SELF-HOSTED SECURITY · PRE-1.0

การป้องกันบอตที่เก็บการตัดสินใจเรื่องความเชื่อถือ ไว้บนเซิร์ฟเวอร์ของคุณเอง

2IZI Guard ปกป้องฟอร์มและการกระทำสาธารณะด้วยการประเมินความเสี่ยงภายในระบบ friction แบบปรับตัว และ token อนุญาตจากเซิร์ฟเวอร์แบบใช้ครั้งเดียว โดยไม่บังคับใช้ CAPTCHA ภายนอก

Core ไม่บังคับพึ่งพา Google, Yandex, Cloudflare, API ภายนอก, CDN หรือ telemetry ของบุคคลที่สาม
PHP 8.1+AdaptiveShadow ModePrivacy-first
2IZI Guardlocal decision surface
actionregister
origin2iziguard.com
sessionbound
modeAdaptive
local risk18/100
PASSsilent
01
Context
02
Risk
03
Challenge
04
Token
05
Consume
0required third-party calls
256-bitopaque token
HMACstate integrity
atomic consume
0required outbound runtime calls
256-bitopaque token entropy
action / session / origin bound
atomic one-time consume
สำหรับการกระทำของแอป

ความปลอดภัยคือการตัดสินใจของเซิร์ฟเวอร์ ไม่ใช่สถานะของ widget

challenge ที่มองเห็นเป็นเพียงหนึ่งชั้น Guard ปกป้อง server action ก่อนทำงานธุรกิจ

ทำงานภายในเป็นค่าเริ่มต้น

การประเมินความเสี่ยง challenge และ authorization อยู่ภายในโปรเจกต์

สิทธิ์อยู่ที่เซิร์ฟเวอร์

JavaScript สำเร็จไม่เท่ากับ authorization เซิร์ฟเวอร์ตรวจและ consume Guard token

Friction แบบปรับตัว

traffic ที่เชื่อถือได้ผ่านได้เงียบ ๆ ส่วนความเสี่ยงสูงอาจใช้ PoW, hold, throttle หรือ deny

Velocity-aware

สามารถรวม limit จาก network, Guard session, account, action และ site-wide context

Privacy-first

IP และ browser signals ไม่ใช่ identity และปิด invasive fingerprinting โดยค่าเริ่มต้น

อธิบายการตัดสินใจได้

Risk Engine เก็บ reason codes และ Shadow Mode predictions สำหรับ tuning

ทำงานอย่างไร

หนึ่ง action ที่ป้องกัน ห้าจุดตรวจอิสระ

Browser อาจมีส่วนใน challenge แต่ business permission ออกและ consume โดยเซิร์ฟเวอร์เสมอ

01

ตรวจ context

ตรวจ Origin, action, session และ limits พื้นฐานก่อนงานที่มีต้นทุนสูง

02

ประเมินภายใน

สัญญาณจาก server และ application สร้าง risk decision ที่อธิบายได้

03

เพิ่ม friction

Policy เลือก PASS, PoW, interaction, throttle หรือ deny

04

ออก token ครั้งเดียว

สุ่ม 256-bit opaque token ผูกกับ session/action/origin และ TTL สั้น

05

Consume แบบ atomic

Business endpoint consume ครั้งเดียว และปฏิเสธ replay, mismatch, expiry

Threat model

สมมติว่าผู้โจมตีรู้โค้ดทั้งหมด

Source, JavaScript, API, DB schema, PoW และ threshold อาจเป็นที่รู้ได้ แต่ secret และ authorization ต้องอยู่บนเซิร์ฟเวอร์

สมมติว่าผู้โจมตีมี
  • source code ทั้งหมด
  • AI models สมัยใหม่
  • Playwright / Selenium / headless Chromium
  • residential proxies
  • captures ของ traffic ตัวเอง
Security ไม่พึ่งการซ่อน
  • JavaScript
  • challenge algorithms
  • field names
  • endpoints
  • risk thresholds
โอเพนซอร์ส

