Skip to content
Β 
Β 

Latest commit

Β 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

KryptonOS - Zero-Trust Host Access Controller

KryptonOS is a high-performance, lightweight Zero-Trust Host Access Controller (ZT-HAC) designed primarily for Linux with Windows support through conditional compilation. It implements a strict "default-deny" security model for network sockets, process execution, and USB device mounting, controlled by a native lightweight desktop interface built with Slint.

πŸ—οΈ Architecture

Unified Rust Application

  • Single Binary: Combines security engine and native UI in one optimized executable
  • Security Engine: High-performance monitoring loops using Tokio async runtime
  • State Storage: Embedded Sled key-value database for policies and whitelists
  • Native UI: Lightweight Slint framework (8MB RAM footprint vs 300+MB for Electron/Chrome)
  • Cross-Platform: #[cfg(target_os = "linux")] / #[cfg(target_os = "windows")] abstraction
  • Zero Web Dependencies: No Node.js, no Chromium, no bloat

Core Components

  1. Security Monitoring Engine - Kernel-level interception of:

    • Process creation/execution (fork/execve monitoring)
    • Network socket operations (bind/connect monitoring)
    • USB device mounting/unmounting
    • File system access (extensible)
  2. Policy Engine - Sled-backed rule evaluation with:

    • Default-deny security model
    • Dynamic whitelist/blacklist management
    • Just-in-Time (JIT) access approvals
    • Audit trail cryptographic logging
  3. Native Control Center - Slint-based UI featuring:

    • System security status toggle (Default-Deny ↔ Bypass)
    • Real-time security events grid (process/network/device)
    • Interactive JIT response controls (Approve/Temp Allow/Terminate)
    • Dark/light theme adaptation
    • Optimized for 800x600+ resolution displays

πŸ“¦ Platform-Specific Installation

🐧 Linux Installation (Ubuntu/Debian/Kali/Arch/CachyOS)

Prerequisites

# Install Rust toolchain (required for all distributions)
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"

# Distribution-specific build dependencies
# Ubuntu/Debian/Kali:
sudo apt update && sudo apt install -y build-essential pkg-config libssl-dev

# Arch/CachyOS:
sudo pacman -S --needed base-devel pkgconf openssl

# Optional but recommended for development:
# sudo apt install -y git clang llvm gdb  # Ubuntu/Debian
# sudo pacman -S --needed git clang llvm gdb  # Arch

Step-by-Step Installation

Option 1: Automated Installation (Recommended)

# 1. Clone the repository
git clone https://github.com/AceBreaker-cell/KryptoOS.git
cd KryptoOS

# 2. Make installer executable and run it
chmod +x scripts/install.sh
sudo ./scripts/install.sh

# 3. The installer will:
#    - Build the application with release optimizations
#    - Create system user/group (kryptonos:kryptonos)
#    - Install binary to /opt/kryptonos/kryptonos
#    - Set required Linux capabilities (net_admin, net_raw, sys_ptrace, dac_override)
#    - Create and start systemd service
#    - Install desktop entry to /usr/share/applications/

Option 2: Manual Installation

# 1. Clone and build
git clone https://github.com/AceBreaker-cell/KryptoOS.git
cd KryptoOS
cargo build --release  # Produces target/release/kryptonos

# 2. Create system user and group
sudo groupadd --system kryptonos
sudo useradd --system --gid kryptonos --no-create-home --shell /usr/sbin/nologin kryptonos

# 3. Create directory structure
sudo mkdir -p /opt/kryptonos /var/log/kryptonos /var/lib/kryptonos /var/run/kryptonos /etc/kryptonos
sudo chown -R kryptonos:kryptonos /opt/kryptonos /var/log/kryptonos /var/lib/kryptonos /var/run/kryptonos /etc/kryptonos

# 4. Install binary
sudo cp target/release/kryptonos /opt/kryptonos/
sudo chown kryptonos:kryptonos /opt/kryptonos/kryptonos
sudo chmod 750 /opt/kryptonos/kryptonos

# 5. Set Linux capabilities (required for interception)
sudo setcap cap_net_admin,cap_net_raw,cap_sys_ptrace,cap_dac_override+ep /opt/kryptonos/kryptonos

