add more sankey options
All checks were successful
Build and Deploy MITM Webserver / traffic_target (push) Successful in 1s
Build and Deploy MITM Webserver / build (push) Successful in 10s

This commit is contained in:
2026-03-30 23:07:14 +02:00
parent 1a0d220f11
commit 5f6eedf859
4 changed files with 239 additions and 42 deletions

View File

@@ -20,6 +20,17 @@ class InterfaceHostEvidence(BaseModel):
destination_on_egress_count: int = Field(..., description="Packets where this endpoint appeared as the destination on egress.")
class ProtocolLayerPathEvidence(BaseModel):
ethernet_protocol: Optional[str] = Field(None, description="Ethernet protocol label for this path, if known.")
ip_protocol: Optional[str] = Field(None, description="IP protocol label for this path, if known.")
packet_count: int = Field(..., description="Packet observations supporting this path.")
last_seen: datetime = Field(..., description="Most recent packet timestamp supporting this path.")
accept_count: int = Field(0, description="Packets with verdict=accept for this path.")
drop_count: int = Field(0, description="Packets with verdict=drop for this path.")
reject_count: int = Field(0, description="Packets with verdict=reject for this path.")
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
class ProtocolEvidence(BaseModel):
protocol: str = Field(..., description="Detected application or fallback transport/network protocol.")
packet_count: int = Field(..., description="Packet observations supporting this interface-host-protocol mapping.")
@@ -30,23 +41,12 @@ class ProtocolEvidence(BaseModel):
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
ethernet_protocol: Optional[str] = Field(None, description="Dominant Ethernet protocol associated with this protocol evidence.")
ip_protocol: Optional[str] = Field(None, description="Dominant IP protocol associated with this protocol evidence.")
layer_paths: List["ProtocolLayerPathEvidence"] = Field(
layer_paths: List[ProtocolLayerPathEvidence] = Field(
default_factory=list,
description="Optional Ethernet/IP breakdown contributing to this protocol evidence.",
)
class ProtocolLayerPathEvidence(BaseModel):
ethernet_protocol: Optional[str] = Field(None, description="Ethernet protocol label for this path, if known.")
ip_protocol: Optional[str] = Field(None, description="IP protocol label for this path, if known.")
packet_count: int = Field(..., description="Packet observations supporting this path.")
last_seen: datetime = Field(..., description="Most recent packet timestamp supporting this path.")
accept_count: int = Field(0, description="Packets with verdict=accept for this path.")
drop_count: int = Field(0, description="Packets with verdict=drop for this path.")
reject_count: int = Field(0, description="Packets with verdict=reject for this path.")
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
class InterfaceHostProtocolEvidence(InterfaceHostEvidence):
protocols: List[ProtocolEvidence] = Field(default_factory=list, description="Protocols observed for this host on the interface.")