โค้ดสาธารณะควรเพิ่มความสามารถในการตรวจสอบ ไม่ใช่ทำให้โมเดลอ่อนแอ

การอ่าน implementation ต้องไม่สร้าง authorization bypass Public review ต้องมี releases, keys, repository permissions และ vulnerability handling ที่มีวินัย

ควรเปิดเผย

  • source และ change history
  • SECURITY.md และ responsible disclosure
  • threat model และ architecture
  • automated security / red-team tests
  • release checksums และ notes

ควรเก็บเป็นความลับ

  • production config/guard.php
  • APP_KEY และ HMAC/privacy/rate-limit keys
  • DB dumps และ security events จริง
  • cookies/tokens/sessions จริง
  • deployment secrets และ private infrastructure
การเชื่อมต่อ

พื้นผิว integration เล็ก สิทธิ์สุดท้ายอยู่บนเซิร์ฟเวอร์

Core ปัจจุบันมุ่ง PHP 8.1+ และ framework-independent ที่ security boundary ปกป้องแต่ละ action อย่างชัดเจนและ consume token ก่อน business operation

Actions ทั่วไปloginregisterpassword_resetcontactcheckoutfile_upload
FrontendHTML
<script src="/guard/public/assets/guard.js" defer></script>
<form data-guard-action="contact">
  …
</form>
Protected actionPHP
$result = Guard::verifyAndConsume(
  $_POST['guard_token'] ?? '',
  'contact'
);
if (!$result->allowed()) { http_response_code(403); exit; }
PRE-1.0
สถานะปัจจุบัน

0.4.10 · pre-1.0 · กำลังพัฒนา

Branch ปัจจุบันเป็น security-first architecture พร้อม automated regression/red-team coverage เริ่มด้วย Shadow Mode แล้ว calibrate enforcement บน traffic จริง

PHP coreพร้อมใช้งาน
Webasyst / Shop-Script adapterหลัง core เสถียร
Verified agents / Privacy Passอนาคต / ขึ้นกับมาตรฐาน
Release0.4.10
FAQ

คำกล่าวชัดเจน ขอบเขตชัดเจน

Public source ทำให้ Guard แตกง่ายขึ้นหรือไม่?+
ทำให้ศึกษา implementation ได้ง่ายขึ้น ดังนั้น security ต้องไม่พึ่ง obscurity Public review และ tests ช่วยพบข้อบกพร่องเร็วขึ้น
Guard แทน MFA, passkey หรือ WAF หรือไม่?+
ไม่ Guard เป็น layer anti-automation / abuse-protection Critical actions ยังต้องใช้ authentication, authorization, CSRF, MFA/passkey และ infrastructure controls
Core runtime ต้องใช้อินเทอร์เน็ตหรือไม่?+
Protection flow หลักไม่ต้องมี outbound requests แบบบังคับ Updates, repository และ optional attestation แยกออกจากกัน
Bot ขั้นสูงยังผ่าน interactive check ได้หรือไม่?+
ได้ Controlled browser, AI หรือ human solver อาจเลียนแบบ interaction ดังนั้น final authorization ยังขึ้นกับ server context, limits, tokens และ business policy

สร้าง abuse protection ที่ตรวจสอบได้

Runtime ภายในระบบ Server authorization Threat model สาธารณะ ไม่มี CAPTCHA ภายนอกแบบบังคับ

ภาษา

EnglishEnglishРусскийRussian简体中文Chinese (Simplified)繁體中文Chinese (Traditional)日本語Japanese한국어KoreanDeutschGermanFrançaisFrenchEspañolSpanishItalianoItalianPortuguês (Brasil)Portuguese (Brazil)العربيةArabicעבריתHebrewTürkçeTurkishPolskiPolishNederlandsDutchBahasa IndonesiaIndonesianTiếng ViệtVietnameseहिन्दीHindiPortuguês (Portugal)Portuguese (Portugal)ČeštinaCzechRomânăRomanianMagyarHungarianΕλληνικάGreekSvenskaSwedishNorskNorwegianDanskDanishSuomiFinnishไทยThai