# 6. Create systemd service
sudo tee /etc/systemd/system/kryptonos.service > /dev/null << EOF
[Unit]
Description=KryptonOS Zero-Trust Host Access Controller
After=network.target auditd.service
Wants=network.target

[Service]
Type=notify
User=kryptonos
Group=kryptonos
ExecStart=/opt/kryptonos/kryptonos
PIDFile=/var/run/kryptonos/kryptonos.pid
Restart=on-failure
RestartSec=5
PrivateTmp=yes
ProtectSystem=strict
ProtectHome=yes
NoNewPrivileges=yes
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_PTRACE CAP_DAC_OVERRIDE
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW CAP_SYS_PTRACE CAP_DAC_OVERRIDE
SystemCallFilter=@system-service
SystemCallError=EPERM
MemoryLimit=50M
CPUQuota=20%
StandardOutput=journal
StandardError=journal

[Install]
WantedBy=multi-user.target
EOF

# 7. Enable and start service
sudo systemctl daemon-reload
sudo systemctl enable kryptonos.service
sudo systemctl start kryptonos.service

# 8. (Optional) Install desktop environment integration
sudo cp kryptonos-ui/src/assets/logo.png /usr/share/pixmaps/kryptonos.png 2>/dev/null || echo "Note: Logo will be embedded in binary UI"
sudo tee /usr/share/applications/kryptonos.desktop > /dev/null << EOF
[Desktop Entry]
Name=KryptonOS
Comment=Zero-Trust Host Access Controller
Exec=/opt/kryptonos/kryptonos
Icon=kryptonos
Terminal=false
Type=Application
Categories=System;Security;
StartupNotify=true
EOF

Post-Installation Verification

# Check service status
sudo systemctl status kryptonos.service

# View logs in real-time
sudo journalctl -u kryptonos.service -f

# Verify binary capabilities
ls -la /opt/kryptonos/kryptonos
getcap /opt/kryptonos/kryptonos
# Should show: /opt/kryptonos/kryptonos = cap_net_admin,cap_net_raw,cap_sys_ptrace,cap_dac_override+ep

# Launch UI (should auto-start with service, or run manually)
/opt/kryptonos/kryptonos  # Will show native interface

Distribution-Specific Notes

  • CachyOS/Arch: The package includes optimized -march=x86-64-v3 flags via Rust's native CPU detection
  • Kali Linux: Pre-configured with necessary kernel headers for potential eBPF development
  • Ubuntu LTS: Fully tested on 22.04 and 24.04
  • SELinux/AppArmor: Service profile includes strict confinement; may need policy adjustments on enforced systems

πŸ’Ώ Windows Installation

Prerequisites

  1. Rust Toolchain:

    • Download and install rustup
    • Restart terminal after installation
  2. Build Tools:

  3. Optional Development Tools:

    • Git for Windows
    • Windows Terminal or PowerShell 7+

Step-by-Step Installation

Building from Source

# 1. Clone repository (using Git Bash, PowerShell, or Windows Terminal)
git clone https://github.com/albatany/KryptoOS.git
cd KryptoOS

# 2. Build for release (optimized for size and performance)
cargo build --release

# 3. The binary will be located at:
#    target\release\kryptonos.exe

Creating Windows Service

# 1. Copy binary to permanent location
$installDir = "C:\Program Files\KryptonOS"
New-Item -ItemType Directory -Path $installDir -Force
Copy-Item -Path "target\release\kryptonos.exe" -Destination "$installDir\kryptonos.exe"

# 2. Create service using PowerShell (run as Administrator)
$serviceName = "KryptonOS"
$binaryPath = "$installDir\kryptonos.exe"

# Create the service
New-Service -Name $serviceName -BinaryPathName "`"$binaryPath`"" -DisplayName "KryptonOS Zero-Trust Host Access Controller" -Description "Enterprise Zero-Trust security agent with default-deny policy enforcement" -StartupType Automatic

