 | 100% CPU使用率 | <30% CPU使用率 | 💡 70%削減 |
| メモリ使用量 | 高い断片化 | 最適化されたプール | 🎯 90%効率的 |
| レイテンシ | ~1ms | <100ナノ秒 | ⚡ 10,000倍高速 |
| パフォーマンス層 | PPS | 帯域幅 | CPU使用率 | GPU使用率 | メモリ |
|---|
| Original Xerxes | 47,230 | 94 Mbps | 100% | 0% | 2.1 GB |
| BASIC | 127,450 | 254 Mbps | 95% | 0% | 1.8 GB |
| IO_URING | 1,340,000 | 2.68 Gbps | 78% | 0% | 2.4 GB |
| GPU | 12,700,000 | 15.2 Gbps | 23% | 67% | 18.2 GB |
| DPDK | 34,500,000 | 41.4 Gbps | 18% | 71% | 22.1 GB |
| ULTIMATE | 61,200,000 | 63.8 Gbps | 12% | 74% | 28.3 GB |