diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2021-05-20 14:55:05 +0200 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2021-05-20 14:55:05 +0200 |
commit | 9a1c2d0ea731724edfaca97195c87569e4321681 (patch) | |
tree | d1371082f38a429a2c491ef918ed2a963936bc9a /test/results/irc.pcap.out | |
parent | db39772aa7b10ee6fb9e21db8f44c0f5fca7a1d2 (diff) |
Reworked layer 4 flow length naming/calculation.
* nDPIsrvd services usually do not care about layer4 data length,
payload length is quite more essential for further processing
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/irc.pcap.out')
-rw-r--r-- | test/results/irc.pcap.out | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/test/results/irc.pcap.out b/test/results/irc.pcap.out index 8bedf1a5e..288d25309 100644 --- a/test/results/irc.pcap.out +++ b/test/results/irc.pcap.out @@ -1,5 +1,5 @@ 00471{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"irc.pcap","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":256,"tick-resolution":1000,"reader-thread-count":1,"idle-scan-period":10000,"generic-max-idle-time":600000,"icmp-max-idle-time":30000,"udp-max-idle-time":180000,"tcp-max-idle-time":7440000,"tcp-max-post-end-flow-time":120000,"max-packets-per-flow-to-send":15,"max-packets-per-flow-to-process":255} -00470{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1387554241634,"flow_last_seen":0,"flow_tot_l4_data_len":40,"flow_min_l4_data_len":40,"flow_max_l4_data_len":40,"flow_avg_l4_data_len":40,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15} +00478{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1387554241634,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15} 00432{"flow_id":1,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":634815,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"AAAMB6wBABNyxPHhCABFAAA8\/+BAAEAGJjUKtJz5JuVGFLNhH0BpMfDFAAAAAKACOQj\/0AAAAgQFtAQCCAq+wg8lAAAAAAEDAwc="} 00430{"flow_id":1,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":665525,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ABNyxPHhANAr0XYACABFAAA8AABAADIGNBYm5UYUCrSc+R9As2GRFS01aTHwxqASFqAOiAAAAgQFtAQCCAowSCUOvsIPJQEDAwY="} 00419{"flow_id":1,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":665548,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"AAAMB6wBABNyxPHhCABFAAA0\/+FAAEAGJjwKtJz5JuVGFLNhH0BpMfDGkRUtNoAQAHNTYQAAAQEICr7CD0QwSCUO"} @@ -7,7 +7,7 @@ 00419{"flow_id":1,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":695656,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ABNyxPHhANAr0XYACABFAAA0CCBAADIGK\/4m5UYUCrSc+R9As2GRFS02aTHw6YAQAFtTTgAAAQEICjBIJRa+wg9E"} 00443{"flow_id":1,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":6,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":695673,"pkt_caplen":83,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":83,"pkt_l4_len":49,"pkt":"AAAMB6wBABNyxPHhCABFAABF\/+NAAEAGJikKtJz5JuVGFLNhH0BpMfDpkRUtNoAYAHMU3gAAAQEICr7CD2IwSCUWTklDSyBtb2xvY2h0ZXN0DQo="} 