Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,14 @@ Findings
host's details page lists the findings about it, and the side menu shows
how many high and medium findings are open.

Pages
- Flow paths start from each host by default (the 10 busiest, the rest as
Other); **By network** switches back to network segments.
- The overview shows the findings below the traffic chart.
- Top-N is called Top 66 and comes right after Overview in the menu.
- Your own logo: **Sources → Logo** takes a PNG, SVG, JPEG, WebP or GIF
(best at 272 × 92 pixels) for the sign-in page and the top of the menu.

Fixes
- A host's details page counted only part of the internal hosts it talked
to (the servers of internal conversations were missed).
Expand Down
24 changes: 15 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -558,8 +558,8 @@ snmp 192.0.2.9 s3cret 10.99.0.9:161

- `net`: private ranges (10/8, 172.16/12, 192.168/16, 100.64/10) are
always yours. Add your public ranges so traffic to and from them counts
as yours too; the name shows up in **Top-N → Segments** and in the flow
paths.
as yours too; the name shows up in **Top 66** grouped by segment and in
the flow paths by network.
- `snmp <device> <community> [<management address>[:port]]`: the device
is the address flows come from. Add the management address when the
device answers SNMP on another address. Interface descriptions read over
Expand Down Expand Up @@ -628,14 +628,14 @@ Pages:
| Page | What it answers |
|---|---|
| Overview | How much traffic now and compared with last week, by application; open findings; top clients and services |
| Top 66 | One table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN |
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Top-N | One table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN |
| Flow paths | Which segment talks to which application in which country |
| Flow paths | Which host uses which application towards which country: the 10 busiest hosts, the rest as Other. **By network** shows networks instead of hosts |
| Geo & networks | Traffic by country and by network (AS) |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Flow records | Individual flows, newest first, with selectable columns |
| Interface check | Flow numbers next to the interface counters, worst first, with reasons |
| Sources | Devices, sampling, loss, collectors, SNMP, the countries and networks database, and **Names** |
| Sources | Devices, sampling, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |

Above the pages: time range (15 minutes to 30 days), an optional search
box, automatic refresh every 30 seconds, and **Copy link**, which copies a
Expand All @@ -645,7 +645,7 @@ the menu.

Ranges longer than 6 hours start on a whole hour, so every number on the
page counts exactly the same time: "24 hours" covers the last 24 whole
hours plus the current one. Top-N over these ranges comes from hourly
hours plus the current one. Top 66 over these ranges comes from hourly
summaries; filters are not available there, and the page says so. Choose a
shorter range to filter. Conversations always read the flow detail, so over long ranges
at high flow rates they can take a while; one hour is fastest.
Expand All @@ -654,6 +654,11 @@ The side menu shows how much disk the data uses and how much is free;
hover over the free space to see how much the kept days of detail need at
the current rate (estimated once there is a day of data).

To show your own logo on the sign-in page and at the top of the menu, use
**Sources → Logo → Upload a logo…**: PNG, SVG, JPEG, WebP or GIF, up to
1 MB, best at 272 × 92 pixels (other sizes are scaled to fit). **Use the
built-in logo** goes back to traffic66's.

### Findings

**Findings** lists what traffic66 found in the flows, most serious first. It
Expand Down Expand Up @@ -691,11 +696,11 @@ no findings except the internet scanner knocking on the website.

![Findings: every step of an attack, found through 1:4096 sFlow sampling](docs/images/findings.png)

![Top-N: the top 66 conversations of the last hour](docs/images/topn.png)
![Top 66: the top 66 conversations of the last hour](docs/images/topn.png)

![Details of one host: the findings about it, its traffic, who it talks to, services, countries and latest flows](docs/images/detail.png)

![Flow paths: which segment uses which application towards which country](docs/images/paths.png)
![Flow paths: which host uses which application towards which country](docs/images/paths.png)

The same overview in Chinese; every page is available in 13 languages:

Expand All @@ -721,7 +726,7 @@ view in a browser, q quit.

