Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,10 @@ jobs:
- name: Static C libraries (Linux)
if: ${{ matrix.container }}
run: |
rpm -q glibc-static || dnf install -y glibc-static || dnf --enablerepo=powertools install -y glibc-static
# only the distribution's own repositories: fetching every repository's
# metadata from slow mirrors has taken up to 20 minutes
quick="--disablerepo=* --enablerepo=baseos,appstream,powertools --setopt=install_weak_deps=False --setopt=timeout=30 --setopt=retries=5"
rpm -q glibc-static || timeout 600 dnf $quick install -y glibc-static || dnf install -y glibc-static || dnf --enablerepo=powertools install -y glibc-static
- name: Resolve modules
run: go mod tidy
- name: Vet
Expand Down
20 changes: 19 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,10 +21,28 @@ Findings
host's details page lists the findings about it, and the side menu shows
how many high and medium findings are open.

Charts and filters (compared with ElastiFlow's dashboards)
- **Device**, **Client**, **Server** and **Service** filter boxes above every
page list the busiest values of the time range.
- Top 66 opens on **Talkers**: traffic by service over time and the top 30
clients and servers with traffic, packets and flow records, and a row for
all traffic. The regroupable table is one click away.
- New page **Traffic details**: clients, servers and services over time in
bits/s and packets/s.
- Interface check shows every interface's traffic over time (ingress and
egress, bits/s and packets/s); Geo & networks shows source and
destination networks (AS) over time.
- Flow records shows how many records there were and when, and pages
through all of them.
- Flow paths can show client → service → server.
- Charts use 8 fixed colours checked for colour-blind readers; the rest is
Other.

Pages
- Flow paths start from each host by default (the 10 busiest, the rest as
Other); **By network** switches back to network segments.
- The overview shows the findings below the traffic chart.
- The overview shows the findings below the traffic chart, and no longer
the "remote location" chart or the change column in Top clients.
- Top-N is called Top 66 and comes right after Overview in the menu.
- Your own logo: **Sources → Logo** takes a PNG, SVG, JPEG, WebP or GIF
(best at 272 × 92 pixels) for the sign-in page and the top of the menu.
Expand Down
36 changes: 24 additions & 12 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,9 @@ in a web UI and in a terminal UI.
- Finds scans, password guessing, lateral movement, unusual uploads, floods
and threat list traffic in the flows, also through sampling, and lists
them as findings to deal with.
- Top 66 lists, flow paths, countries and networks, threat list matches,
flow records, encapsulation (GRE, IPIP, VXLAN, GENEVE, MPLS).
- Top 66 lists, traffic over time by client, server, service, interface
and network (AS), flow paths, countries, threat list matches, flow
records, encapsulation (GRE, IPIP, VXLAN, GENEVE, MPLS).
- 13 languages in the web UI and the terminal UI.

![Overview: open findings, bandwidth by application compared with last week, top clients and services](docs/images/overview.png)
Expand Down Expand Up @@ -503,7 +504,7 @@ traffic66 compares them with the device's own interface counters and shows
the difference on **Interface check**, with the likely cause when it is
larger than sampling alone explains.

![Interface check: flow estimate next to the device counter for every interface](docs/images/interfaces.png)
![Interface check: traffic of every interface, and the flow estimate next to the device counter](docs/images/interfaces.png)

To get counters to compare with:

Expand Down Expand Up @@ -627,21 +628,30 @@ Pages:

| Page | What it answers |
|---|---|
| Overview | How much traffic now and compared with last week, by application; open findings; top clients and services |
| Top 66 | One table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN |
| Overview | How much traffic now and compared with last week, by application; open findings; direction and protocol; top clients and services |
| Top 66 | Opens on **Talkers**: traffic by service over time, and the top 30 clients and servers side by side with traffic, packets and flow records, above a row for all traffic. **Table** is one table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN |
| Traffic details | Clients, servers and services over time, in bits/s and in packets/s: the top 8 of each, and how many there were |
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Flow paths | Which host uses which application towards which country: the 10 busiest hosts, the rest as Other. **By network** shows networks instead of hosts |
| Geo & networks | Traffic by country and by network (AS) |
| Flow paths | Which host uses which application towards which country: the 8 busiest hosts, the rest as Other. **Client → server** shows client → service → server; **By network** shows networks instead of hosts |
| Geo & networks | The networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Flow records | Individual flows, newest first, with selectable columns |
| Interface check | Flow numbers next to the interface counters, worst first, with reasons |
| Flow records | How many flow records there were and when (a bar per interval), and the records themselves, newest first, page by page, with selectable columns |
| Interface check | Traffic of every interface over time (ingress and egress, bits/s and packets/s), and flow numbers next to the interface counters, worst first, with reasons |
| Sources | Devices, sampling, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |

