Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 23 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,29 @@
The release notes on GitHub are taken from this file: the section whose
heading is the version number.

## 0.1.2
## 0.2.0

Findings
- traffic66 now looks through the flows every 5 minutes and lists what
needs attention on a new **Findings** page: scans, port scans, password
guessing, lateral movement inside the network, unusual uploads to new
destinations, floods and traffic with addresses on threat lists. Each
finding is a sentence (who did what to whom, when, for how long) with the
numbers behind it and how the data was sampled.
- The rules work on sampled sFlow and NetFlow. Tested with the demo's
attack sent through a switch sampling 1:4096: every step is found, each
as one finding; a day of normal traffic gives no findings apart from the
internet scanner.
- **Dealt with** and **Not a problem** close a finding; "not a problem" is
never reported again. The overview shows the open findings first, a
host's details page lists the findings about it, and the side menu shows
how many high and medium findings are open.

Fixes
- A host's details page counted only part of the internal hosts it talked
to (the servers of internal conversations were missed).
- Arabic and Urdu: ports read backwards ("tcp/445") and names ran into
their addresses.

Drill-down and naming
- **Show details** on any host, device or service opens a page about it:
Expand Down
55 changes: 49 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,11 +14,14 @@ in a web UI and in a terminal UI.
capture from a network interface or mirror port.
- Checks its own numbers against interface counters (sFlow counters or
SNMP) and says why they differ when they do.
- Finds scans, password guessing, lateral movement, unusual uploads, floods
and threat list traffic in the flows, also through sampling, and lists
them as findings to deal with.
- Top 66 lists, flow paths, countries and networks, threat list matches,
flow records, encapsulation (GRE, IPIP, VXLAN, GENEVE, MPLS).
- 13 languages in the web UI and the terminal UI.

![Overview: bandwidth by application compared with last week, top clients and services](docs/images/overview.png)
![Overview: open findings, bandwidth by application compared with last week, top clients and services](docs/images/overview.png)

<sub>All screenshots come from `traffic66 demo`, a simulated company network that you can run yourself (see [Try the demo](#1-try-the-demo)).</sub>

Expand Down Expand Up @@ -83,9 +86,11 @@ cd traffic66-windows-amd64

Open http://127.0.0.1:8066 and sign in as `admin` / `try66`. The demo builds
a small company network with a day of history and live traffic from four
simulated devices, including two incidents to find: start on **Overview**,
click a host in **Top clients**, choose **Show details**, and keep clicking
from there. Stop it with Ctrl+C.
simulated devices, including an attack: **Findings** shows each step of it
(a scan, a port scan, password guessing, lateral movement, an upload to a
control server) and a flood on the public website. Click **Details** on a
finding, or start on **Overview**, click a host in **Top clients**, choose
**Show details**, and keep clicking from there. Stop it with Ctrl+C.
Demo data is kept in `traffic66-demo` next to the program; delete that
folder to start the demo afresh.

Expand Down Expand Up @@ -622,7 +627,8 @@ Pages:

| Page | What it answers |
|---|---|
| Overview | How much traffic now and compared with last week, by application; top clients and services |
| Overview | How much traffic now and compared with last week, by application; open findings; top clients and services |
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Top-N | One table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN |
| Flow paths | Which segment talks to which application in which country |
| Geo & networks | Traffic by country and by network (AS) |
Expand All @@ -648,9 +654,46 @@ The side menu shows how much disk the data uses and how much is free;
hover over the free space to see how much the kept days of detail need at
the current rate (estimated once there is a day of data).