![Terminal UI: overview](docs/images/tui-overview.png)

![Terminal UI: Top-N conversations](docs/images/tui-topn.png)
![Terminal UI: Top 66 conversations](docs/images/tui-topn.png)

## 11. Local capture

Expand Down Expand Up @@ -855,6 +860,7 @@ The data directory holds everything:
| `traffic66.duckdb` | summaries, interface counters and the current hour |
| `password` | login passwords (hashed) |
| `inventory.txt` | names (**Sources → Names**) |
| `logo.png` (or `.svg`, `.jpg`, `.webp`, `.gif`) | your logo (**Sources → Logo**), if you uploaded one |
| `country.mmdb`, `asn.mmdb`, `asn.tsv.gz`, `threats/` | countries and networks databases and threat lists you added |

**How long data is kept**: flow detail 30 days, summaries (overview and long
Expand Down
11 changes: 10 additions & 1 deletion cmd/traffic66/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -370,7 +370,16 @@ func serve(args []string, demo bool) {
startDemoAgents(ctx, s)
log.Printf("demo: simulated exporters are running (core router, switch, firewall, branch router)")
}
go poller.Run(ctx)
go func() {
if demo { // let the simulated devices count a few seconds first
select {
case <-ctx.Done():
return
case <-time.After(10 * time.Second):
}
}
poller.Run(ctx)
}()

checker := loginChecker(f.data, f.user, f.password)
tok := randomHex(24)
Expand Down
23 changes: 15 additions & 8 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -584,7 +584,8 @@ snmp 192.0.2.9 s3cret 10.99.0.9:161

- `net`: النطاقات الخاصة (10/8 و172.16/12 و192.168/16 و100.64/10) تُعدّ
دائمًا نطاقاتك. أضف نطاقاتك العامة كي تُحتسب الحركة منها وإليها لك أيضًا؛
ويظهر الاسم في **Top-N ← المقاطع** وفي مسارات الحركة.
ويظهر الاسم في **أعلى 66** عند التجميع حسب المقطع، وفي مسارات الحركة حسب
الشبكة.
- `snmp <device> <community> [<management address>[:port]]`: الجهاز هو
العنوان الذي تأتي منه التدفقات. أضف عنوان الإدارة إذا كان الجهاز يجيب
على SNMP من عنوان آخر. تُستخدم أوصاف الواجهات المقروءة عبر SNMP أسماءً
Expand Down Expand Up @@ -653,14 +654,14 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
| الصفحة | ما الذي تجيب عنه |
|---|---|
| نظرة عامة | حجم الحركة الآن ومقارنةً بالأسبوع الماضي حسب التطبيق؛ الاكتشافات المفتوحة؛ أبرز العملاء والخدمات |
| أعلى 66 | جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN |
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| Top-N | جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN |
| مسارات الحركة | أي مقطع يتواصل مع أي تطبيق في أي دولة |
| مسارات الحركة | أي مضيف يستخدم أي تطبيق نحو أي دولة: أكثر 10 مضيفات نشاطًا، والباقي ضمن «أخرى». ويعرض **حسب المقطع** الشبكات بدل المضيفات |
| الجغرافيا والشبكات | الحركة حسب الدولة وحسب الشبكة (AS) |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| سجلات التدفق | التدفقات الفردية، الأحدث أولًا، مع أعمدة قابلة للاختيار |
| مطابقة الواجهات | أرقام التدفقات بجوار عدّادات الواجهات، الأسوأ أولًا، مع الأسباب |
| المصادر | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، و**الأسماء** |
| المصادر | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |

فوق الصفحات: النطاق الزمني (من 15 دقيقة إلى 30 يومًا)، ومربع بحث اختياري،
وتحديث تلقائي كل 30 ثانية، و**نسخ الرابط** الذي ينسخ رابطًا إلى العرض
Expand All @@ -669,7 +670,7 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

