From d80ea84d2ebebe29761f3727fbc5295ba3cb81b8 Mon Sep 17 00:00:00 2001 From: Toni Uhlig Date: Wed, 8 Nov 2023 01:27:42 +0100 Subject: Reset `Unidirectional Traffc` risk if packets from both directions processed. * Fixed risk hash value calculation, which was only done lower 32 bits. * Reduced default reader threads count to two if cross compiling. Signed-off-by: Toni Uhlig --- test/results/flow-info/default/kerberos.pcap.out | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) (limited to 'test/results/flow-info/default/kerberos.pcap.out') diff --git a/test/results/flow-info/default/kerberos.pcap.out b/test/results/flow-info/default/kerberos.pcap.out index 8b9c19b95..eb5c40e8a 100644 --- a/test/results/flow-info/default/kerberos.pcap.out +++ b/test/results/flow-info/default/kerberos.pcap.out @@ -4,9 +4,11 @@ new: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] @@ -18,9 +20,11 @@ new: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [....11] [ip4][..tcp] [...172.16.8.201][49165] -> [.....172.16.8.8][49155] [MIDSTREAM] new: [....12] [ip4][..tcp] [...172.16.8.201][49169] -> [.....172.16.8.8][..389] [MIDSTREAM] @@ -42,18 +46,22 @@ new: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] [MIDSTREAM] new: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [MIDSTREAM] detected: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] RISK: Unidirectional Traffic + detection-update: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] new: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] [MIDSTREAM] new: [....31] [ip4][..tcp] [...172.16.8.201][49192] -> [.....172.16.8.8][...88] [MIDSTREAM] @@ -67,14 +75,14 @@ not-detected: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] [Unknown][Unknown][Unrated] idle: [....26] [ip4][..tcp] [...172.16.8.201][49185] -> [.....172.16.8.8][49155] idle: [.....1] [ip4][..tcp] [...172.16.8.201][49157] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] + idle: [.....2] [ip4][..tcp] [...172.16.8.201][49158] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....3] [ip4][..tcp] [...172.16.8.201][49159] -> [.....172.16.8.8][...88] idle: [.....4] [ip4][..tcp] [...172.16.8.201][49160] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [.....6] [ip4][..tcp] [...172.16.8.201][49162] -> [.....172.16.8.8][...88] idle: [.....8] [ip4][..tcp] [...172.16.8.201][49166] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] + idle: [.....9] [ip4][..tcp] [...172.16.8.201][49167] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....10] [ip4][..tcp] [...172.16.8.201][49168] -> [.....172.16.8.8][...88] guessed: [....13] [ip4][..tcp] [...172.16.8.201][49170] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] @@ -86,13 +94,13 @@ idle: [....17] [ip4][..tcp] [...172.16.8.201][49175] -> [.....172.16.8.8][...88] idle: [....18] [ip4][..tcp] [...172.16.8.201][49176] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....22] [ip4][..tcp] [...172.16.8.201][49181] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] + idle: [....23] [ip4][..tcp] [...172.16.8.201][49182] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....24] [ip4][..tcp] [...172.16.8.201][49183] -> [.....172.16.8.8][...88] guessed: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....25] [ip4][..tcp] [...172.16.8.201][49186] -> [.....172.16.8.8][...88] idle: [....27] [ip4][..tcp] [...172.16.8.201][49187] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] - idle: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] + idle: [....28] [ip4][..tcp] [...172.16.8.201][49188] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] guessed: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] idle: [....29] [ip4][..tcp] [...172.16.8.201][49189] -> [.....172.16.8.8][...88] guessed: [....30] [ip4][..tcp] [...172.16.8.201][49190] -> [.....172.16.8.8][...88] [Kerberos][Unknown][Network][Acceptable] -- cgit v1.2.3