diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2022-01-31 20:38:58 +0100 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2022-01-31 20:54:02 +0100 |
commit | 1a0d7ddbfaccc20e081a2fcd0a27495c166e1dbe (patch) | |
tree | 05195d13f935abf90f48b06a381c0a847d55fc18 /test/results/android.pcap.out | |
parent | 7022d0b1c57b4b6233fc2bd89d03328a5f90208e (diff) |
Process additional layer 3 protocols.
* bump libnDPI to c53c82d4823b5a8f856d1375155ac5112b68e8af
* run_tests.sh: improved execution from non-git directories e.g. via `make dist`
* updated JSON schema to be more restrictive
* nDPId: splitted generic get_ip_from_sockaddr into IPv4/IPv6 to prevent compiler warnings on some platforms
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/android.pcap.out')
-rw-r--r-- | test/results/android.pcap.out | 24 |
1 files changed, 6 insertions, 18 deletions
diff --git a/test/results/android.pcap.out b/test/results/android.pcap.out index d7487bab4..1a7ba1235 100644 --- a/test/results/android.pcap.out +++ b/test/results/android.pcap.out @@ -38,20 +38,8 @@ 00602{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":46,"source":"android.pcap","alias":"nDPId-test","flow_id":11,"flow_packet_id":1,"flow_last_seen":1582454825629,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":168,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":168,"pkt_l4_len":134,"ts_msec":1582454825629,"pkt":"AQBef\/\/6xiwDYGpkCABFAACaWhcAAAERrJjAqAIB7\/\/\/+sjTB2wAhk51TS1TRUFSQ0ggKiBIVFRQLzEuMQ0KSE9TVDogMjM5LjI1NS4yNTUuMjUwOjE5MDANCk1BTjogInNzZHA6ZGlzY292ZXIiDQpNWDogMQ0KU1Q6IHVybjpkaWFsLW11bHRpc2NyZWVuLW9yZzpzZXJ2aWNlOmRpYWw6MQ0KDQoA"} 00591{"flow_event_id":6,"flow_event_name":"detected","thread_id":0,"packet_id":46,"source":"android.pcap","alias":"nDPId-test","flow_id":11,"flow_packets_processed":1,"flow_first_seen":1582454825629,"flow_last_seen":1582454825629,"flow_idle_time":180000,"flow_min_l4_payload_len":126,"flow_max_l4_payload_len":126,"flow_tot_l4_payload_len":126,"flow_avg_l4_payload_len":126,"midstream":0,"ts_msec":1582454825629,"l3_proto":"ip4","src_ip":"192.168.2.1","dst_ip":"239.255.255.250","src_port":51411,"dst_port":1900,"l4_proto":"udp","ndpi": {"proto":"SSDP","breed":"Acceptable","category":"System"}} 00494{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":47,"source":"android.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":2,"flow_last_seen":1582454826369,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":86,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":86,"pkt_l4_len":52,"ts_msec":1582454826369,"pkt":"\/\/\/\/\/\/\/\/xiwDYGpkCABFAABItCAAAEARQDTAqAIBwKgC\/+EV4RUANNgcU3BvdFVkcDDcFXQoLlJiTAABAARIlcIDokHeIIm5eNggVkvVDJHA6KPmCng="} -00434{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":53,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":113,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":113,"pkt_l4_len":0,"ts_msec":1582454839884,"pkt":"TGr2n\/Yn2DBiVgAciI4CAwBfAgCKABAAAAAAAAAAAIz8BFqJChwkZ1iJYPgAYGUrS4o4DJHL\/S\/E6LdOr1skAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":53,"source":"android.pcap","alias":"nDPId-test","type":34958} -00461{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":54,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":135,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":135,"pkt_l4_len":0,"ts_msec":1582454839890,"pkt":"2DBiVgAcTGr2n\/YniI4BAwB1AgEKAAAAAAAAAAAAABuBPQRawmcmCJuMCTTl787Fbc92e9r2cPO8HkAbqnp8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACI+Bbd0vg6TUoOiFATr40\/ABYwFAEAAA+sBAEAAA+sBAEAAA+sAgAA"} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":54,"source":"android.pcap","alias":"nDPId-test","type":34958} 01117{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":58,"source":"android.