Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 17 additions & 6 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,12 +61,20 @@ Drill-down and naming
- **Name it…** on any host or device names it on the spot; the name is
saved and shown everywhere. The Names box on Sources now shows examples.

Countries and networks database
- Upload a database on the Sources page: MaxMind GeoLite2 or DB-IP Lite
`.mmdb` files (country or ASN) or an IP-to-ASN table (`.tsv`, `.tsv.gz`).
It is checked, saved and used for new traffic at once, without a
restart. The `.mmdb` reader was checked against MaxMind's own reader on
60,000 lookups in six DB-IP databases with no difference.
Countries and networks
- Works out of the box: DB-IP's free country and ASN databases (CC BY 4.0)
are built in, so countries and networks show without uploading anything.
**Update DB-IP Lite now** on the Sources page downloads this month's
version.
- Sources lists the free databases (DB-IP Lite, MaxMind GeoLite2, IPinfo
Lite, IPtoASN) with their licences and where to get them. Uploaded files
are used first and the built-in DB-IP Lite answers the rest; **Remove**
goes back. IPinfo Lite, which holds countries and networks in one file,
is now understood.
- The `.mmdb` reader was checked against MaxMind's own reader on 60,000
lookups in six DB-IP databases with no difference.
- **Geo & networks** shows remote traffic on a world map; point at a country
for its traffic, click it to filter.

Simpler pages
- Top-N is one table: conversations (client, server, service, country) by
Expand All @@ -76,6 +84,9 @@ Simpler pages
smallest average packet size finds scanners and floods. The row of
eleven tabs is gone.
- "Who grew" is gone from the overview (web and terminal UI).
- Narrow windows: the menu, time range and tables no longer push the page
wider than the window, and "Log out" stays inside the menu in every
language.
- Flow paths: labels, bars and flows can all be clicked; before, only the
thin bars could.
- The side menu no longer shows group headings that looked like buttons;
Expand Down
52 changes: 34 additions & 18 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -570,27 +570,43 @@ snmp 192.0.2.9 s3cret 10.99.0.9:161

## 8. Countries, networks and threat lists

Countries and network (AS) names need a database that maps addresses to
them. Upload one in the web UI: **Sources → Countries and networks
database → Upload a database file…**. It is checked, saved in the data
Countries and networks (AS) work out of the box: traffic66 has DB-IP's free
**IP to Country Lite** and **IP to ASN Lite** databases built in (licensed
[CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); "IP Geolocation
by DB-IP", [db-ip.com](https://db-ip.com)). The pages that show countries
and networks name the data's source.

The built-in copy is from the release you run. DB-IP publishes a new one
every month; **Sources → Countries and networks database → Update DB-IP
Lite now** downloads the latest from db-ip.com (the server running
traffic66 needs internet access for this; the web UI says so if it fails).

You can also use another free database. Download it, then upload it on the
same page with **Upload a database file…**. It is checked, saved in the data
directory and used for new traffic at once; no restart is needed. Traffic
already stored keeps the country it was saved with.

Accepted files:
| Database | Gives | Licence | Where to get it |
|---|---|---|---|
| DB-IP Lite (built in) | countries; networks | CC BY 4.0, no account | [db-ip.com/db/lite.php](https://db-ip.com/db/lite.php) |
| MaxMind GeoLite2 Country and ASN, `.mmdb` | countries; networks | GeoLite2 EULA, free account | [maxmind.com](https://www.maxmind.com/en/geolite2/signup) |
| IPinfo Lite, `ipinfo_lite.mmdb` | countries and networks in one file | CC BY-SA 4.0, free account | [ipinfo.io/lite](https://ipinfo.io/lite) |
| IPtoASN, `ip2asn-combined.tsv.gz` | networks with their country | PDDL 1.0, no account | [iptoasn.com](https://iptoasn.com) |

| File | Gives | Where to get it |
|---|---|---|
| DB-IP Lite country or ASN, `.mmdb` | country, or AS number and name | free, no account: [db-ip.com/db/lite.php](https://db-ip.com/db/lite.php) |
| MaxMind GeoLite2 Country or ASN, `.mmdb` | country, or AS number and name | free with a MaxMind account: [maxmind.com](https://www.maxmind.com/en/geolite2/signup) |
| IP-to-ASN table, `.tsv` or `.tsv.gz` | AS number, AS name and country | free: [iptoasn.com](https://iptoasn.com) (`ip2asn-combined.tsv.gz`) |

Upload a country database and an ASN database to get both; where several
are loaded, the `.mmdb` files take precedence for what they contain. New
versions come out monthly: upload the new file the same way to replace the
old one.
Your own files are used first; the built-in DB-IP Lite answers what they
do not cover. **Remove** next to a file goes back to the rest. The page
lists what is in use and the date of each database.

Without the web UI, copy the file into the data directory as
`country.mmdb`, `asn.mmdb` or `asn.tsv.gz` and restart traffic66.
`country.mmdb`, `asn.mmdb`, `both.mmdb` (a file with countries and
networks, such as IPinfo Lite) or `asn.tsv.gz` and restart traffic66.

**Geo & networks** shows the traffic to and from other countries on a
world map: the darker a country, the more traffic. Point at a country for
its traffic; click it to filter or open its flow records. Country outlines
come from [Natural Earth](https://www.naturalearthdata.com) (public domain).

