Skip to main content

ferrox_security/
mtd.rs

1use std::sync::RwLock;
2use std::time::{Duration, Instant};
3use rand::Rng;
4
5/// Moving Target Defense (MTD) Cryptographic Key & Seed Shuffler
6/// Periodically mutates internal signature seeds to invalidate black-box adversarial probing.
7pub struct MovingTargetDefense {
8    current_seed: RwLock<u64>,
9    last_mutation: RwLock<Instant>,
10    mutation_interval: Duration,
11}
12
13impl MovingTargetDefense {
14    pub fn new(mutation_interval_secs: u64) -> Self {
15        let mut rng = rand::thread_rng();
16        Self {
17            current_seed: RwLock::new(rng.gen()),
18            last_mutation: RwLock::new(Instant::now()),
19            mutation_interval: Duration::from_secs(mutation_interval_secs),
20        }
21    }
22
23    /// Mutates seed if interval expired. Returns current active MTD seed.
24    pub fn get_active_seed(&self) -> u64 {
25        let now = Instant::now();
26        let mut last = self.last_mutation.write().unwrap();
27
28        if now.duration_since(*last) >= self.mutation_interval {
29            let mut rng = rand::thread_rng();
30            let mut seed = self.current_seed.write().unwrap();
31            *seed = rng.gen();
32            *last = now;
33        }
34
35        *self.current_seed.read().unwrap()
36    }
37}