From d80ea84d2ebebe29761f3727fbc5295ba3cb81b8 Mon Sep 17 00:00:00 2001 From: Toni Uhlig Date: Wed, 8 Nov 2023 01:27:42 +0100 Subject: Reset `Unidirectional Traffc` risk if packets from both directions processed. * Fixed risk hash value calculation, which was only done lower 32 bits. * Reduced default reader threads count to two if cross compiling. Signed-off-by: Toni Uhlig --- test/results/flow-info/default/nfsv3.pcap.out | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) (limited to 'test/results/flow-info/default/nfsv3.pcap.out') diff --git a/test/results/flow-info/default/nfsv3.pcap.out b/test/results/flow-info/default/nfsv3.pcap.out index d0ddb664f..b6c774dfa 100644 --- a/test/results/flow-info/default/nfsv3.pcap.out +++ b/test/results/flow-info/default/nfsv3.pcap.out @@ -36,19 +36,17 @@ detected: [.....8] [ip4][..udp] [....139.25.22.2][..722] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] RISK: Known Proto on Non Std Port, Unidirectional Traffic idle: [.....5] [ip4][..udp] [....139.25.22.2][.3298] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Unidirectional Traffic idle: [.....1] [ip4][..udp] [....139.25.22.2][.3295] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....4] [ip4][..udp] [....139.25.22.2][.3297] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....7] [ip4][..udp] [....139.25.22.2][.3299] -> [..139.25.22.102][..111] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....3] [ip4][..udp] [....139.25.22.2][..706] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....8] [ip4][..udp] [....139.25.22.2][..722] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....2] [ip4][..udp] [....139.25.22.2][.3296] -> [..139.25.22.102][.1048] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Known Proto on Non Std Port, Unidirectional Traffic + RISK: Known Proto on Non Std Port idle: [.....6] [ip4][..udp] [....139.25.22.2][.1022] -> [..139.25.22.102][.2049] [NFS][Unknown][DataTransfer][Acceptable] - RISK: Unidirectional Traffic DAEMON-EVENT: shutdown -- cgit v1.2.3