ebpf parsing minimized
All checks were successful
Build and Deploy MITM Webserver / build (push) Successful in 9s

This commit is contained in:
2026-03-07 16:10:52 +01:00
parent 62ac1d4300
commit f55e899fc5

View File

@@ -34,13 +34,6 @@ IDENTITY_FIELDS = (
"src_port", "src_port",
"dst_port", "dst_port",
"length", "length",
"ip_id",
"icmp_type",
"icmp_code",
"arp_op",
"tcp_seq",
"tcp_ack",
"tcp_flags",
) )
BPF_SOURCE = r""" BPF_SOURCE = r"""
@@ -54,8 +47,6 @@ BPF_SOURCE = r"""
#include <linux/in.h> #include <linux/in.h>
#include <linux/tcp.h> #include <linux/tcp.h>
#include <linux/udp.h> #include <linux/udp.h>
#include <linux/icmp.h>
#include <linux/icmpv6.h>
#include <linux/if_arp.h> #include <linux/if_arp.h>
#include <linux/version.h> #include <linux/version.h>
@@ -84,16 +75,9 @@ struct event_t {
__u16 vlan_id; __u16 vlan_id;
__u16 src_port; __u16 src_port;
__u16 dst_port; __u16 dst_port;
__u16 ip_id;
__u16 arp_op;
__u32 protocol_raw; __u32 protocol_raw;
__u32 tcp_seq;
__u32 tcp_ack;
__u8 event_type; __u8 event_type;
__u8 ip_version; __u8 ip_version;
__u8 icmp_type;
__u8 icmp_code;
__u8 tcp_flags;
char ifname[IFNAMSIZ]; char ifname[IFNAMSIZ];
unsigned char src_mac[6]; unsigned char src_mac[6];
unsigned char dst_mac[6]; unsigned char dst_mac[6];
@@ -161,7 +145,6 @@ static __always_inline int parse_skb(struct sk_buff *skb, struct event_t *event)
struct arphdr arph = {}; struct arphdr arph = {};
struct arp_eth_ipv4_t arp_body = {}; struct arp_eth_ipv4_t arp_body = {};
bpf_probe_read_kernel(&arph, sizeof(arph), l3_ptr); bpf_probe_read_kernel(&arph, sizeof(arph), l3_ptr);
event->arp_op = ntohs(arph.ar_op);
if (arph.ar_hrd == htons(ARPHRD_ETHER) && arph.ar_pro == htons(ETH_P_IP) && if (arph.ar_hrd == htons(ARPHRD_ETHER) && arph.ar_pro == htons(ETH_P_IP) &&
arph.ar_hln == ETH_ALEN && arph.ar_pln == 4) { arph.ar_hln == ETH_ALEN && arph.ar_pln == 4) {
bpf_probe_read_kernel(&arp_body, sizeof(arp_body), l3_ptr + sizeof(struct arphdr)); bpf_probe_read_kernel(&arp_body, sizeof(arp_body), l3_ptr + sizeof(struct arphdr));
@@ -177,30 +160,19 @@ static __always_inline int parse_skb(struct sk_buff *skb, struct event_t *event)
bpf_probe_read_kernel(&iph, sizeof(iph), l3_ptr); bpf_probe_read_kernel(&iph, sizeof(iph), l3_ptr);
event->ip_version = 4; event->ip_version = 4;
event->protocol_raw = iph.protocol; event->protocol_raw = iph.protocol;
event->ip_id = ntohs(iph.id);
bpf_probe_read_kernel(event->src_ip, 4, &iph.saddr); bpf_probe_read_kernel(event->src_ip, 4, &iph.saddr);
bpf_probe_read_kernel(event->dst_ip, 4, &iph.daddr); bpf_probe_read_kernel(event->dst_ip, 4, &iph.daddr);
if (iph.protocol == IPPROTO_TCP) { if (iph.protocol == IPPROTO_TCP) {
struct tcphdr tcph = {}; struct tcphdr tcph = {};
unsigned char flags = 0;
bpf_probe_read_kernel(&tcph, sizeof(tcph), head + transport_header); bpf_probe_read_kernel(&tcph, sizeof(tcph), head + transport_header);
event->src_port = ntohs(tcph.source); event->src_port = ntohs(tcph.source);
event->dst_port = ntohs(tcph.dest); event->dst_port = ntohs(tcph.dest);
event->tcp_seq = ntohl(tcph.seq);
event->tcp_ack = ntohl(tcph.ack_seq);
bpf_probe_read_kernel(&flags, sizeof(flags), (void *)(head + transport_header + 13));
event->tcp_flags = flags;
} else if (iph.protocol == IPPROTO_UDP) { } else if (iph.protocol == IPPROTO_UDP) {
struct udphdr udph = {}; struct udphdr udph = {};
bpf_probe_read_kernel(&udph, sizeof(udph), head + transport_header); bpf_probe_read_kernel(&udph, sizeof(udph), head + transport_header);