### Findings

**Findings** lists what traffic66 found in the flows, most serious first. It
checks the last 10 minutes every 5 minutes; something that goes on for an
hour is one finding that grows, not a new one at every check.

| Finding | What it means | Severity |
|---|---|---|
| Scan | One address sent small probes to many addresses on one port (TCP or ping) | High from inside your network, low from the internet |
| Port scan | One address sent small probes to many ports of one host | High from inside, low from the internet |
| Password guessing | Many short connections to a login service (SSH, RDP, SMB, databases and others) | High from inside, low from the internet |
| Lateral movement | Inside your network, file sharing or remote administration sessions (SMB, RDP, SSH, WinRM, VNC) to hosts that never offered that service before | High |
| Unusual upload | An internal host sent much more than it received (100 MB in 10 minutes, three times what it received) to an address it had not exchanged data with before | High |
| Flood | 20,000 or more small packets per second to one address, ten times its usual rate | Medium |
| Threat list | Traffic with an address on one of your threat lists | High when your host connected to it, low when the listed address knocked from outside |

Each finding says who did what to whom, when and for how long, with the
numbers behind it and how the data was sampled. **Details** opens the
host's page, which also lists the findings about it. **Dealt with** closes
a finding; if it happens again, a new one opens. **Not a problem** closes it
for good: it is never reported again. The red number next to **Findings** in
the side menu counts the open high and medium findings of the last 24 hours.

Lateral movement and unusual uploads need to know what is normal, so they
are reported once there is a day of history. On first start traffic66
learns from the history it already has.

With sampled data (sFlow, sampled NetFlow) the rules count what the samples
show and ask for fewer of them, but then each must look like one short
probe, so busy normal hosts do not trigger them. What sampling hides cannot
be found: behind 1:4096 sampling, a scan of a few dozen hosts sends too few
packets to be seen. The demo's attack goes through a switch that samples
1:4096 and is found completely; a day of the demo's normal traffic produces
no findings except the internet scanner knocking on the website.

![Findings: every step of an attack, found through 1:4096 sFlow sampling](docs/images/findings.png)

![Top-N: the top 66 conversations of the last hour](docs/images/topn.png)

![Details of one host: its traffic, who it talks to, services, countries and latest flows](docs/images/detail.png)
![Details of one host: the findings about it, its traffic, who it talks to, services, countries and latest flows](docs/images/detail.png)

![Flow paths: which segment uses which application towards which country](docs/images/paths.png)

Expand Down
5 changes: 4 additions & 1 deletion cmd/traffic66/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@ import (
"github.com/githubflyideas/traffic66/internal/auth"
"github.com/githubflyideas/traffic66/internal/capture"
"github.com/githubflyideas/traffic66/internal/collector"
"github.com/githubflyideas/traffic66/internal/detect"
"github.com/githubflyideas/traffic66/internal/dnsres"
"github.com/githubflyideas/traffic66/internal/enrich"
"github.com/githubflyideas/traffic66/internal/flow"
Expand Down Expand Up @@ -299,10 +300,12 @@ func serve(args []string, demo bool) {
ctx, stop := signal.NotifyContext(context.Background(), os.Interrupt, syscall.SIGTERM)
defer stop()

det := detect.New(st, inv, detect.Config{})
if demo {
backfillDemo(pipe, st)
}
go pipe.Run(ctx)
go det.Loop(ctx)

for _, part := range strings.Split(f.listen, ",") {
part = strings.TrimSpace(part)
Expand Down Expand Up @@ -380,7 +383,7 @@ func serve(args []string, demo bool) {
} else {
dns = dnsres.New(dnsres.Options{Upstream: f.dnsUpstream, PerSecond: f.dnsRate, TTL: f.dnsTTL})
}
srv := &api.Server{Store: st, Pipe: pipe, Col: col, Inv: inv, ASN: asn, Thr: thr, DNS: dns, Static: web.FS(), Version: version,
srv := &api.Server{Store: st, Pipe: pipe, Col: col, Inv: inv, ASN: asn, Thr: thr, DNS: dns, Det: det, Static: web.FS(), Version: version,
Demo: demo, Check: checker.Check, Exists: checker.Exists, LocalTok: tok, DataDir: f.data, Started: time.Now()}
srv.SNMP = poller.Status
srv.Capture = func() []api.CaptureInfo {
Expand Down
56 changes: 51 additions & 5 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,11 +16,14 @@
اختياري من واجهة شبكة أو منفذ مرآة.
- يقارن أرقامه بعدّادات الواجهات (عدّادات sFlow أو SNMP) ويشرح سبب
الاختلاف حين يقع.
- يكتشف في التدفقات عمليات المسح وتخمين كلمات المرور والتحرك الجانبي وعمليات
الرفع غير المعتادة والإغراق وحركة قوائم التهديدات، حتى عبر أخذ العينات،
ويعرضها اكتشافاتٍ تحتاج إلى معالجة.
- قوائم أعلى 66، ومسارات الحركة، والدول والشبكات، والتطابقات مع قوائم
التهديدات، وسجلات التدفق، والتغليف (GRE وIPIP وVXLAN وGENEVE وMPLS).
- 13 لغة في واجهة الويب والواجهة الطرفية.