تبدأ النطاقات الأطول من 6 ساعات عند ساعة كاملة، كي يحسب كل رقم في الصفحة
الفترة الزمنية نفسها تمامًا: يغطي "24 ساعة" آخر 24 ساعة كاملة إضافةً إلى
الساعة الجارية. تُبنى Top-N لهذه النطاقات من ملخّصات ساعية؛ والمرشّحات غير
الساعة الجارية. تُبنى صفحة أعلى 66 لهذه النطاقات من ملخّصات ساعية؛ والمرشّحات غير
متاحة فيها، وتنبّه الصفحة إلى ذلك. اختر نطاقًا أقصر لتتمكن من التصفية. تقرأ المحادثات تفاصيل
التدفقات دائمًا، لذا قد تستغرق بعض الوقت في النطاقات الطويلة عند معدلات
التدفق العالية؛ ونطاق الساعة الواحدة هو الأسرع.
Expand All @@ -678,6 +679,11 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
مرّر المؤشر فوق المساحة الحرة لترى ما تحتاجه أيام التفاصيل المحفوظة بالمعدل
الحالي (يُقدَّر ذلك بعد توفر بيانات يوم كامل).

لعرض شعارك في صفحة تسجيل الدخول وأعلى القائمة، استخدم
**المصادر ← الشعار ← رفع شعار…**: PNG أو SVG أو JPEG أو WebP أو GIF، حتى 1 MB،
وأفضل مقاس 272 × 92 بكسل (تُحجَّم المقاسات الأخرى لتلائم). ويعيد
**العودة إلى الشعار المدمج** شعار traffic66.

<a id="findings"></a>

### الاكتشافات
Expand Down Expand Up @@ -717,11 +723,11 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

![الاكتشافات: كل خطوة من هجوم، اكتُشفت عبر أخذ عينات sFlow بنسبة 1:4096](images/findings.png)

![Top-N: أعلى 66 محادثة في الساعة الأخيرة](images/topn.png)
![أعلى 66: أعلى 66 محادثة في الساعة الأخيرة](images/topn.png)

![تفاصيل مضيف واحد: الاكتشافات المتعلقة به، وحركته، ومن يتواصل معه، والخدمات، والدول، وأحدث التدفقات](images/detail.png)

![مسارات الحركة: أي مقطع يستخدم أي تطبيق نحو أي دولة](images/paths.png)
![مسارات الحركة: أي مضيف يستخدم أي تطبيق نحو أي دولة](images/paths.png)

النظرة العامة نفسها باللغة الصينية؛ كل صفحة متاحة بـ 13 لغة:

Expand Down Expand Up @@ -749,7 +755,7 @@ traffic66 -tui # collect and show the termina

![الواجهة الطرفية: نظرة عامة](images/tui-overview.png)

![الواجهة الطرفية: أعلى المحادثات في Top-N](images/tui-topn.png)
![الواجهة الطرفية: محادثات أعلى 66](images/tui-topn.png)

<a id="11-local-capture"></a>

Expand Down Expand Up @@ -898,6 +904,7 @@ traffic66 -data /var/lib/traffic66 -listen "sflow=:6343,netflow=:2055,ipfix=:473
| `traffic66.duckdb` | الملخّصات وعدّادات الواجهات والساعة الجارية |
| `password` | كلمات مرور تسجيل الدخول (مُجزّأة) |
| `inventory.txt` | الأسماء (**المصادر ← الأسماء**) |
| `logo.png` (أو `.svg`، `.jpg`، `.webp`، `.gif`) | شعارك (**المصادر ← الشعار**)، إن كنت قد رفعته |
| `country.mmdb`، `asn.mmdb`، `asn.tsv.gz`، `threats/` | قواعد بيانات الدول والشبكات وقوائم التهديدات التي أضفتها |

**مدة الاحتفاظ بالبيانات**: تفاصيل التدفقات 30 يومًا، والملخصات (النظرة العامة والفترات الطويلة) 400 يوم.
Expand Down
Loading
Loading