Above the pages: time range (15 minutes to 30 days), an optional search
box, automatic refresh every 30 seconds, and **Copy link**, which copies a
link to exactly the current view (page, time range and filters) to send to
a colleague. The language follows the browser; change it at the bottom of
the menu.
a colleague. Under them, **Device**, **Client**, **Server** and **Service**
list the busiest values of the time range: pick one, or type one, to filter
every page; empty the box to remove the filter. The language follows the
browser; change it at the bottom of the menu.

Charts over time show the 8 largest values in fixed colours and the rest as
Other; the legend gives each value's total and can be clicked like any
other value. Charts of clients and servers leave the rest out of the
drawing, since with thousands of hosts it would flatten the top 8; the
legend still gives its total.

Ranges longer than 6 hours start on a whole hour, so every number on the
page counts exactly the same time: "24 hours" covers the last 24 whole
Expand Down Expand Up @@ -696,7 +706,9 @@ no findings except the internet scanner knocking on the website.

![Findings: every step of an attack, found through 1:4096 sFlow sampling](docs/images/findings.png)

![Top 66: the top 66 conversations of the last hour](docs/images/topn.png)
![Top 66, Talkers: traffic by service, and the top 30 clients and servers with a row for all traffic](docs/images/topn.png)

![Traffic details: clients, servers and services over time, in bits/s and packets/s](docs/images/traffic.png)

![Details of one host: the findings about it, its traffic, who it talks to, services, countries and latest flows](docs/images/detail.png)

Expand Down
35 changes: 23 additions & 12 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,9 @@
- يكتشف في التدفقات عمليات المسح وتخمين كلمات المرور والتحرك الجانبي وعمليات
الرفع غير المعتادة والإغراق وحركة قوائم التهديدات، حتى عبر أخذ العينات،
ويعرضها اكتشافاتٍ تحتاج إلى معالجة.
- قوائم أعلى 66، ومسارات الحركة، والدول والشبكات، والتطابقات مع قوائم
التهديدات، وسجلات التدفق، والتغليف (GRE وIPIP وVXLAN وGENEVE وMPLS).
- قوائم أعلى 66، والحركة عبر الزمن حسب العميل والخادم والخدمة والواجهة
والشبكة (AS)، ومسارات الحركة، والدول، والتطابقات مع قوائم التهديدات،
وسجلات التدفق، والتغليف (GRE وIPIP وVXLAN وGENEVE وMPLS).
- 13 لغة في واجهة الويب والواجهة الطرفية.

![نظرة عامة: الاكتشافات المفتوحة، واستهلاك عرض النطاق حسب التطبيق مقارنةً بالأسبوع الماضي، وأبرز العملاء والخدمات](images/overview.png)
Expand Down Expand Up @@ -528,7 +529,7 @@ softflowd -i eth0 -n 192.0.2.50:2055 -v 9 -t maxlife=60
**مطابقة الواجهات**، مع السبب المرجّح حين يكون الفرق أكبر مما يفسّره أخذ
العينات وحده.

![مطابقة الواجهات: تقدير التدفقات بجوار عدّاد الجهاز لكل واجهة](images/interfaces.png)
![مطابقة الواجهات: حركة كل واجهة، وتقدير التدفقات بجوار عدّاد الجهاز](images/interfaces.png)

للحصول على عدّادات للمقارنة:

Expand Down Expand Up @@ -653,20 +654,28 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

