From 1a0d220f11d4f2ae4b2f53119ce1c90a769d3828 Mon Sep 17 00:00:00 2001 From: malmert Date: Mon, 30 Mar 2026 23:04:05 +0200 Subject: [PATCH] add sankey ip ethernet layer --- backend/src/api/analysis_api.py | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/backend/src/api/analysis_api.py b/backend/src/api/analysis_api.py index a99aa49..6adecf9 100644 --- a/backend/src/api/analysis_api.py +++ b/backend/src/api/analysis_api.py @@ -28,6 +28,23 @@ class ProtocolEvidence(BaseModel): drop_count: int = Field(0, description="Packets with verdict=drop for this protocol.") reject_count: int = Field(0, description="Packets with verdict=reject for this protocol.") unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.") + ethernet_protocol: Optional[str] = Field(None, description="Dominant Ethernet protocol associated with this protocol evidence.") + ip_protocol: Optional[str] = Field(None, description="Dominant IP protocol associated with this protocol evidence.") + layer_paths: List["ProtocolLayerPathEvidence"] = Field( + default_factory=list, + description="Optional Ethernet/IP breakdown contributing to this protocol evidence.", + ) + + +class ProtocolLayerPathEvidence(BaseModel): + ethernet_protocol: Optional[str] = Field(None, description="Ethernet protocol label for this path, if known.") + ip_protocol: Optional[str] = Field(None, description="IP protocol label for this path, if known.") + packet_count: int = Field(..., description="Packet observations supporting this path.") + last_seen: datetime = Field(..., description="Most recent packet timestamp supporting this path.") + accept_count: int = Field(0, description="Packets with verdict=accept for this path.") + drop_count: int = Field(0, description="Packets with verdict=drop for this path.") + reject_count: int = Field(0, description="Packets with verdict=reject for this path.") + unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.") class InterfaceHostProtocolEvidence(InterfaceHostEvidence):