nfstream debug
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 12s
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 12s
This commit is contained in:
@@ -36,22 +36,38 @@ def _safe_text(value: Any) -> Optional[str]:
|
||||
return text if text else None
|
||||
|
||||
|
||||
def _normalized_label(value: Any) -> Optional[str]:
|
||||
text = _safe_text(value)
|
||||
if text is None:
|
||||
return None
|
||||
if text.isdigit():
|
||||
return None
|
||||
if text.lower() in {"unknown", "other", "unclassified", "none", "null"}:
|
||||
return None
|
||||
return text
|
||||
|
||||
|
||||
def _infer_is_encrypted(payload: Dict[str, Any]) -> Optional[bool]:
|
||||
application_name = str(payload.get("application_name") or "").upper()
|
||||
application_name = str(_normalized_label(payload.get("application_name")) or "").upper()
|
||||
if any(token in application_name for token in ("TLS", "HTTPS", "QUIC", "SSL")):
|
||||
return True
|
||||
if payload.get("requested_server_name") or payload.get("client_fingerprint") or payload.get("server_fingerprint"):
|
||||
return True
|
||||
return None
|
||||
|
||||
|
||||
def _build_enrichment(payload: Dict[str, Any], iface: str, flow_key: str) -> Dict[str, Any]:
|
||||
app_protocol = _normalized_label(payload.get("application_name"))
|
||||
if app_protocol is None and any(payload.get(key) for key in ("user_agent", "content_type")):
|
||||
app_protocol = "HTTP"
|
||||
|
||||
metadata = {
|
||||
"iface": iface,
|
||||
"flow_key": flow_key,
|
||||
"first_seen_ms": int(payload.get("first_seen_ms") or 0) or None,
|
||||
"last_seen_ms": int(payload.get("last_seen_ms") or 0) or None,
|
||||
"event": payload.get("event"),
|
||||
"application_name": _safe_text(payload.get("application_name")),
|
||||
"application_category_name": _safe_text(payload.get("application_category_name")),
|
||||
"application_confidence": _safe_text(payload.get("application_confidence")),
|
||||
"bidirectional_packets": payload.get("bidirectional_packets"),
|
||||
"bidirectional_bytes": payload.get("bidirectional_bytes"),
|
||||
}
|
||||
@@ -67,9 +83,9 @@ def _build_enrichment(payload: Dict[str, Any], iface: str, flow_key: str) -> Dic
|
||||
)
|
||||
|
||||
return {
|
||||
"app_protocol": _safe_text(payload.get("application_name")),
|
||||
"app_master_protocol": _safe_text(payload.get("application_name")),
|
||||
"app_category": _safe_text(payload.get("application_category_name")),
|
||||
"app_protocol": app_protocol,
|
||||
"app_master_protocol": app_protocol,
|
||||
"app_category": _normalized_label(payload.get("application_category_name")),
|
||||
"app_confidence": _safe_text(payload.get("application_confidence")),
|
||||
"app_hostname": _safe_text(payload.get("requested_server_name")),
|
||||
"app_is_encrypted": _infer_is_encrypted(payload),
|
||||
|
||||
Reference in New Issue
Block a user