From e5e69d0f7ab382e3507660fe752027c09e32310e Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Sun, 10 May 2020 21:25:38 +0200 Subject: Added the ability to detect when a known protocol is using a non-standard port Added check to spot executables exchanged via HTTP --- example/reader_util.c | 2 ++ 1 file changed, 2 insertions(+) (limited to 'example/reader_util.c') diff --git a/example/reader_util.c b/example/reader_util.c index 142e0ebe8..1feb2d7ff 100644 --- a/example/reader_util.c +++ b/example/reader_util.c @@ -993,6 +993,8 @@ void process_ndpi_collected_info(struct ndpi_workflow * workflow, struct ndpi_fl snprintf(flow->flow_extra_info, sizeof(flow->flow_extra_info), "%s", flow->ndpi_flow->flow_extra_info); + flow->risk = flow->ndpi_flow->risk; + if(is_ndpi_proto(flow, NDPI_PROTOCOL_DHCP)) { snprintf(flow->dhcp_fingerprint, sizeof(flow->dhcp_fingerprint), "%s", flow->ndpi_flow->protos.dhcp.fingerprint); } else if(is_ndpi_proto(flow, NDPI_PROTOCOL_BITTORRENT)) { -- cgit v1.2.3