diff --git a/backend/src/utilities/database.py b/backend/src/utilities/database.py index ae4b63c..4635f9d 100644 --- a/backend/src/utilities/database.py +++ b/backend/src/utilities/database.py @@ -496,10 +496,6 @@ class DatabasePool: stream_kind: str, stream_id: int, observed_at_ms: int, - src_ip: str, - dst_ip: str, - src_port: int, - dst_port: int, enrichment: Dict[str, Any], window_ms: int, ) -> int: @@ -526,29 +522,15 @@ class DatabasePool: AND (capture_iface = $2 OR ingress_if = $2 OR egress_if = $2) AND timestamp BETWEEN $5 AND $6 AND ( - ( - CASE - WHEN $3 = 'tcp' THEN COALESCE(dpi_metadata -> 'tcp' ->> 'stream', '') - WHEN $3 = 'udp' THEN COALESCE(dpi_metadata -> 'udp' ->> 'stream', '') - ELSE '' - END - ) = $4 - OR ( - src_ip = $7::inet - AND dst_ip = $8::inet - AND COALESCE(src_port, 0) = $9 - AND COALESCE(dst_port, 0) = $10 - ) - OR ( - src_ip = $8::inet - AND dst_ip = $7::inet - AND COALESCE(src_port, 0) = $10 - AND COALESCE(dst_port, 0) = $9 - ) - ) + CASE + WHEN $3 = 'tcp' THEN COALESCE(dpi_metadata -> 'tcp' ->> 'stream', '') + WHEN $3 = 'udp' THEN COALESCE(dpi_metadata -> 'udp' ->> 'stream', '') + ELSE '' + END + ) = $4 AND ( app_protocol IS NULL - OR app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH') + OR UPPER(app_protocol) IN ('TCP', 'UDP', 'IP', 'IPV4', 'IPV6', 'ETH', 'ETHERNET', 'ETHERTYPE', 'FRAME', 'DATA') OR app_category IS NULL OR app_category IN ('Transport', 'Network', 'Protocol') OR app_confidence IS NULL @@ -563,22 +545,22 @@ class DatabasePool: SET updated_at = NOW(), app_protocol = CASE - WHEN packets.app_protocol IS NULL OR packets.app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH') - THEN COALESCE($11, packets.app_protocol) + WHEN packets.app_protocol IS NULL OR UPPER(packets.app_protocol) IN ('TCP', 'UDP', 'IP', 'IPV4', 'IPV6', 'ETH', 'ETHERNET', 'ETHERTYPE', 'FRAME', 'DATA') + THEN COALESCE($7, packets.app_protocol) ELSE packets.app_protocol END, app_category = CASE WHEN packets.app_category IS NULL OR packets.app_category IN ('Transport', 'Network', 'Protocol') - THEN COALESCE($12, packets.app_category) + THEN COALESCE($8, packets.app_category) ELSE packets.app_category END, app_confidence = CASE - WHEN packets.app_protocol IS NULL OR packets.app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH') - THEN COALESCE($13, packets.app_confidence) + WHEN packets.app_protocol IS NULL OR UPPER(packets.app_protocol) IN ('TCP', 'UDP', 'IP', 'IPV4', 'IPV6', 'ETH', 'ETHERNET', 'ETHERTYPE', 'FRAME', 'DATA') + THEN COALESCE($9, packets.app_confidence) ELSE packets.app_confidence END, - app_hostname = COALESCE(packets.app_hostname, $14), - app_is_encrypted = COALESCE(packets.app_is_encrypted, $15), + app_hostname = COALESCE(packets.app_hostname, $10), + app_is_encrypted = COALESCE(packets.app_is_encrypted, $11), flow_id = COALESCE( packets.flow_id, COALESCE(NULLIF(packets.capture_session_id, '') || ':', '') || $3 || ':' || $4 @@ -588,7 +570,7 @@ class DatabasePool: SELECT DISTINCT source FROM unnest( COALESCE(packets.capture_sources, ARRAY[]::text[]) || - COALESCE($16::text[], ARRAY[]::text[]) + COALESCE($12::text[], ARRAY[]::text[]) ) AS source ) ) @@ -602,10 +584,6 @@ class DatabasePool: str(stream_id), lower_bound, upper_bound, - src_ip, - dst_ip, - src_port, - dst_port, enrichment.get("app_protocol"), enrichment.get("app_category"), enrichment.get("app_confidence"), diff --git a/backend/src/utilities/tshark_manager.py b/backend/src/utilities/tshark_manager.py index d977e75..1316229 100644 --- a/backend/src/utilities/tshark_manager.py +++ b/backend/src/utilities/tshark_manager.py @@ -956,10 +956,6 @@ class TsharkManager: stream_kind=stream_kind, stream_id=stream_id, observed_at_ms=int(event["observed_at_ms"]), - src_ip=str(event["src_ip"]), - dst_ip=str(event["dst_ip"]), - src_port=int(event["src_port"]), - dst_port=int(event["dst_port"]), enrichment=stream_enrichment, window_ms=max(settings.tshark_match_window_ms, 10_000), )