event->src_port = ntohs(udph.source); event->src_port = ntohs(udph.source);
event->dst_port = ntohs(udph.dest); event->dst_port = ntohs(udph.dest);
} else if (iph.protocol == IPPROTO_ICMP) {
struct icmphdr icmph = {};
bpf_probe_read_kernel(&icmph, sizeof(icmph), head + transport_header);
event->icmp_type = icmph.type;
event->icmp_code = icmph.code;
} }
return 1; return 1;
} }
@@ -215,24 +187,14 @@ static __always_inline int parse_skb(struct sk_buff *skb, struct event_t *event)
if (ip6h.nexthdr == IPPROTO_TCP) { if (ip6h.nexthdr == IPPROTO_TCP) {
struct tcphdr tcph = {}; struct tcphdr tcph = {};
unsigned char flags = 0;
bpf_probe_read_kernel(&tcph, sizeof(tcph), head + transport_header); bpf_probe_read_kernel(&tcph, sizeof(tcph), head + transport_header);
event->src_port = ntohs(tcph.source); event->src_port = ntohs(tcph.source);
event->dst_port = ntohs(tcph.dest); event->dst_port = ntohs(tcph.dest);
event->tcp_seq = ntohl(tcph.seq);
event->tcp_ack = ntohl(tcph.ack_seq);
bpf_probe_read_kernel(&flags, sizeof(flags), (void *)(head + transport_header + 13));
event->tcp_flags = flags;
} else if (ip6h.nexthdr == IPPROTO_UDP) { } else if (ip6h.nexthdr == IPPROTO_UDP) {
struct udphdr udph = {}; struct udphdr udph = {};
bpf_probe_read_kernel(&udph, sizeof(udph), head + transport_header); bpf_probe_read_kernel(&udph, sizeof(udph), head + transport_header);
event->src_port = ntohs(udph.source); event->src_port = ntohs(udph.source);
event->dst_port = ntohs(udph.dest); event->dst_port = ntohs(udph.dest);
} else if (ip6h.nexthdr == IPPROTO_ICMPV6) {
struct icmp6hdr icmp6 = {};
bpf_probe_read_kernel(&icmp6, sizeof(icmp6), head + transport_header);
event->icmp_type = icmp6.icmp6_type;
event->icmp_code = icmp6.icmp6_code;
} }
return 1; return 1;
} }
@@ -313,16 +275,9 @@ class Event(ct.Structure):
("vlan_id", ct.c_ushort), ("vlan_id", ct.c_ushort),
("src_port", ct.c_ushort), ("src_port", ct.c_ushort),
("dst_port", ct.c_ushort), ("dst_port", ct.c_ushort),
("ip_id", ct.c_ushort),
("arp_op", ct.c_ushort),
("protocol_raw", ct.c_uint), ("protocol_raw", ct.c_uint),
("tcp_seq", ct.c_uint),
("tcp_ack", ct.c_uint),
("event_type", ct.c_ubyte), ("event_type", ct.c_ubyte),
("ip_version", ct.c_ubyte), ("ip_version", ct.c_ubyte),
("icmp_type", ct.c_ubyte),
("icmp_code", ct.c_ubyte),
("tcp_flags", ct.c_ubyte),
("ifname", ct.c_char * 16), ("ifname", ct.c_char * 16),
("src_mac", ct.c_ubyte * 6), ("src_mac", ct.c_ubyte * 6),
("dst_mac", ct.c_ubyte * 6), ("dst_mac", ct.c_ubyte * 6),
@@ -387,13 +342,6 @@ def _emit_event(cpu: int, data: int, size: int) -> None:
"protocol_raw": int(event.protocol_raw) or None, "protocol_raw": int(event.protocol_raw) or None,
"src_port": int(event.src_port) or None, "src_port": int(event.src_port) or None,
"dst_port": int(event.dst_port) or None, "dst_port": int(event.dst_port) or None,
"ip_id": int(event.ip_id) or None,
"arp_op": int(event.arp_op) or None,
"icmp_type": int(event.icmp_type) or None,
"icmp_code": int(event.icmp_code) or None,
"tcp_seq": int(event.tcp_seq) or None,
"tcp_ack": int(event.tcp_ack) or None,
"tcp_flags": int(event.tcp_flags) or None,
"reason": _reason_name(int(event.reason)) if event.event_type == 3 else None, "reason": _reason_name(int(event.reason)) if event.event_type == 3 else None,
"reason_code": int(event.reason) if event.event_type == 3 else None, "reason_code": int(event.reason) if event.event_type == 3 else None,
} }