![نظرة عامة: استهلاك عرض النطاق حسب التطبيق مقارنةً بالأسبوع الماضي، وأبرز العملاء والخدمات](images/overview.png)
![نظرة عامة: الاكتشافات المفتوحة، واستهلاك عرض النطاق حسب التطبيق مقارنةً بالأسبوع الماضي، وأبرز العملاء والخدمات](images/overview.png)

<sub>جميع لقطات الشاشة مأخوذة من `traffic66 demo`، وهي شبكة شركة محاكاة يمكنك تشغيلها بنفسك (انظر [جرّب العرض التوضيحي](#1-try-the-demo)).</sub>

Expand Down Expand Up @@ -89,8 +92,11 @@ cd traffic66-windows-amd64

افتح http://127.0.0.1:8066 وسجّل الدخول باسم `admin` وكلمة المرور `try66`.
ينشئ العرض التوضيحي شبكة شركة صغيرة بسجلّ يوم كامل وحركة حية من أربعة أجهزة
محاكاة، وفيها حادثتان عليك اكتشافهما: ابدأ من **نظرة عامة**، وانقر على
مضيف في **أكثر العملاء**، واختر **عرض التفاصيل**، ثم تابع النقر من هناك. أوقفه بـ Ctrl+C. تُحفظ بيانات العرض في
محاكاة، وفيها هجوم: تعرض **الاكتشافات** كل خطوة منه (مسح، ومسح للمنافذ، وتخمين
لكلمات المرور، وتحرك جانبي، ورفع إلى خادم تحكم) وإغراقًا على الموقع العام.
انقر **التفاصيل** على أحد الاكتشافات، أو ابدأ من **نظرة عامة**، وانقر على مضيف
في **أكثر العملاء**، واختر **عرض التفاصيل**، ثم تابع النقر من هناك. أوقفه بـ
Ctrl+C. تُحفظ بيانات العرض في
`traffic66-demo` بجوار البرنامج؛ احذف هذا المجلد لتبدأ العرض من جديد.

يستخدم العرض التوضيحي المنافذ نفسها التي يستخدمها التثبيت الفعلي (8066،
Expand Down Expand Up @@ -646,7 +652,8 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

| الصفحة | ما الذي تجيب عنه |
|---|---|
| نظرة عامة | حجم الحركة الآن ومقارنةً بالأسبوع الماضي حسب التطبيق؛ أبرز العملاء والخدمات |
| نظرة عامة | حجم الحركة الآن ومقارنةً بالأسبوع الماضي حسب التطبيق؛ الاكتشافات المفتوحة؛ أبرز العملاء والخدمات |
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| Top-N | جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN |
| مسارات الحركة | أي مقطع يتواصل مع أي تطبيق في أي دولة |
| الجغرافيا والشبكات | الحركة حسب الدولة وحسب الشبكة (AS) |
Expand All @@ -671,9 +678,48 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
مرّر المؤشر فوق المساحة الحرة لترى ما تحتاجه أيام التفاصيل المحفوظة بالمعدل
الحالي (يُقدَّر ذلك بعد توفر بيانات يوم كامل).

