Files

259 lines
14 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover">
<title>Threat Model &amp; Security Assumptions | ChronoSeal Documentation</title>
<meta name="description" content="ChronoSeal threat model, classification parameters, attacker categories, mitigations, and security boundaries.">
<link rel="stylesheet" href="css/chronoseal.css">
<link rel="stylesheet" href="css/docs.css">
<link rel="stylesheet" href="css/print.css" media="print">
<link rel="manifest" href="site.webmanifest">
<link rel="icon" href="assets/logo.svg" type="image/svg+xml">
<!-- Font Awesome for Icons -->
<link rel="preconnect" href="https://cdnjs.cloudflare.com" crossorigin />
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css"
integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw=="
crossorigin="anonymous"
referrerpolicy="no-referrer" />
</head>
<body>
<!-- Floating Background Spheres -->
<div class="bg-animation">
<div class="gradient-sphere sphere-1"></div>
<div class="gradient-sphere sphere-2"></div>
<div class="gradient-sphere sphere-3"></div>
</div>
<!-- Header / Navbar -->
<nav class="navbar" id="navbar">
<div class="nav-container">
<a href="index.html" class="logo">
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo">
<span>ChronoSeal</span>
</a>
<div class="nav-links" id="navLinks">
<a href="philosophy.html">Philosophy</a>
<a href="architecture.html">Architecture</a>
<a href="protocol.html">Protocol</a>
<a href="comparison.html">Comparison</a>
<div class="nav-dropdown">
<a href="#" class="nav-link">More <small>▼</small></a>
<div class="nav-dropdown-menu">
<a href="api.html">API Reference</a>
<a href="deployment.html">Deployment Guide</a>
<a href="operations.html">Operations Guide</a>
<a href="testing.html">Testing Strategy</a>
<a href="performance.html">Performance Tuning</a>
<a href="threat-model.html" class="active">Threat Model</a>
<a href="security.html">Security Policy</a>
<a href="privacy.html">Privacy Policy</a>
</div>
</div>
<button class="btn btn-ghost btn-sm btn-icon search-trigger" aria-label="Search" onclick="ChronoSearch.open()">
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24" width="16" height="16"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
</button>
<a href="https://github.com/thakares/chronoseal-rs" class="github-btn" target="_blank" rel="noopener">
<i class="fab fa-github"></i> GitHub
</a>
</div>
<button class="nav-toggle" id="menuBtn" aria-label="Toggle Navigation">
<i class="fas fa-bars"></i>
</button>
</div>
</nav>
<!-- Doc Page Shell -->
<div class="doc-page">
<div class="doc-layout">
<!-- Sidebar -->
<aside class="doc-sidebar">
<button class="doc-sidebar-toggle">
<i class="fas fa-bars"></i> Sidebar Menu
</button>
<div class="doc-nav-group">
<div class="doc-nav-label">Core Concepts</div>
<a href="philosophy.html" class="doc-nav-item">Design Philosophy</a>
<a href="architecture.html" class="doc-nav-item">Architecture Overview</a>
<a href="comparison.html" class="doc-nav-item">ChronoSeal vs Others</a>
</div>
<div class="doc-nav-group">
<div class="doc-nav-label">Protocol &amp; API</div>
<a href="protocol.html" class="doc-nav-item">Protocol Specification</a>
<a href="api.html" class="doc-nav-item">API Reference</a>
</div>
<div class="doc-nav-group">
<div class="doc-nav-label">Operations &amp; Security</div>
<a href="threat-model.html" class="doc-nav-item active">Threat Model</a>
<a href="security.html" class="doc-nav-item">Security Policy</a>
<a href="privacy.html" class="doc-nav-item">Privacy Policy</a>
<a href="performance.html" class="doc-nav-item">Performance Tuning</a>
</div>
<div class="doc-nav-group">
<div class="doc-nav-label">Lifecycle &amp; Dev</div>
<a href="deployment.html" class="doc-nav-item">Deployment Guide</a>
<a href="operations.html" class="doc-nav-item">Operations Handbook</a>
<a href="testing.html" class="doc-nav-item">Testing Strategy</a>
</div>
</aside>
<!-- Main Content Area -->
<main class="doc-main">
<nav class="doc-breadcrumb" aria-label="Breadcrumb">
<a href="index.html">Home</a>
<span class="sep">/</span>