# 3. Configure service recovery and restrictions
sc.exe failure $serviceName reset= 86400 actions= restart/5000/restart/10000/restart/15000/
sc.exe sidtype $serviceName unrestricted
sc.exe privs $serviceName SeAuditPrivilege/SeChangeNotifyPrivilege/SeCreateGlobalPrivilege/SeIncreaseQuotaPrivilege/SeSystemtimePrivilege/SeTimeZonePrivilege

# 4. Start the service
Start-Service -Name $serviceName

Manual Execution (Testing/Development)

# Run directly from build directory (requires Administrator for full features)
& "target\release\kryptonos.exe"

# Or from installed location
& "C:\Program Files\KryptonOS\kryptonos.exe"

Windows-Specific Notes

  • Feature Parity: Core security monitoring (process, network, device) works on Windows 10/11
  • Interception Mechanisms: Uses Windows Filtering Platform (WFP) and Process Monitor callbacks
  • Privileges: Requires Administrator for installation; runs as Local Service with adjusted privileges
  • Compatibility: Tested on Windows 10 22H2 and Windows 11 23H2
  • Antivirus: May trigger heuristic scans; add exclusion for kryptonos.exe in AV software
  • Updates: Use standard Windows service update procedures or redeploy binary and restart service

Verification on Windows

# Check service status
Get-Service -Name KryptonOS

# View logs (if using EventLog sink or file logging)
Get-WinEvent -LogName Application -Source KryptonOS | Select-Object -First 20

# Or check console output if running manually
# The application logs to stdout/stderr when not running as service

πŸ”§ Configuration and Usage

First Launch

  1. Linux: Service starts automatically on boot; UI accessible via application menu or kryptonos command
  2. Windows: Service starts automatically; UI accessible from Start Menu or by running kryptonos.exe

Using the Control Center

  • Master Toggle: Switch between "Default-Deny (Protected)" and "Bypass Mode" (use bypass only for troubleshooting)
  • Security Events Grid: Shows real-time intercepted operations with:
    • Process name and action (e.g., "chrome.exe - Network Connection")
    • Target (IP:port, file path, device ID)
    • Timestamp and status (πŸ”΄ Blocked, 🟒 Allowed, 🟑 Pending)
  • JIT Response Popup: When an operation is blocked:
    • Approve Permanently: Add to whitelist forever
    • Temp Allow (15m): Temporary whitelist with automatic expiry
    • Terminate Process: Forcefully end the triggering process
  • Audit Trail: All actions cryptographically logged to local database

Advanced Configuration

  • Data Location:
    • Linux: /var/lib/kryptonos/ (rules.db, logs/)
    • Windows: %PROGRAMDATA%\KryptonOS\
  • Custom Rules: Modify through UI or directly edit Sled database (advanced users)
  • Logging Level: Adjust via environment variable RUST_LOG=info,kryptonos=debug

πŸ›‘οΈ Security Model Deep Dive

Zero-Trust Principles Implemented

  1. Implicit Distrust: No process, network connection, or device is trusted by default
  2. Continuous Verification: Every operation undergoes real-time policy evaluation
  3. Least Privilege Access: Permissions granted minimally and for shortest necessary duration
  4. Assume Breach: Monitoring assumes hostile intent and validates all behavior
  5. Micro-Segmentation: Fine-grained control per process/action/target combination

Protection Mechanisms

  • Network Layer: Blocks unauthorized outbound/inbound connections at socket level
  • Process Layer: Prevents unauthorized executable launches and DLL injections
  • Device Layer: Controls USB and peripheral mounting/enumeration
  • File Layer: (Extensible) Monitors sensitive file access patterns
  • Privilege Layer: Prevents privilege escalation through monitored syscalls

Response Actions

Action Description Persistence Use Case
Allow Permits operation Session-only Trusted known-good operations
Block Prevents operation Session-only Clearly malicious/intended blocks
Approve Permanently Adds to whitelist Forever Legitimate business applications
Temp Allow (15m) Time-limited whitelist 15 minutes Temporary troubleshooting/access
Terminate Process Force ends process Immediate Active malware/ransomware response

🐳 Performance Characteristics

Resource Footprint (Typical Deployment)