<a id="findings"></a>

### الاكتشافات

تسرد **الاكتشافات** ما وجده traffic66 في التدفقات، الأخطر أولًا. يفحص آخر 10
دقائق كل 5 دقائق؛ والشيء الذي يستمر ساعة هو اكتشاف واحد يكبر، لا اكتشاف جديد
عند كل فحص.

| الاكتشاف | معناه | الخطورة |
|---|---|---|
| مسح | عنوان واحد أرسل مجسّات صغيرة إلى عناوين كثيرة على منفذ واحد (TCP أو ping) | عالية من داخل شبكتك، منخفضة من الإنترنت |
| مسح المنافذ | عنوان واحد أرسل مجسّات صغيرة إلى منافذ كثيرة لمضيف واحد | عالية من الداخل، منخفضة من الإنترنت |
| تخمين كلمات المرور | اتصالات قصيرة كثيرة بخدمة تسجيل دخول (SSH وRDP وSMB وقواعد البيانات وغيرها) | عالية من الداخل، منخفضة من الإنترنت |
| تحرك جانبي | داخل شبكتك، جلسات مشاركة ملفات أو إدارة عن بُعد (SMB وRDP وSSH وWinRM وVNC) إلى مضيفات لم تقدّم تلك الخدمة من قبل | عالية |
| رفع غير معتاد | مضيف داخلي أرسل أكثر بكثير مما استقبل (100 MB في 10 دقائق، ثلاثة أضعاف ما استقبله) إلى عنوان لم يتبادل معه بيانات من قبل | عالية |
| إغراق | 20,000 حزمة صغيرة أو أكثر في الثانية إلى عنوان واحد، عشرة أضعاف معدله المعتاد | متوسطة |
| قائمة التهديدات | حركة مع عنوان في إحدى قوائم التهديدات لديك | عالية حين اتصل مضيفك به، منخفضة حين طرق العنوان المدرج من الخارج |

يبيّن كل اكتشاف من فعل ماذا بمن، ومتى، وكم استمر، مع الأرقام التي يستند إليها
وطريقة أخذ عينات البيانات. يفتح **التفاصيل** صفحة المضيف، التي تسرد أيضًا
الاكتشافات المتعلقة به. ويغلق **تمت المعالجة** الاكتشاف؛ وإن تكرر الأمر فُتح
اكتشاف جديد. أما **ليست مشكلة** فيغلقه نهائيًا: لا يُبلَّغ عنه مرة أخرى أبدًا.
ويعدّ الرقم الأحمر بجوار **الاكتشافات** في القائمة الجانبية الاكتشافات
المفتوحة ذات الخطورة العالية والمتوسطة في آخر 24 ساعة.

يحتاج التحرك الجانبي والرفع غير المعتاد إلى معرفة ما هو طبيعي، لذا لا يُبلَّغ
عنهما إلا بعد توفر سجلّ يوم كامل. وعند التشغيل الأول يتعلّم traffic66 من
السجلّ المتوفر لديه.

مع البيانات المأخوذة بالعينات (sFlow وNetFlow بالعينات) تعدّ القواعد ما تُظهره
العينات وتطلب عددًا أقل منها، لكن يجب حينها أن تبدو كل عينة مجسًّا قصيرًا
واحدًا، كي لا تُطلقها المضيفات الطبيعية المزدحمة. ما يخفيه أخذ العينات لا يمكن
اكتشافه: خلف أخذ عينات بنسبة 1:4096، يرسل مسحٌ لبضع عشرات من المضيفات حزمًا
أقل من أن تُرى. يمر هجوم العرض التوضيحي عبر محوّل يأخذ العينات بنسبة 1:4096
ويُكتشف بالكامل؛ ولا ينتج يوم من الحركة الطبيعية في العرض التوضيحي أي اكتشافات
سوى الماسح القادم من الإنترنت الذي يطرق الموقع.

![الاكتشافات: كل خطوة من هجوم، اكتُشفت عبر أخذ عينات sFlow بنسبة 1:4096](images/findings.png)

![Top-N: أعلى 66 محادثة في الساعة الأخيرة](images/topn.png)

![تفاصيل مضيف واحد: حركته، ومن يتواصل معه، والخدمات، والدول، وأحدث التدفقات](images/detail.png)
![تفاصيل مضيف واحد: الاكتشافات المتعلقة به، وحركته، ومن يتواصل معه، والخدمات، والدول، وأحدث التدفقات](images/detail.png)

![مسارات الحركة: أي مقطع يستخدم أي تطبيق نحو أي دولة](images/paths.png)

Expand Down
Loading
Loading