gossan-engine 0.3.3

High-performance stateless SYN scanner and banner grabber
docs.rs failed to build gossan-engine-0.3.3
Please check the build logs for more information.
See Builds for ideas on how to fix a failed build, or Metadata for how to configure docs.rs builds.
If you believe this is docs.rs' fault, open an issue.
Visit the last successful build: gossan-engine-0.3.2

gossan-engine

High-performance stateless SYN scanner and banner grabber, the masscan-class scan engine for the Gossan attack-surface scanner.

Architecture

  • netforge packet I/O (sendmmsg / pnet / AF_XDP backends)
  • Stateless cookie verification (no per-target state in TX)
  • Multi-threaded TX with CPU pinning, stride-partitioned Blackrock permutation, per-thread raw socket
  • Single shared RX thread with recvmmsg batched receive
  • Slash24 RST-burst backoff: when a /24 RSTs us above RST_BURST_THRESHOLD packets/sec the RX thread inserts the prefix into a 30-second backoff and TX threads silently skip probes against that subnet for the window. Surfaced as backoff_skipped in the scan-end log.
  • Banner grab + classify post-SYN-ACK with 500-way concurrency, routed through gossan-classify.

Throughput

  • 17 Mpps single-thread on a 5950X
  • 96–110 Mpps at 8 threads, NIC-bound thereafter
  • Scales linearly with TX threads up to ~8; beyond that softirq / ring contention dominates and AF_XDP (separate backend) is the next step.

Running

let scanner = gossan_engine::EngineScanner::new();
scanner.run(input, &config).await?;

CAP_NET_RAW (or root) required.

License

MIT