Secure, Scalable Tunneling

Expose your local services to the public internet securely. Equipped with Web Application Firewall (WAF), WireGuard VPN integration, and automatic HTTPS.

What is ArusBalik?

ArusBalik is a control plane and reverse tunnel solution. It allows you to securely expose applications running on local, private networks (like behind NAT or firewalls) to the public internet using a centralized VPS server. It manages the entire lifecycle of tunnels, including automatic SSL certificate provisioning (via Let's Encrypt and Caddy), DNS updates, and secure multiplexed connections using modern protocols like QUIC/WebSockets.

Architecture Flow

graph TD Client[User / Internet] -->|HTTPS Requests| VPS[VPS Server] VPS --> Caddy[Caddy Reverse Proxy] Caddy --> WAF[Web Application Firewall - WAF] WAF --> TunnelServer[ArusBalik Tunnel Server] TunnelServer <==>|Multiplexed Secure Tunnel| TunnelClient[ArusBalik Tunnel Client] TunnelClient --> LocalService[Local Service / App] subgraph "Local Network (Behind NAT)" TunnelClient LocalService end subgraph "Public Cloud (VPS)" VPS Caddy WAF TunnelServer end

Technology Stack

Web Application Firewall (WAF)

ArusBalik includes a built-in WAF to inspect incoming HTTP traffic, block malicious requests (e.g., SQLi, XSS), and ensure only legitimate traffic reaches your exposed local services.

WireGuard VPN

For deeper network integration, ArusBalik provides a WireGuard VPN manager. Connect clients to a virtual subnet for direct, encrypted Layer 3 access to resources.

Caddy Web Server

Automatic HTTPS is managed seamlessly via Caddy. When a new route is published, ArusBalik dynamically updates Caddy's configuration to instantly provision Let's Encrypt certificates.

Go & QUIC

Built with Go, ArusBalik utilizes Yamux and QUIC for high-performance, multiplexed, and reliable tunneling, easily capable of handling thousands of concurrent streams.

Why ArusBalik? Academic Foundations

ArusBalik's architecture is deeply rooted in recent networking and security research.

Performance & Privacy

"QUIC is a UDP-based transport protocol... It enhances privacy by encrypting entire packets and offers improvements over TCP, such as native multiplexing and connection migration."

— A Performance Evaluation of QUIC in Real-Time Networks

ArusBalik's approach: Leverages QUIC to ensure the reverse tunnel provides minimal latency and maximum encryption for all multiplexed streams.

Application-Layer Security

"We conclude that protocol-level evolution [to HTTP/3] does not mitigate application-layer concurrency risks... it shifts the attack surface dynamics toward more efficient exploitation primitives."

— QUIC-er Races: HTTP/3 won't save you from TOCTOU vulnerabilities

ArusBalik's approach: Integrates a robust Web Application Firewall (WAF) because modern transport protocols alone cannot stop sophisticated race conditions and web exploits.

Disruption Tolerance

"Disruption-tolerant networks (DTNs) have a wide range of applications, including emergencies where traditional communication infrastructure has been destroyed..."

— QUICL: Disruption-tolerant networking via a QUIC convergence layer

ArusBalik's approach: By utilizing QUIC and WireGuard, the tunnel maintains a persistent connection even in unstable or NAT-restricted environments.