Refactor: Remove NFStream and flow identity utilities; introduce Tshark manager
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s

- Deleted flow_identity.py and nfstream_flow_worker.py as they are no longer needed.
- Removed nfstream_manager.py and its associated logic for managing NFStream workers.
- Added tshark_manager.py to manage tshark packet enrichment and matching.
- Updated setup_build_server.sh to include default environment variables for tshark.
- Implemented packet signature generation and enrichment logic in the new TsharkManager class.
This commit is contained in:
2026-03-07 19:51:29 +01:00
parent dfad09fa21
commit 22bb6b8526
11 changed files with 603 additions and 695 deletions

View File

@@ -54,17 +54,12 @@ class BackendSettings:
bridge_bpf_build_dir: str
telemetry_process_stop_timeout_seconds: float
telemetry_reader_join_timeout_seconds: float
nfstream_enabled: bool
nfstream_promiscuous_mode: bool
nfstream_idle_timeout_seconds: int
nfstream_active_timeout_seconds: int
nfstream_snapshot_length: int
nfstream_n_dissections: int
nfstream_n_meters: int
nfstream_cache_ttl_seconds: float
nfstream_lookup_window_ms: int
nfstream_reader_join_timeout_seconds: float
nfstream_process_stop_timeout_seconds: float
tshark_enabled: bool
tshark_display_filter: str
tshark_cache_ttl_seconds: float
tshark_match_window_ms: int
tshark_reader_join_timeout_seconds: float
tshark_process_stop_timeout_seconds: float
def load_settings() -> BackendSettings:
@@ -92,17 +87,12 @@ def load_settings() -> BackendSettings:
bridge_bpf_build_dir=_env_str("BACKEND_BRIDGE_BPF_BUILD_DIR", "/tmp/mitm-bpf"),
telemetry_process_stop_timeout_seconds=_env_float("BACKEND_TELEMETRY_PROCESS_STOP_TIMEOUT_SECONDS", 3.0),
telemetry_reader_join_timeout_seconds=_env_float("BACKEND_TELEMETRY_READER_JOIN_TIMEOUT_SECONDS", 2.0),
nfstream_enabled=_env_bool("BACKEND_NFSTREAM_ENABLED", True),
nfstream_promiscuous_mode=_env_bool("BACKEND_NFSTREAM_PROMISCUOUS_MODE", True),
nfstream_idle_timeout_seconds=_env_int("BACKEND_NFSTREAM_IDLE_TIMEOUT_SECONDS", 120),
nfstream_active_timeout_seconds=_env_int("BACKEND_NFSTREAM_ACTIVE_TIMEOUT_SECONDS", 1800),
nfstream_snapshot_length=_env_int("BACKEND_NFSTREAM_SNAPSHOT_LENGTH", 1536),
nfstream_n_dissections=_env_int("BACKEND_NFSTREAM_N_DISSECTIONS", 20),
nfstream_n_meters=_env_int("BACKEND_NFSTREAM_N_METERS", 1),
nfstream_cache_ttl_seconds=_env_float("BACKEND_NFSTREAM_CACHE_TTL_SECONDS", 10.0),
nfstream_lookup_window_ms=_env_int("BACKEND_NFSTREAM_LOOKUP_WINDOW_MS", 5_000),
nfstream_reader_join_timeout_seconds=_env_float("BACKEND_NFSTREAM_READER_JOIN_TIMEOUT_SECONDS", 2.0),
nfstream_process_stop_timeout_seconds=_env_float("BACKEND_NFSTREAM_PROCESS_STOP_TIMEOUT_SECONDS", 3.0),
tshark_enabled=_env_bool("BACKEND_TSHARK_ENABLED", True),
tshark_display_filter=_env_str("BACKEND_TSHARK_DISPLAY_FILTER", "http or tls or dns"),
tshark_cache_ttl_seconds=_env_float("BACKEND_TSHARK_CACHE_TTL_SECONDS", 5.0),
tshark_match_window_ms=_env_int("BACKEND_TSHARK_MATCH_WINDOW_MS", 1_500),
tshark_reader_join_timeout_seconds=_env_float("BACKEND_TSHARK_READER_JOIN_TIMEOUT_SECONDS", 2.0),
tshark_process_stop_timeout_seconds=_env_float("BACKEND_TSHARK_PROCESS_STOP_TIMEOUT_SECONDS", 3.0),
)