Class: AiRootShield::RaspProtection

Inherits:
Object
  • Object
show all
Defined in:
lib/ai_root_shield/rasp_protection.rb

Overview

Runtime Application Self-Protection (RASP) system Provides real-time protection against debugging, tampering, and injection attacks

Constant Summary collapse

RASP_EVENTS =

RASP event types for real-time reporting

{
  debug_attempt: "DEBUG_ATTEMPT_DETECTED",
  tamper_detected: "CODE_TAMPER_DETECTED", 
  injection_blocked: "INJECTION_ATTEMPT_BLOCKED",
  integrity_violation: "INTEGRITY_VIOLATION_DETECTED",
  memory_patch: "MEMORY_PATCH_DETECTED"
}.freeze

Instance Method Summary collapse

Constructor Details

#initialize(config = {}) ⇒ RaspProtection

Returns a new instance of RaspProtection.



19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
# File 'lib/ai_root_shield/rasp_protection.rb', line 19

def initialize(config = {})
  @config = {
    enable_anti_debug: true,
    enable_anti_tamper: true,
    enable_memory_protection: true,
    enable_integrity_monitor: true,
    enable_real_time_alerts: true,
    alert_callback: nil,
    critical_functions: [],
    protection_interval: 1.0
  }.merge(config)
  
  @event_callbacks = []
  @protection_active = false
  @integrity_hashes = {}
  @original_memory_maps = {}
  @protection_thread = nil
  @last_check_time = Time.now
  
  initialize_protection if @config[:enable_real_time_alerts]
end

Instance Method Details

#on_rasp_event(&block) ⇒ Object

Register callback for RASP events



75
76
77
# File 'lib/ai_root_shield/rasp_protection.rb', line 75

def on_rasp_event(&block)
  @event_callbacks << block if block_given?
end

#protection_status ⇒ Object

Check current protection status



80
81
82
83
84
85
86
87
88
89
90
# File 'lib/ai_root_shield/rasp_protection.rb', line 80

def protection_status
  {
    active: @protection_active,
    anti_debug_enabled: @config[:enable_anti_debug],
    anti_tamper_enabled: @config[:enable_anti_tamper],
    memory_protection_enabled: @config[:enable_memory_protection],
    integrity_monitor_enabled: @config[:enable_integrity_monitor],
    events_detected: @events_detected || 0,
    last_check: @last_check_time
  }
end

#start_protection ⇒ Object

Start RASP protection monitoring



42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# File 'lib/ai_root_shield/rasp_protection.rb', line 42

def start_protection
  return if @protection_active
  
  @protection_active = true
  
  # Initialize anti-debug protection
  setup_anti_debug_protection if @config[:enable_anti_debug]
  
  # Initialize anti-tamper protection
  setup_anti_tamper_protection if @config[:enable_anti_tamper]
  
  # Initialize memory protection
  setup_memory_protection if @config[:enable_memory_protection]
  
  # Initialize integrity monitoring
  setup_integrity_monitoring if @config[:enable_integrity_monitor]
  
  # Start real-time monitoring thread
  start_monitoring_thread
  
  report_rasp_event(:protection_started, "RASP protection activated")
end

#stop_protection ⇒ Object

Stop RASP protection monitoring



66
67
68
69
70
71
72
# File 'lib/ai_root_shield/rasp_protection.rb', line 66

def stop_protection
  @protection_active = false
  @protection_thread&.kill
  @protection_thread = nil
  
  report_rasp_event(:protection_stopped, "RASP protection deactivated")
end