app proto flow determination improvement
All checks were successful
Build and Deploy MITM Webserver / traffic_target (push) Successful in 1s
Build and Deploy MITM Webserver / build (push) Successful in 11s

This commit is contained in:
2026-03-30 22:06:41 +02:00
parent dbd052a7ac
commit de6edd6b68
4 changed files with 111 additions and 50 deletions

View File

@@ -496,6 +496,10 @@ class DatabasePool:
stream_kind: str,
stream_id: int,
observed_at_ms: int,
src_ip: str,
dst_ip: str,
src_port: int,
dst_port: int,
enrichment: Dict[str, Any],
window_ms: int,
) -> int:
@@ -522,12 +526,26 @@ class DatabasePool:
AND (capture_iface = $2 OR ingress_if = $2 OR egress_if = $2)
AND timestamp BETWEEN $5 AND $6
AND (
CASE
WHEN $3 = 'tcp' THEN COALESCE(dpi_metadata -> 'tcp' ->> 'stream', '')
WHEN $3 = 'udp' THEN COALESCE(dpi_metadata -> 'udp' ->> 'stream', '')
ELSE ''
END
) = $4
(
CASE
WHEN $3 = 'tcp' THEN COALESCE(dpi_metadata -> 'tcp' ->> 'stream', '')
WHEN $3 = 'udp' THEN COALESCE(dpi_metadata -> 'udp' ->> 'stream', '')
ELSE ''
END
) = $4
OR (
src_ip = $7::inet
AND dst_ip = $8::inet
AND COALESCE(src_port, 0) = $9
AND COALESCE(dst_port, 0) = $10
)
OR (
src_ip = $8::inet
AND dst_ip = $7::inet
AND COALESCE(src_port, 0) = $10
AND COALESCE(dst_port, 0) = $9
)
)
AND (
app_protocol IS NULL
OR app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH')
@@ -546,21 +564,21 @@ class DatabasePool:
updated_at = NOW(),
app_protocol = CASE
WHEN packets.app_protocol IS NULL OR packets.app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH')
THEN COALESCE($7, packets.app_protocol)
THEN COALESCE($11, packets.app_protocol)
ELSE packets.app_protocol
END,
app_category = CASE
WHEN packets.app_category IS NULL OR packets.app_category IN ('Transport', 'Network', 'Protocol')
THEN COALESCE($8, packets.app_category)
THEN COALESCE($12, packets.app_category)
ELSE packets.app_category
END,
app_confidence = CASE
WHEN packets.app_protocol IS NULL OR packets.app_protocol IN ('TCP', 'UDP', 'IP', 'IPv6', 'ETH')
THEN COALESCE($9, packets.app_confidence)
THEN COALESCE($13, packets.app_confidence)
ELSE packets.app_confidence
END,
app_hostname = COALESCE(packets.app_hostname, $10),
app_is_encrypted = COALESCE(packets.app_is_encrypted, $11),
app_hostname = COALESCE(packets.app_hostname, $14),
app_is_encrypted = COALESCE(packets.app_is_encrypted, $15),
flow_id = COALESCE(
packets.flow_id,
COALESCE(NULLIF(packets.capture_session_id, '') || ':', '') || $3 || ':' || $4
@@ -570,7 +588,7 @@ class DatabasePool:
SELECT DISTINCT source
FROM unnest(
COALESCE(packets.capture_sources, ARRAY[]::text[]) ||
COALESCE($12::text[], ARRAY[]::text[])
COALESCE($16::text[], ARRAY[]::text[])
) AS source
)
)
@@ -584,6 +602,10 @@ class DatabasePool:
str(stream_id),
lower_bound,
upper_bound,
src_ip,
dst_ip,
src_port,
dst_port,
enrichment.get("app_protocol"),
enrichment.get("app_category"),
enrichment.get("app_confidence"),