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":3,"flow_last_seen":1582454853081,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":552,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":552,"pkt_l4_len":518,"ts_msec":1582454853081,"pkt":"\/\/\/\/\/\/\/\/xiwDYGpkCABFAAIaAQwAAEAR8XbAqAIBwKgC\/0RcRFwCBr34eyJ2ZXJzaW9uIjogWzIsIDBdLCAicG9ydCI6IDE3NTAwLCAiaG9zdF9pbnQiOiAzMzA0MDI2MjQwMTMxNjcxMTI3MTc3MTQ1ODMyOTcxNTM2ODg0ODIsICJkaXNwbGF5bmFtZSI6ICIiLCAibmFtZXNwYWNlcyI6IFsyNzUwMzcwNTYwLCA3ODUyNjYxNzcsIDE1MjYyNjMwNDUsIDEzMzg2NTkyMDEsIDE0ODE5MzM3LCA0ODEwNTkxNzYwLCA0NTE0NzI2NTgsIDczNjM0MTUyOCwgOTM4ODEzODQ5LCAxMjY3Njk1MTA5LCA1NDQwNDA3MDcyLCA1ODM0NDk5NiwgOTk2MzA2MjE1LCA1MzAzMzAxMjQ4LCAyODUyMTYwNywgNDA1NjQ2MjU5MiwgNzA1MzYyNzE4NCwgMTUyMjE3NzU4NywgMTQyMTExNDM5OSwgMTI1MjExNjQyOSwgOTk0Njk3NzMsIDcwNzk2MzY2ODgsIDE3Njk2NDMwNywgMTI1NTQwNTY2LCAxMDQ3NDI4MTg5LCA0NzE2MTkwMDQ4LCA1NDY3MTYzMDg4LCAxMTk1MDQ0MDcxLCA5Njg1MzIyNCwgMTc2MDk5NjMsIDY0NzgzMDM0NDAsIDUxMTcwNjY0MiwgNjI5Nzk1NTE4NCwgMTQxNTYyMDM1MF19"} 00494{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":59,"source":"android.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":3,"flow_last_seen":1582454856384,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":86,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":86,"pkt_l4_len":52,"ts_msec":1582454856384,"pkt":"\/\/\/\/\/\/\/\/xiwDYGpkCABFAABIA+oAAEAR8GrAqAIBwKgC\/+EV4RUANNgcU3BvdFVkcDDcFXQoLlJiTAABAARIlcIDokHeIIm5eNggVkvVDJHA6KPmCng="} -00433{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":60,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":113,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":113,"pkt_l4_len":0,"ts_msec":1582454865004,"pkt":"TGr2n\/Yn2DBiVgAciI4CAwBfAgCKABAAAAAAAAAAAItGYkOhXtVHFSBei+KDaRb2mr+UrA3yLPv\/bW2693f7AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":60,"source":"android.pcap","alias":"nDPId-test","type":34958} -00461{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":61,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":135,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":135,"pkt_l4_len":0,"ts_msec":1582454865009,"pkt":"2DBiVgAcTGr2n\/YniI4BAwB1AgEKAAAAAAAAAAAAABovI0nixZFFW\/ZpJww553gjQO2Uwi5137Ow8+iP3PqwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABg6nQQ8V4nFthsHWtgZMXFABYwFAEAAA+sBAEAAA+sBAEAAA+sAgAA"} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":61,"source":"android.pcap","alias":"nDPId-test","type":34958} -00510{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":62,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":169,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":169,"pkt_l4_len":0,"ts_msec":1582454865009,"pkt":"TGr2n\/Yn2DBiVgAciI4CAwCXAhPKABAAAAAAAAAAAYtGYkOhXtVHFSBei+KDaRb2mr+UrA3yLPv\/bW2693f7AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADZcbSnYYoBu5dETlqS4YLUADjuvEvKQvPJ0rVdu0zb5LSOsCSMjRkTMYTV0rOZo1ZtYgUxQ\/1u64gYvePhWbMqouPvhtSR61kuMw=="} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":62,"source":"android.pcap","alias":"nDPId-test","type":34958} -00432{"packet_event_id":1,"packet_event_name":"packet","thread_id":0,"packet_id":63,"source":"android.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_caplen":113,"pkt_type":34958,"pkt_l3_offset":14,"pkt_l4_offset":0,"pkt_len":113,"pkt_l4_len":0,"ts_msec":1582454865013,"pkt":"2DBiVgAcTGr2n\/YniI4BAwBfAgMKAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACSXhMQpT7Z+H8pmeIKqgblAAA="} -00149{"basic_event_id":5,"basic_event_name":"Unknown packet type","thread_id":0,"packet_id":63,"source":"android.pcap","alias":"nDPId-test","type":34958} 00517{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":64,"source":"android.pcap","alias":"nDPId-test","flow_id":12,"flow_packets_processed":1,"flow_first_seen":1582454865794,"flow_last_seen":1582454865794,"flow_idle_time":120000,"flow_min_l4_payload_len":24,"flow_max_l4_payload_len":24,"flow_tot_l4_payload_len":24,"flow_avg_l4_payload_len":24,"midstream":0,"ts_msec":1582454865794,"l3_proto":"ip6","src_ip":"::","dst_ip":"ff02::1:ff9f:f627","l4_proto":"icmp6","flow_datalink":1,"flow_max_packets":3} 