<a href="#">Operations &amp; Security</a>
<span class="sep">/</span>
<span>Threat Model</span>
</nav>
<article class="doc-content">
<h1>ChronoSeal Threat Model &amp; Security Assumptions</h1>
<p class="doc-subtitle">ChronoSeal is a cost-raising session attestation layer. It makes API scraping and session replay attacks expensive by requiring continuous, stateful execution.</p>
<hr>
<h2>Security Objectives</h2>
<p>The system aims to achieve the following cryptographic and protocol protections:</p>
<ul>
<li>Reject replayed or out-of-order heartbeat payloads.</li>
<li>Reject heartbeats that do not maintain the exact server-issued synthetic gene mutation sequence.</li>
<li>Bind heartbeats to a browser-local Ed25519 session key.</li>
<li>Ensure basic HTTP clients (without JS/WASM engines) cannot pass validation.</li>
<li>Avoid detailed verification feedback via a silent failure model.</li>
<li>Ensure user privacy by avoiding long-term profiling or cross-site tracking.</li>
</ul>
<h2>Attacker Cost Model &amp; Classification</h2>
<p>We classify potential adversaries into four distinct capability tiers:</p>
<h3>Tier 1: Commodity HTTP Clients</h3>
<p><strong>Examples:</strong> <code>curl</code> requests, Python <code>requests</code>, Go scrapers, or scripts without browser execution capabilities.</p>
<p><strong>Status:</strong> <span class="check"><i class="fas fa-check-circle"></i> Fully Protected</span>. These clients cannot generate Ed25519 signatures, interpret the VM math challenges, or maintain the BLAKE3 hash-chain. They are rejected at the first check.</p>
<h3>Tier 2: Basic Headless Browsers</h3>
<p><strong>Examples:</strong> Out-of-the-box Puppeteer, Playwright, or Selenium setups.</p>
<p><strong>Status:</strong> <span class="times" style="color:var(--warning)"><i class="fas fa-exclamation-circle"></i> Partially Protected</span>. These engines can run JS and load the WASM runtime. However, the attacker must simulate plausible interaction paths, maintain state, and solve VM challenges. This imposes substantial CPU and memory overhead on the automation runner, rendering large-scale automated scraping expensive.</p>
<h3>Tier 3: Stealth Automation</h3>
<p><strong>Examples:</strong> Patched browser binaries, custom Node.js scripts using mock variables, or WASM emulator state runners.</p>
<p><strong>Status:</strong> <span class="times" style="color:var(--warning)"><i class="fas fa-exclamation-circle"></i> Partially Protected</span>. Attackers must implement the complete state progression model. The server-controlled Synthetic Gene Mutation Engine forces emulator scripts to execute matching dynamic programs. Silent rejection hides which validation failed, complicating debugging.</p>
<h3>Tier 4: Distributed Browser Farms</h3>
<p><strong>Examples:</strong> Clusters of real browsers, custom input hardware simulators, or human-operated CAPTCHA solvers.</p>
<p><strong>Status:</strong> <span class="times"><i class="fas fa-times-circle"></i> Unprotected</span>. ChronoSeal raises execution costs but cannot guarantee complete protection against real user machines. Additional application-level access gating is required.</p>
<h2>Attack Vectors &amp; Mitigations</h2>
<h3>1. Replay Attacks</h3>
<p><strong>Attack:</strong> Intercepting a successful client heartbeat and sending it again to keep a session alive.</p>
<p><strong>Mitigation:</strong> The server checks if the request's <code>prev_hash</code> matches the stored <code>last_hash</code>. Since accepted heartbeats rotate the salt and advance the hash, a repeated payload is immediately discarded as stale. Step counts and timestamp drift bounds also block historical replays.</p>
<h3>2. Signature Forgery</h3>
<p><strong>Attack:</strong> Generating heartbeats without possessing the session's private key.</p>
<p><strong>Mitigation:</strong> All heartbeats are signed using the Ed25519 key generated locally in the WASM engine. The server validates the signature against the registered public key before processing.</p>
<h3>3. Mutation Spoofing</h3>