  • Memory Usage: 8-15 MB RSS (Resident Set Size)
  • CPU Usage: <2% average on idle system, <15% during active event processing
  • Disk I/O: Minimal (<50 KB/s steady state, spikes during bulk policy updates)
  • Binary Size: ~3.5 MB stripped release build (vs 50+ MB for Electron alternatives)

Optimization Features

  • Size Optimizations: opt-level = "z", LTO, codegen-units = 1
  • Runtime Efficiency:
    • Async Tokio event loop with minimal allocations
    • Bounded event storage (last 100 events only)
    • Zero-copy data structures where possible
    • Efficient Sled B-tree database access
  • Security Hardening:
    • Stack smashing protection
    • Fortify source (panic = "abort" eliminates unwinding tables)
    • Symbol stripping (strip = true)
    • Reduced attack surface (no JS engine, no browser)

πŸ”„ Extending KryptonOS

Adding New Interception Points

  1. Linux: Implement in src/interceptors/linux.rs using:
    • eBPF (via redbpf or aya crates)
    • Netfilter/nftables hooks
    • Audit subsystem
    • LSM hooks (requires kernel module)
  2. Windows: Implement in src/interceptors/windows.rs using:
    • Windows Filtering Platform (WFP) callouts
    • Process and thread notification routines
    • Registry and file system minifilters
    • ETW (Event Tracing for Windows) providers

Adding New Policy Types

  1. Extend RuleType enum in src/security_policy.rs
  2. Add corresponding fields to RuleCriteria struct
  3. Implement evaluation logic in src/policy.rs
  4. Add UI controls in src/ui.slint (if user-facing)
  5. Update IPC protocol if remote configuration needed

Customizing the UI

  • Modify src/ui.slint for layout/theme changes
  • Adjust color palette in Slint theme variables
  • Add new widgets/components as needed
  • Rebuild with cargo build --release

πŸ“œ Licensing

KryptonOS is dual-licensed to maximize flexibility:

MIT License

Copyright (c) 2024 KryptonOS Project

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
DEALINGS IN THE SOFTWARE.

OR Apache License 2.0

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

⚠️ Important Notes and Disclaimers

Supported Platforms

  • Primary: Linux (kernel 5.4+ recommended for eBPF features)
  • Secondary: Windows 10 1809+ / Windows 11 (WSL2 also supported)
  • Experimental: macOS (limited interception capabilities)

Production Readiness

This implementation provides a solid foundation for Zero-Trust security. For enterprise production deployment, consider:

  1. Network Integration: Centralized policy management via REST/gRPC API
  2. Logging Forwarding: SIEM integration (Syslog/JSON over TLS)
  3. Update Scheduling: Automated binary version checking and deployment
  4. Hardening: FIPS 140-2 validated cryptography modules (if required)
  5. Compliance: Validation against SOC 2, ISO 27001, NIST 800-53, etc.

Legal and Ethical Use

  • Deploy only on systems you own or have explicit authorization to monitor
  • Comply with all applicable laws regarding surveillance and data privacy
  • Inform end-users of monitoring where legally required
  • Securely handle and retain audit logs per organizational policy
  • Regularly review and update security policies to minimize false positives

Known Limitations

  • Windows: Some advanced interception (e.g., kernel callbacks) require test signing mode in development
  • Virtualization: May require nested virtualization enabled in certain VM/cloud environments
  • Performance: Extreme high-frequency trading systems may need kernel-bypass tuning
  • Compatibility: Conflict possible with other security software (AV, HIPS, EDR) - test in staging

🀝 Community and Support

Contributing

We welcome contributions! Please see:

Getting Help

  • Documentation: This README and inline code comments
  • Issue Tracker: GitHub Issues for bug reports and feature requests
  • Discussions: GitHub Discussions for questions and ideas
  • Security: security@kryptonos.org for vulnerability reports

Citation

If you use KryptonOS in research or production, please cite:

@software{kryptonos2024,
  title = {KryptonOS: Zero-Trust Host Access Controller},
  author = {The KryptonOS Project},
  year = {2024},
  url = {https://github.com/albatany/KryptoOS}
}

Last updated: October 2026 | Version: 0.1.0
Built with Rust 1.78.0 | Slint 1.3.0 | Sled 0.34.0

About

Zero-Trust Host Access Controller

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages