数据源管理
rho-aias 支持多种规则来源,包括威胁情报订阅、地域封禁数据库等,通过统一的接口管理所有数据源。
概述
威胁情报
威胁情报源提供已知的恶意 IP/CIDR 列表,自动订阅更新。
配置
yaml
intel:
enabled: true
auto_refresh_on_start: true # 启动时自动刷新
persistence_dir: ./data/intel # 持久化目录
batch_size: 1000 # 批量写入大小
sources:
ipsum:
enabled: true
periodic: true # 周期性更新
schedule: "0 1 * * *" # 每天凌晨 1 点
url: https://example.com/ipsum.txt
format: ipsum
spamhaus:
enabled: true
periodic: true
schedule: "0 2 * * *" # 每天凌晨 2 点
url: https://www.spamhaus.org/drop/drop.txt
format: spamhaus支持的情报源
| 名称 | 格式 | 说明 | 规则数量 |
|---|---|---|---|
| IPSum | ipsum | 聚合多个威胁情报源 | ~23 万条 |
| Spamhaus DROP | spamhaus | 垃圾邮件黑名单 | ~1500 条 |
数据格式
IPSum 格式
# 注释行
1.2.3.4 500
5.6.7.8 300每行格式:IP [置信度]
Spamhaus DROP 格式
; 注释行
1.0.0.0/24 ; SBL12345
2.0.0.0/8 ; SBL67890每行格式:CIDR ; 备注
API 接口
获取情报源状态
bash
GET /api/intel/status响应:
json
{
"enabled": true,
"sources": {
"ipsum": {
"enabled": true,
"rule_count": 230000,
"last_update": "2026-03-28T01:00:00Z",
"next_update": "2026-03-29T01:00:00Z",
"status": "active"
},
"spamhaus": {
"enabled": true,
"rule_count": 1500,
"last_update": "2026-03-28T02:00:00Z",
"status": "active"
}
},
"total_rules": 231500
}手动触发更新
bash
POST /api/intel/update地域封禁
基于 MaxMind GeoIP 数据库实现国家/地区级别的访问控制。
配置
yaml
geo_blocking:
enabled: true
auto_refresh_on_start: true
mode: whitelist # whitelist 或 blacklist
allowed_countries:
- CN # 中国
- US # 美国
allow_private_networks: true # 允许私有网段
persistence_dir: ./data/geo
batch_size: 1000
sources:
maxmind:
enabled: true
periodic: true
schedule: "0 3 * * *" # 每天凌晨 3 点
url: https://example.com/GeoLite2-Country.mmdb
format: maxmind-db工作模式
白名单模式 (whitelist)
仅允许指定国家的流量:
yaml
geo_blocking:
mode: whitelist
allowed_countries:
- CN # 仅允许中国黑名单模式 (blacklist)
封禁指定国家的流量:
yaml
geo_blocking:
mode: blacklist
allowed_countries: # 此处实际为封禁列表
- KP # 封禁朝鲜
- IR # 封禁伊朗私有网络绕过
yaml
geo_blocking:
allow_private_networks: true启用后,以下网段将绕过地域检查:
10.0.0.0/8172.16.0.0/12192.168.0.0/16127.0.0.0/8169.254.0.0/16- IPv6 私有地址
API 接口
获取地域封禁状态
bash
GET /api/geoblocking/status响应:
json
{
"enabled": true,
"mode": "whitelist",
"allowed_countries": ["CN", "US"],
"allow_private_networks": true,
"rule_count": 50000,
"last_update": "2026-03-28T03:00:00Z",
"source": {
"name": "maxmind",
"status": "active"
}
}手动触发更新
bash
POST /api/geoblocking/update更新配置
bash
POST /api/geoblocking/config请求体:
json
{
"mode": "whitelist",
"allowed_countries": ["CN", "US", "JP"]
}统一数据源 API
获取所有数据源状态
bash
GET /api/sources/status响应:
json
{
"sources": [
{
"type": "intel",
"id": "ipsum",
"enabled": true,
"last_update": "2026-03-28T01:00:00Z",
"rule_count": 230000,
"status": "active"
},
{
"type": "intel",
"id": "spamhaus",
"enabled": true,
"last_update": "2026-03-28T02:00:00Z",
"rule_count": 1500,
"status": "active"
},
{
"type": "geo",
"id": "maxmind",
"enabled": true,
"last_update": "2026-03-28T03:00:00Z",
"rule_count": 50000,
"status": "active"
}
]
}获取指定类型数据源
bash
GET /api/sources/:type/status:type=intel或geo
获取指定数据源
bash
GET /api/sources/:type/:id/status示例:
bash
GET /api/sources/intel/ipsum/status手动触发刷新
bash
POST /api/sources/:type/:id/refresh示例:
bash
curl -X POST -H "Authorization: Bearer <token>" \
http://localhost:8081/api/sources/intel/ipsum/refresh持久化机制
离线启动支持
数据源支持本地持久化,实现离线启动:
持久化目录结构
./data/
├── intel/
│ ├── ipsum.json # IPSum 缓存
│ └── spamhaus.json # Spamhaus 缓存
├── geo/
│ ├── maxmind.json # GeoIP 规则缓存
│ └── GeoLite2-Country.mmdb # MMDB 文件
└── manual/
├── rules.json # 黑名单规则
└── whitelist.json # 白名单规则规则来源位掩码
多源规则通过位掩码实现聚合管理:
| 来源 | 位掩码 | 十六进制 |
|---|---|---|
| IPSum | Bit 0 | 0x01 |
| Spamhaus | Bit 1 | 0x02 |
| 手动规则 | Bit 2 | 0x04 |
| WAF 联动 | Bit 3 | 0x08 |
| DDoS 防护 | Bit 4 | 0x10 |
| 频率限制 | Bit 5 | 0x20 |
| 异常检测 | Bit 6 | 0x40 |
| SSH 防爆破 | Bit 7 | 0x80 |
白名单说明
IP 白名单已从位掩码机制中分离,不再占用位掩码位。白名单使用独立的 eBPF Map 存储,具有最高优先级,直接放行。
聚合示例
某 IP 同时被 IPSum 和 WAF 封禁:
source_mask = 0x01 | 0x08 = 0x09 (二进制 00001001)某 IP 同时被手动规则、WAF 和 FailGuard 封禁:
source_mask = 0x04 | 0x08 | 0x80 = 0x8C (二进制 10001100)解除封禁逻辑
最佳实践
1. 更新时间错开
避免多个数据源同时更新:
yaml
intel:
sources:
ipsum:
schedule: "0 1 * * *" # 凌晨 1 点
spamhaus:
schedule: "0 2 * * *" # 凌晨 2 点
geo_blocking:
sources:
maxmind:
schedule: "0 3 * * *" # 凌晨 3 点2. 离线环境部署
在内网环境部署时,可将数据文件托管到内部服务器:
yaml
intel:
sources:
ipsum:
url: http://internal-server/ipsum.txt3. 监控数据源状态
定期检查更新状态和规则数量:
bash
# 定时任务检查
curl -s http://localhost:8081/api/sources/status | jq '.sources[] | select(.status != "active")'4. 测试新数据源
添加新数据源前建议:
- 先在测试环境验证格式兼容性
- 检查规则数量是否合理
- 观察对性能的影响
5. 数据源优先级
规则生效优先级(从高到低):
- 白名单 - 最高优先级,直接放行
- 黑名单 - 各种来源的封禁规则
- 地域封禁 - 国家级别过滤
- 默认放行 - 未匹配任何规则