Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | Improved event parsing for Python scripts. | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Added event validation functions and fixed Python scripts. | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Use --squash for git subtree pull. | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Centralized EventName validation and moved code parts. | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Removed DISABLE_JSMN define for c-json-stdout (built-in per default). | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Added shell script to update/pull JSMN. | Toni Uhlig | 2020-09-26 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Merge commit 'e8af059ab3deb2a49e75c20ddcaf14ee19bcc223' as 'contrib/jsmn' | Toni Uhlig | 2020-09-26 |
|\ | |||
| * | Squashed 'contrib/jsmn/' content from commit 053d3cd | Toni Uhlig | 2020-09-26 |
| | | | | | git-subtree-dir: contrib/jsmn git-subtree-split: 053d3cd29200edb1bfd181d917d140c16c1f8834 | ||
* | Removed examples/c-json-stdout/jsmn as it's new location will be ↵ | Toni Uhlig | 2020-09-26 |
| | | | | | | contrib/jsmn, soon. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Added host_server_name length to hash to send a detection update if length ↵ | Toni Uhlig | 2020-09-26 |
| | | | | | | changed (hacky). Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Added new flow event: FLOW_EVENT_DETECTION_UPDATE | Toni Uhlig | 2020-09-25 |
| | | | | | | | * This event will be triggered when nDPI detection has some new information for us (hopefully). * Detection change is based on hashing with 32-bit murmur3 certain members of the ndpi flow struct. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Process extra packets with nDPI, still not perfect but results in a more ↵ | Toni Uhlig | 2020-09-24 |
| | | | | | | | | | accurate detection. * set default user used for setuid() * added 2 TODOs Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPId: Change user/group after init. | Toni Uhlig | 2020-09-21 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: Use of an anonymous enum for collector/distributor socket types ↵ | Toni Uhlig | 2020-09-07 |
| | | | | | | fits best. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: Change user/group, allow listening on UNIX socket for incoming ↵ | Toni Uhlig | 2020-09-05 |
| | | | | | | distributor connections Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | go-dashboard: Print unmarshalled JSON string in a textbox. | Toni Uhlig | 2020-09-03 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | go-dashboard: Added event structs and JSON unmarshal semantic. | Toni Uhlig | 2020-09-02 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | go-dashboard: go mod/vendor support + termdash text user interface | Toni Uhlig | 2020-09-01 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPId: Print compiled-in libgcrypt version (if libndpi was compiled with ↵ | Toni Uhlig | 2020-08-31 |
| | | | | | | libgcrypt support). Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Added golang JSON deserializer example. | Toni Uhlig | 2020-08-31 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Increased network buffer size from 8448 to 9216 with the hope that it might ↵ | Toni Uhlig | 2020-08-27 |
| | | | | | | be finally enough. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPId: Improved command line option parsing, app usage and subopts for ↵ | Toni Uhlig | 2020-08-26 |
| | | | | | | (carefully) tuning some daemon options. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Makefile: Allow pkg-config based builds and also allow setting libndpi build ↵ | Toni Uhlig | 2020-08-24 |
| | | | | | | options manually. Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | risky-flow-to-pcap.py: dump the first few packets of a "risky" flow to a ↵ | Toni Uhlig | 2020-08-23 |
| | | | | | | PCAP file Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPId: subopt parsing skeleton | Toni Uhlig | 2020-08-19 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd.py: improved PCAP writing for guessed/undetected flows (ignore ↵ | Toni Uhlig | 2020-08-19 |
| | | | | | | empty UDP/TCP packets) Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | added pkt_type and pkt_ipoffset to json serialization | Toni Uhlig | 2020-08-19 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: add command line option for distributor listen host/port | Toni Uhlig | 2020-08-18 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | merged code to reduce code duplicates | Toni Uhlig | 2020-08-18 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: log ip:port for distributor connection fails | Toni Uhlig | 2020-08-17 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | added nDPIsrvd communication/utils python module | Toni Uhlig | 2020-08-16 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | minor improvments regarding flow guessing on flow end/idle and other not ↵ | Toni Uhlig | 2020-08-16 |
| | | | | | | worth to mention Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | yet another README.md update | Toni Uhlig | 2020-08-15 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | error handling enhancements | Toni Uhlig | 2020-08-15 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | README.md update | Toni Uhlig | 2020-08-15 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: fixed another two bugs; one related to EPOLLIN event for fd with ↵ | Toni Uhlig | 2020-08-15 |
| | | | | | | shutdown reading end, one if write() did not write all bytes Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | adjust some config values | Toni Uhlig | 2020-08-15 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | several fixes and improvments | Toni Uhlig | 2020-08-14 |
| | | | | | | | | - set errno to 0 if it is checked right after a libc call - ignore SIGPIPE as we want to avoid signal handling where possible - fixed another issue in nDPIsrvd/c-json-stdout which caused buffering errors Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | minor improvments | Toni Uhlig | 2020-08-14 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | c-json-stdout: fixed broken buffering | Toni Uhlig | 2020-08-14 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPIsrvd: fixed broken buffering | Toni Uhlig | 2020-08-14 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | nDPId: removed unused code, process remaining flows on shutdown (useful for ↵ | Toni Uhlig | 2020-08-14 |
| | | | | | | replaying pcap files) Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | flow-undetected-to-pcap.py: apply 'guessed' or 'undetected' to the filepath | Toni Uhlig | 2020-08-14 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | Makefile: ENABLE_DEBUG disables function inlining | Toni Uhlig | 2020-08-14 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | set detection_completed = 1 if guessed/not-detected event thrown | Toni Uhlig | 2020-08-13 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | flow-info.py, flow-undetected-to-pcap.py: throw socket error runtime ↵ | Toni Uhlig | 2020-08-13 |
| | | | | | | exception if disconnect received Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | flow-undetected-to-pcap.py: do not write pcaps for midstream flows, write ↵ | Toni Uhlig | 2020-08-13 |
| | | | | | | pcaps after detection completed or flow EoF but only once Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | improved TCP-FIN/TCP-RST and TCP-keepalive/-idle timeout handling | Toni Uhlig | 2020-08-13 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> | ||
* | replaced deprecated pcap_lookupdev with pcap_findalldevs | Toni Uhlig | 2020-08-12 |
| | |||
* | improved nDPIsrvd buffering if write returned EAGAIN | Toni Uhlig | 2020-08-12 |
| | | | | Signed-off-by: Toni Uhlig <matzeton@googlemail.com> |