00504{"flow_id":1,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":7,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":695929,"pkt_caplen":128,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":128,"pkt_l4_len":94,"pkt":"ABNyxPHhANAr0XYACABFAAByCCFAADIGK78m5UYUCrSc+R9As2GRFS02aTHw6YAYAFuk2AAAAQEICjBIJRa+wg9EOmNhcmQuZnJlZW5vZGUubmV0IE5PVElDRSAqIDoqKiogTG9va2luZyB1cCB5b3VyIGhvc3RuYW1lLi4uDQo="} -00545{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":7,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":7,"flow_first_seen":1387554241634,"flow_last_seen":1387554241695,"flow_tot_l4_data_len":354,"flow_min_l4_data_len":32,"flow_max_l4_data_len":94,"flow_avg_l4_data_len":50,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","ndpi": {"flow_risk": {"22":"Unsafe Protocol"},"proto":"IRC","breed":"Unsafe","category":"Chat"}} +00556{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":7,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":7,"flow_first_seen":1387554241634,"flow_last_seen":1387554241695,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":62,"flow_tot_l4_payload_len":114,"flow_avg_l4_payload_len":16,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","ndpi": {"flow_risk": {"22":"Unsafe Protocol"},"proto":"IRC","breed":"Unsafe","category":"Chat"}} 00419{"flow_id":1,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":8,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":695943,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"AAAMB6wBABNyxPHhCABFAAA0\/+RAAEAGJjkKtJz5JuVGFLNhH0BpMfD6kRUtdIAQAHNSyQAAAQEICr7CD2IwSCUW"} 00488{"flow_id":1,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":9,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":726130,"pkt_caplen":115,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":115,"pkt_l4_len":81,"pkt":"ABNyxPHhANAr0XYACABFAABlCCJAADIGK8sm5UYUCrSc+R9As2GRFS10aTHw+oAYAFuqEAAAAQEICjBIJR2+wg9iOmNhcmQuZnJlZW5vZGUubmV0IE5PVElDRSAqIDoqKiogQ2hlY2tpbmcgSWRlbnQNCg=="} 00421{"flow_id":1,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":10,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554241,"pkt_ts_usec":726146,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"AAAMB6wBABNyxPHhCABFAAA0\/+VAAEAGJjgKtJz5JuVGFLNhH0BpMfD6kRUtpYAQAHNScwAAAQEICr7CD4AwSCUd"} @@ -16,5 +16,5 @@ 00494{"flow_id":1,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":13,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554250,"pkt_ts_usec":645455,"pkt_caplen":118,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":118,"pkt_l4_len":84,"pkt":"ABNyxPHhANAr0XYACABFAABoCCRAADIGK8Ym5UYUCrSc+R9As2GRFS3baTHw+oAYAFsCCQAAAQEICjBILdO+wg+3OmNhcmQuZnJlZW5vZGUubmV0IE5PVElDRSAqIDoqKiogTm8gSWRlbnQgcmVzcG9uc2UNCg=="} 00421{"flow_id":1,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":14,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554250,"pkt_ts_usec":645480,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"AAAMB6wBABNyxPHhCABFAAA0\/+dAAEAGJjYKtJz5JuVGFLNhH0BpMfD6kRUuD4AQAHMmewAAAQEICr7CMlgwSC3T"} 02358{"flow_id":1,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":15,"source":"irc.