Expose your local services to the public internet securely. Equipped with Web Application Firewall (WAF), WireGuard VPN integration, and automatic HTTPS.
ArusBalik is a control plane and reverse tunnel solution. It allows you to securely expose applications running on local, private networks (like behind NAT or firewalls) to the public internet using a centralized VPS server. It manages the entire lifecycle of tunnels, including automatic SSL certificate provisioning (via Let's Encrypt and Caddy), DNS updates, and secure multiplexed connections using modern protocols like QUIC/WebSockets.
ArusBalik includes a built-in WAF to inspect incoming HTTP traffic, block malicious requests (e.g., SQLi, XSS), and ensure only legitimate traffic reaches your exposed local services.
For deeper network integration, ArusBalik provides a WireGuard VPN manager. Connect clients to a virtual subnet for direct, encrypted Layer 3 access to resources.
Automatic HTTPS is managed seamlessly via Caddy. When a new route is published, ArusBalik dynamically updates Caddy's configuration to instantly provision Let's Encrypt certificates.
Built with Go, ArusBalik utilizes Yamux and QUIC for high-performance, multiplexed, and reliable tunneling, easily capable of handling thousands of concurrent streams.
ArusBalik's architecture is deeply rooted in recent networking and security research.
"QUIC is a UDP-based transport protocol... It enhances privacy by encrypting entire packets and offers improvements over TCP, such as native multiplexing and connection migration."
ArusBalik's approach: Leverages QUIC to ensure the reverse tunnel provides minimal latency and maximum encryption for all multiplexed streams.
"We conclude that protocol-level evolution [to HTTP/3] does not mitigate application-layer concurrency risks... it shifts the attack surface dynamics toward more efficient exploitation primitives."
ArusBalik's approach: Integrates a robust Web Application Firewall (WAF) because modern transport protocols alone cannot stop sophisticated race conditions and web exploits.
"Disruption-tolerant networks (DTNs) have a wide range of applications, including emergencies where traditional communication infrastructure has been destroyed..."
ArusBalik's approach: By utilizing QUIC and WireGuard, the tunnel maintains a persistent connection even in unstable or NAT-restricted environments.