| الصفحة | ما الذي تجيب عنه |
|---|---|
| نظرة عامة | حجم الحركة الآن ومقارنةً بالأسبوع الماضي حسب التطبيق؛ الاكتشافات المفتوحة؛ أبرز العملاء والخدمات |
| أعلى 66 | جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN |
| نظرة عامة | حجم الحركة الآن ومقارنةً بالأسبوع الماضي حسب التطبيق؛ الاكتشافات المفتوحة؛ الاتجاه والبروتوكول؛ أبرز العملاء والخدمات |
| أعلى 66 | تُفتح على **أكثر الأطراف نشاطًا**: الحركة حسب الخدمة عبر الزمن، وأعلى 30 عميلًا وخادمًا جنبًا إلى جنب مع الحركة والحزم وسجلات التدفق، فوق صف لكل الحركة. أما **جدول** فهو جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN |
| تفاصيل الحركة | العملاء والخوادم والخدمات عبر الزمن، بوحدة bits/s وpackets/s: أعلى 8 من كل منها، وكم كان عددها |
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| مسارات الحركة | أي مضيف يستخدم أي تطبيق نحو أي دولة: أكثر 10 مضيفات نشاطًا، والباقي ضمن «أخرى». ويعرض **حسب المقطع** الشبكات بدل المضيفات |
| الجغرافيا والشبكات | الحركة حسب الدولة وحسب الشبكة (AS) |
| مسارات الحركة | أي مضيف يستخدم أي تطبيق نحو أي دولة: أكثر 8 مضيفات نشاطًا، والباقي ضمن «أخرى». ويعرض **العميل ← الخادم** العميل ← الخدمة ← الخادم؛ ويعرض **حسب المقطع** الشبكات بدل المضيفات |
| الجغرافيا والشبكات | الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| سجلات التدفق | التدفقات الفردية، الأحدث أولًا، مع أعمدة قابلة للاختيار |
| مطابقة الواجهات | أرقام التدفقات بجوار عدّادات الواجهات، الأسوأ أولًا، مع الأسباب |
| سجلات التدفق | كم سجل تدفق كان هناك ومتى (شريط لكل فترة)، والسجلات نفسها، الأحدث أولًا، صفحةً صفحة، مع أعمدة قابلة للاختيار |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن (الدخول والخروج، bits/s وpackets/s)، وأرقام التدفقات بجوار عدّادات الواجهات، الأسوأ أولًا، مع الأسباب |
| المصادر | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |

فوق الصفحات: النطاق الزمني (من 15 دقيقة إلى 30 يومًا)، ومربع بحث اختياري،
وتحديث تلقائي كل 30 ثانية، و**نسخ الرابط** الذي ينسخ رابطًا إلى العرض
الحالي بالضبط (الصفحة والنطاق الزمني والمرشّحات) لإرساله إلى زميل. تتبع
اللغة إعدادات المتصفح؛ ويمكن تغييرها من أسفل القائمة.
الحالي بالضبط (الصفحة والنطاق الزمني والمرشّحات) لإرساله إلى زميل. وتحتها
تعرض **الجهاز** و**العميل** و**الخادم** و**الخدمة** أكثر القيم نشاطًا في النطاق
الزمني: اختر قيمة أو اكتبها لتصفية كل الصفحات؛ وأفرغ المربع لإزالة المرشّح.
تتبع اللغة إعدادات المتصفح؛ ويمكن تغييرها من أسفل القائمة.

تعرض المخططات عبر الزمن أكبر 8 قيم بألوان ثابتة والباقي ضمن «أخرى»؛ وتعطي
وسيلة الإيضاح مجموع كل قيمة، ويمكن النقر عليها كأي قيمة أخرى. ولا ترسم مخططات
العملاء والخوادم الباقي، لأنه مع آلاف المضيفات سيُسطّح أعلى 8؛ لكن وسيلة
الإيضاح تبقى تعطي مجموعه.

تبدأ النطاقات الأطول من 6 ساعات عند ساعة كاملة، كي يحسب كل رقم في الصفحة
الفترة الزمنية نفسها تمامًا: يغطي "24 ساعة" آخر 24 ساعة كاملة إضافةً إلى
Expand Down Expand Up @@ -723,7 +732,9 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

![الاكتشافات: كل خطوة من هجوم، اكتُشفت عبر أخذ عينات sFlow بنسبة 1:4096](images/findings.png)

![أعلى 66: أعلى 66 محادثة في الساعة الأخيرة](images/topn.png)
![أعلى 66، أكثر الأطراف نشاطًا: الحركة حسب الخدمة، وأعلى 30 عميلًا وخادمًا مع صف لكل الحركة](images/topn.png)

![تفاصيل الحركة: العملاء والخوادم والخدمات عبر الزمن، بوحدة bits/s وpackets/s](images/traffic.png)

![تفاصيل مضيف واحد: الاكتشافات المتعلقة به، وحركته، ومن يتواصل معه، والخدمات، والدول، وأحدث التدفقات](images/detail.png)

Expand Down
Loading
Loading