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1387554250,"pkt_ts_usec":647295,"pkt_caplen":1514,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1514,"pkt_l4_len":1480,"pkt":"ABNyxPHhANAr0XYACABFAAXcCCVAADIGJlEm5UYUCrSc+R9As2GRFS4PaTHw+oAQAFsv4QAAAQEICjBILdS+wg+3OmNhcmQuZnJlZW5vZGUubmV0IDAwMSBtb2xvY2h0ZXN0IDpXZWxjb21lIHRvIHRoZSBmcmVlbm9kZSBJbnRlcm5ldCBSZWxheSBDaGF0IE5ldHdvcmsgbW9sb2NodGVzdA0KOmNhcmQuZnJlZW5vZGUubmV0IDAwMiBtb2xvY2h0ZXN0IDpZb3VyIGhvc3QgaXMgY2FyZC5mcmVlbm9kZS5uZXRbMzguMjI5LjcwLjIwLzgwMDBdLCBydW5uaW5nIHZlcnNpb24gaXJjZC1zZXZlbi0xLjEuMw0KOmNhcmQuZnJlZW5vZGUubmV0IDAwMyBtb2xvY2h0ZXN0IDpUaGlzIHNlcnZlciB3YXMgY3JlYXRlZCBTdW4gRGVjIDExIDIwMTEgYXQgMjI6MTY6MTAgVVRDDQo6Y2FyZC5mcmVlbm9kZS5uZXQgMDA0IG1vbG9jaHRlc3QgY2FyZC5mcmVlbm9kZS5uZXQgaXJjZC1zZXZlbi0xLjEuMyBET1FSU1phZ2hpbG9wc3d6IENGSUxNUFFTYmNlZmdpamtsbW5vcHFyc3R2eiBia2xvdmVxamZJDQo6Y2FyZC5mcmVlbm9kZS5uZXQgMDA1IG1vbG9jaHRlc3QgQ0hBTlRZUEVTPSMgRVhDRVBUUyBJTlZFWCBDSEFOTU9ERVM9ZUlicSxrLGZsaixDRkxNUFFTY2dpbW5wcnN0eiBDSEFOTElNSVQ9IzoxMjAgUFJFRklYPShvdilAKyBNQVhMSVNUPWJxZUk6MTAwIE1PREVTPTQgTkVUV09SSz1mcmVlbm9kZSBLTk9DSyBTVEFUVVNNU0c9QCsgQ0FMTEVSSUQ9ZyA6YXJlIHN1cHBvcnRlZCBieSB0aGlzIHNlcnZlcg0KOmNhcmQuZnJlZW5vZGUubmV0IDAwNSBtb2xvY2h0ZXN0IENBU0VNQVBQSU5HPXJmYzE0NTkgQ0hBUlNFVD1hc2NpaSBOSUNLTEVOPTE2IENIQU5ORUxMRU49NTAgVE9QSUNMRU49MzkwIEVUUkFDRSBDUFJJVk1TRyBDTk9USUNFIERFQUY9RCBNT05JVE9SPTEwMCBGTkMgVEFSR01BWD1OQU1FUzoxLExJU1Q6MSxLSUNLOjEsV0hPSVM6MSxQUklWTVNHOjQsTk9USUNFOjQsQUNDRVBUOixNT05JVE9SOiA6YXJlIHN1cHBvcnRlZCBieSB0aGlzIHNlcnZlcg0KOmNhcmQuZnJlZW5vZGUubmV0IDAwNSBtb2xvY2h0ZXN0IEVYVEJBTj0kLGFyeHogV0hPWCBDTElFTlRWRVI9My4wIFNBRkVMSVNUIEVMSVNUPUNUVSA6YXJlIHN1cHBvcnRlZCBieSB0aGlzIHNlcnZlcg0KOmNhcmQuZnJlZW5vZGUubmV0IDI1MSBtb2xvY2h0ZXN0IDpUaGVyZSBhcmUgMjIxIHVzZXJzIGFuZCA5MDE2NSBpbnZpc2libGUgb24gMjggc2VydmVycw0KOmNhcmQuZnJlZW5vZGUubmV0IDI1MiBtb2xvY2h0ZXN0IDMxIDpJUkMgT3BlcmF0b3JzIG9ubGluZQ0KOmNhcmQuZnJlZW5vZGUubmV0IDI1MyBtb2xvY2h0ZXN0IDEgOnVua25vd24gY29ubmVjdGlvbihzKQ0KOmNhcmQuZnJlZW5vZGUubmV0IDI1NCBtb2xvY2h0ZXN0IDU0NzQwIDpjaGFubmVscyBmb3JtZWQNCjpjYXJkLmZyZWVub2RlLm5ldCAyNTUgbW9sb2NodGVzdCA6SSBoYXZlIDIzMjQgY2xpZW50cyBhbmQgOCBzZXJ2ZXJzDQo6Y2FyZC5mcmVlbm9kZS5uZXQgMjY1IG1vbG9jaHRlc3QgMjMyNCA5OTI3IDpDdXJyZW50IGxvY2FsIHVzZXJzIDI="} -00490{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":29,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":29,"flow_first_seen":1387554241634,"flow_last_seen":1387554256201,"flow_tot_l4_data_len":7959,"flow_min_l4_data_len":32,"flow_max_l4_data_len":1480,"flow_avg_l4_data_len":274,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15} +00501{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":29,"source":"irc.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":29,"flow_first_seen":1387554241634,"flow_last_seen":1387554256201,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1448,"flow_tot_l4_payload_len":7015,"flow_avg_l4_payload_len":241,"midstream":0,"l3_proto":"ip4","src_ip":"10.180.156.249","dst_ip":"38.229.70.20","src_port":45921,"dst_port":8000,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15} 00123{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":29,"source":"irc.pcap","alias":"nDPId-test"} |