Refactor: Remove NFStream and flow identity utilities; introduce Tshark manager
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 11s
- Deleted flow_identity.py and nfstream_flow_worker.py as they are no longer needed. - Removed nfstream_manager.py and its associated logic for managing NFStream workers. - Added tshark_manager.py to manage tshark packet enrichment and matching. - Updated setup_build_server.sh to include default environment variables for tshark. - Implemented packet signature generation and enrichment logic in the new TsharkManager class.
This commit is contained in:
@@ -33,9 +33,9 @@ from src.utilities.interface_bridge_helpers import (
|
||||
)
|
||||
from src.config import settings
|
||||
from src.utilities.bridge_telemetry import bridge_telemetry_manager
|
||||
from src.utilities.nfstream_manager import nfstream_manager
|
||||
from src.utilities.packet_identity import build_packet_uid
|
||||
from src.utilities.packet_tracker import packet_tracker
|
||||
from src.utilities.tshark_manager import tshark_manager
|
||||
from src.Models.etherType import EtherTypeEnum, ethertype_from_int
|
||||
from src.Models.ip_protocol import IPProtocolEnum, protocol_from_number
|
||||
|
||||
@@ -371,13 +371,13 @@ def parse_packet(pkt, bridge_label: str, capture_metadata: Optional[Dict[str, An
|
||||
if Raw in pkt and not pkt_info.get("protocol_name"):
|
||||
pkt_info["protocol_name"] = "RAW"
|
||||
|
||||
# Flow-level enrichment using NFStream, if available.
|
||||
# Packet-level enrichment using tshark, if available.
|
||||
try:
|
||||
flow_info = nfstream_manager.lookup_packet(pkt, pkt_iface)
|
||||
if flow_info:
|
||||
_merge_enrichment(pkt_info, flow_info)
|
||||
packet_info = tshark_manager.lookup_packet(pkt, pkt_iface)
|
||||
if packet_info:
|
||||
_merge_enrichment(pkt_info, packet_info)
|
||||
except Exception:
|
||||
logger.exception("NFStream enrichment failed")
|
||||
logger.exception("tshark enrichment failed")
|
||||
|
||||
if ICMP in pkt:
|
||||
inner = pkt[ICMP].payload
|
||||
@@ -536,9 +536,9 @@ def _sync_bridge_telemetry() -> None:
|
||||
}
|
||||
)
|
||||
try:
|
||||
nfstream_manager.update_interfaces(active_enrichment_ifaces)
|
||||
tshark_manager.update_interfaces(active_enrichment_ifaces)
|
||||
except Exception:
|
||||
logger.exception("Failed to update NFStream enrichment workers")
|
||||
logger.exception("Failed to update tshark enrichment workers")
|
||||
|
||||
|
||||
# -------------------------
|
||||
@@ -839,6 +839,6 @@ def get_internal_debug_state() -> dict:
|
||||
"buffer_len": len(_PACKET_BUFFER),
|
||||
"bridge_capture_mode": "tc_ingress_raw" if any(s.get("is_bridge") for s in sessions.values()) else "af_packet",
|
||||
"telemetry_ports": sorted({iface for session in sessions.values() for iface in session.get("ports", [])}),
|
||||
"nfstream": nfstream_manager.get_debug_snapshot(),
|
||||
"tshark": tshark_manager.get_debug_snapshot(),
|
||||
"packet_tracker": packet_tracker.get_debug_snapshot(),
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user