00484{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":64,"source":"android.pcap","alias":"nDPId-test","flow_id":12,"flow_packet_id":1,"flow_last_seen":1582454865794,"flow_idle_time":120000,"pkt_oversize":false,"pkt_caplen":78,"pkt_type":34525,"pkt_l3_offset":14,"pkt_l4_offset":54,"pkt_len":78,"pkt_l4_len":24,"ts_msec":1582454865794,"pkt":"MzP\/n\/YnTGr2n\/Ynht1gAAAAABg6\/wAAAAAAAAAAAAAAAAAAAAD\/AgAAAAAAAAAAAAH\/n\/YnhwBLLgAAAAD+gAAAAAAAAE5q9v\/+n\/Yn"} 00552{"flow_event_id":6,"flow_event_name":"detected","thread_id":0,"packet_id":64,"source":"android.pcap","alias":"nDPId-test","flow_id":12,"flow_packets_processed":1,"flow_first_seen":1582454865794,"flow_last_seen":1582454865794,"flow_idle_time":120000,"flow_min_l4_payload_len":24,"flow_max_l4_payload_len":24,"flow_tot_l4_payload_len":24,"flow_avg_l4_payload_len":24,"midstream":0,"ts_msec":1582454865794,"l3_proto":"ip6","src_ip":"::","dst_ip":"ff02::1:ff9f:f627","l4_proto":"icmp6","ndpi": {"proto":"ICMPV6","breed":"Acceptable","category":"Network"}} @@ -389,7 +377,7 @@ 00552{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":500,"source":"android.pcap","alias":"nDPId-test","flow_id":36,"flow_packets_processed":2,"flow_first_seen":1582454871061,"flow_last_seen":1582454871100,"flow_idle_time":180000,"flow_min_l4_payload_len":42,"flow_max_l4_payload_len":58,"flow_tot_l4_payload_len":100,"flow_avg_l4_payload_len":50,"midstream":0,"ts_msec":1582454872047,"l3_proto":"ip4","src_ip":"192.168.2.16","dst_ip":"192.168.2.1","src_port":7660,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":3} 00552{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":500,"source":"android.pcap","alias":"nDPId-test","flow_id":48,"flow_packets_processed":2,"flow_first_seen":1582454871600,"flow_last_seen":1582454871601,"flow_idle_time":180000,"flow_min_l4_payload_len":37,"flow_max_l4_payload_len":53,"flow_tot_l4_payload_len":90,"flow_avg_l4_payload_len":45,"midstream":0,"ts_msec":1582454872047,"l3_proto":"ip4","src_ip":"192.168.2.16","dst_ip":"192.168.2.1","src_port":58892,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":3} 00552{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":500,"source":"android.pcap","alias":"nDPId-test","flow_id":24,"flow_packets_processed":2,"flow_first_seen":1582454867723,"flow_last_seen":1582454867761,"flow_idle_time":180000,"flow_min_l4_payload_len":37,"flow_max_l4_payload_len":53,"flow_tot_l4_payload_len":90,"flow_avg_l4_payload_len":45,"midstream":0,"ts_msec":1582454872047,"l3_proto":"ip4","src_ip":"192.168.2.16","dst_ip":"192.168.2.1","src_port":54837,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":3} -00158{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":500,"source":"android.pcap","alias":"nDPId-test","total-events-serialized":392} +00158{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":500,"source":"android.pcap","alias":"nDPId-test","total-events-serialized":380} ~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~ ~~ packets captured/processed: 500/475 ~~ skipped flows.............: 0 @@ -398,10 +386,10 @@ ~~ total active/idle flows...: 63/63 ~~ total timeout flows.......: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -~~ total memory allocated....: 4888108 bytes -~~ total memory freed........: 4888108 bytes -~~ total allocations/frees...: 100461/100461 +~~ total memory allocated....: 4894018 bytes +~~ total memory freed........: 4894018 bytes +~~ total allocations/frees...: 100480/100480 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -~~ json string min len.......: 154 chars +~~ json string min len.......: 163 chars ~~ json string max len.......: 2228 chars -~~ json string avg len.......: 1191 chars +~~ json string avg len.......: 1266 chars |