<p><strong>Attack:</strong> Submitting fake gene commitments or bypassing mutation rounds.</p>
<p><strong>Mitigation:</strong> The server keeps the authoring program of the pending mutation. It applies the program to a clone of the session's committed gene state and asserts that the client's submitted commitment matches, failing silently on divergence.</p>
<h3>4. Feedback Oracle Probing</h3>
<p><strong>Attack:</strong> Eliciting detailed error reasons (e.g. "invalid signature", "limiter triggered") to reverse-engineer verification thresholds.</p>
<p><strong>Mitigation:</strong> Heartbeat endpoints always return <code>200 OK</code> with a standard <code>status: ok</code> JSON shape on failure. Accepted responses are distinguished only by containing next-state keys (<code>next_salt</code>, etc.).</p>
<h2>Key Security Invariants</h2>
<p>The system guarantees the following invariants to preserve attestation integrity:</p>
<ul>
<li><strong>Single Sequence:</strong> A session can have exactly one expected step at any time. Bifurcation is impossible.</li>
<li><strong>VM Parity:</strong> Stack results must exactly match server re-execution of the VM opcodes.</li>
<li><strong>Locking:</strong> Session changes use Compare-And-Swap (CAS) optimistic locking to prevent race conditions.</li>
</ul>
<div class="doc-alert doc-alert--warn">
<div class="doc-alert-icon">⚠️</div>
<div class="doc-alert-body">
<strong>v1.0.2 Hardening:</strong> We enforce strict CPU concurrency limits (1 to 256), DPR boundaries, aspect ratio validations, and an entropy event cap (max 500 events) to prevent server resource exhaustion attacks.
</div>
</div>
</article>
<!-- Pager -->
<nav class="doc-pager" aria-label="Doc navigation Pager">
<a href="api.html" class="doc-pager-link">
<div class="doc-pager-label">Previous</div>
<div class="doc-pager-title">API Reference</div>
</a>
<a href="performance.html" class="doc-pager-link doc-pager-link--next">
<div class="doc-pager-label">Next</div>
<div class="doc-pager-title">Performance Tuning</div>
</a>
</nav>
<div class="doc-meta">
Last Updated: June 2026 (v1.0.2)
</div>
</main>
</div>
</div>
<!-- Footer -->
<footer class="footer">
<div class="footer-content">
<div class="footer-section">
<h4>
<img class="logobar" src="assets/logo.svg" alt="ChronoSeal Logo" style="width: 24px; height: 24px; vertical-align: middle;"> ChronoSeal
</h4>
<p>Next-generation browser attestation daemon built for the modern web.</p>
</div>
<div class="footer-section">
<h4>Resources</h4>
<a href="philosophy.html">Design Philosophy</a>
<a href="architecture.html">Architecture</a>
<a href="protocol.html">Protocol</a>
<a href="api.html">API Reference</a>
<a href="comparison.html">Comparison</a>
</div>
<div class="footer-section">
<h4>Community</h4>
<a href="https://github.com/thakares/chronoseal-rs" target="_blank" rel="noopener"><i class="fab fa-github"></i> GitHub</a>
<a href="deployment.html"><i class="fas fa-rocket"></i> Deployment</a>
<a href="testing.html"><i class="fas fa-vial"></i> Testing</a>
</div>
<div class="footer-section">
<h4>Legal &amp; Security</h4>
<a href="security.html">Security Policy</a>
<a href="privacy.html">Privacy Policy</a>
<a href="performance.html">Performance Tuning</a>
<a href="operations.html">Operations Guide</a>
</div>
</div>
<div class="footer-bottom">
<p>&copy; 2026 ChronoSeal Project. Built with 🦀 Rust and ❤️ for open source.</p>
</div>
</footer>
<!-- Search Overlay -->
<div class="search-overlay">
<div class="search-box">
<div class="search-input-wrap">
<svg fill="none" stroke="currentColor" stroke-width="2" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" d="M21 21l-6-6m2-5a7 7 0 11-14 0 7 7 0 0114 0z"></path></svg>
<input type="text" class="search-input" placeholder="Search documentation... (Esc to close)">
<span class="search-kbd">/</span>
</div>
<div class="search-results"></div>
</div>
</div>
<!-- Back to top -->
<a href="#" class="back-to-top" aria-label="Back to top">▲</a>
<!-- JS Scripts -->
<script src="js/search.js"></script>
<script src="js/app.js"></script>
</body>
</html>