![Geo & networks: remote traffic by country on a world map](docs/images/geo.png)

Threat lists are plain text files with one address or network per line
(text after `#` or `;` is ignored), saved as `<data directory>/threats/<name>.txt`, for
Expand Down Expand Up @@ -633,7 +649,7 @@ Pages:
| Traffic details | Clients, servers and services over time, in bits/s and in packets/s: the top 8 of each, and how many there were |
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Flow paths | Which host uses which application towards which country: the 8 busiest hosts, the rest as Other. **Client → server** shows client → service → server; **By network** shows networks instead of hosts |
| Geo & networks | The networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Geo & networks | A world map of traffic by country; the networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Flow records | How many flow records there were and when (a bar per interval), and the records themselves, newest first, page by page, with selectable columns |
| Interface check | Traffic of every interface over time (ingress and egress, bits/s and packets/s), and flow numbers next to the interface counters, worst first, with reasons |
Expand Down Expand Up @@ -847,7 +863,7 @@ Options of `traffic66` and `traffic66 demo`:
| `-sampling-wait` | `5m` | how long records wait for a sampling rate |
| `-capture` | | capture on a local interface (repeatable) |
| `-inventory` | `<data>/inventory.txt` | names file |
| `-asn` | `<data>/asn.tsv.gz` | IP-to-ASN table (`.mmdb` files: upload them, or `<data>/country.mmdb` and `<data>/asn.mmdb`) |
| `-asn` | `<data>/asn.tsv.gz` | IP-to-ASN table (`.mmdb` files: upload them, or `<data>/country.mmdb`, `<data>/asn.mmdb`, `<data>/both.mmdb`) |
| `-threat` | `<data>/threats/*.txt` | extra threat list as `name=path` (repeatable) |
| `-dns-upstream` | system resolver | DNS server for showing host names |
| `-dns-rate` | `20` | reverse lookups per second at most |
Expand All @@ -873,7 +889,7 @@ The data directory holds everything:
| `password` | login passwords (hashed) |
| `inventory.txt` | names (**Sources → Names**) |
| `logo.png` (or `.svg`, `.jpg`, `.webp`, `.gif`) | your logo (**Sources → Logo**), if you uploaded one |
| `country.mmdb`, `asn.mmdb`, `asn.tsv.gz`, `threats/` | countries and networks databases and threat lists you added |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/` | countries and networks databases you added or downloaded, and threat lists |

**How long data is kept**: flow detail 30 days, summaries (overview and long
time ranges) 400 days. Older data is deleted automatically, checked every 5
Expand Down
22 changes: 22 additions & 0 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Third-party data in traffic66

traffic66 itself contains no third-party code beyond its Go modules (see
`go.mod`). It includes the following data.

## DB-IP Lite

`internal/geo/dbip/country.mmdb.gz` and `internal/geo/dbip/asn.mmdb.gz`:
DB-IP "IP to Country Lite" and "IP to ASN Lite", in MaxMind DB format as
packaged by the ip-location-db project.

IP Geolocation by DB-IP (https://db-ip.com), licensed under the Creative
Commons Attribution 4.0 International License
(https://creativecommons.org/licenses/by/4.0/). traffic66 shows this
attribution on the pages that use the data.

## Natural Earth

`internal/web/static/world.json`: country outlines derived from Natural
Earth 1:50m Admin 0 – Countries (https://www.naturalearthdata.com), public
domain, via world-atlas (https://github.com/topojson/world-atlas, ISC
license), simplified and projected by `tools/worldmap/build.mjs`.
22 changes: 7 additions & 15 deletions cmd/traffic66/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ import (
"github.com/githubflyideas/traffic66/internal/dnsres"
"github.com/githubflyideas/traffic66/internal/enrich"
"github.com/githubflyideas/traffic66/internal/flow"
"github.com/githubflyideas/traffic66/internal/geo"
"github.com/githubflyideas/traffic66/internal/pipeline"
"github.com/githubflyideas/traffic66/internal/sim"
"github.com/githubflyideas/traffic66/internal/snmp"
Expand Down Expand Up @@ -247,21 +246,14 @@ func serve(args []string, demo bool) {
log.Printf("ASN table: %d ranges from %s", asn.Size(), asnPath)
}
}
for _, name := range []string{"country.mmdb", "asn.mmdb"} {
p := filepath.Join(f.data, name)
if _, err := os.Stat(p); err != nil {
continue
}
r, err := geo.Open(p)
if err != nil {
log.Printf("%s: %v", p, err)
continue
}
asn.SetMMDB(r, name)
log.Printf("geo database %s: %s", name, r.Type)
for _, err := range asn.LoadMMDBs(f.data) {
log.Printf("geo database %v", err)
}
if err := asn.LoadDBIP(f.data); err != nil {
log.Printf("%v", err)
}
if !asn.Loaded() {
log.Printf("no country/ASN database; upload one on the Sources page to see countries and networks")
for _, src := range asn.Sources() {
log.Printf("geo database: %s %s (%s, built %s)", src.Kind, src.File, src.Type, src.Built.Format("2006-01-02"))
}
thr := enrich.NewThreats()
threatFiles := map[string]string{}
Expand Down
37 changes: 19 additions & 18 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -598,25 +598,26 @@ snmp 192.0.2.9 s3cret 10.99.0.9:161

## 8. الدول والشبكات وقوائم التهديدات

تحتاج أسماء الدول والشبكات (AS) إلى قاعدة بيانات تربط العناوين بها. ارفعها من
واجهة الويب: **المصادر ← قاعدة بيانات الدول والشبكات ← رفع ملف قاعدة بيانات…**.
يُفحص الملف ويُحفظ في دليل البيانات ويُستخدم للحركة الجديدة فورًا؛ ولا حاجة
إلى إعادة التشغيل. أما الحركة المخزّنة من قبل فتحتفظ بالدولة التي حُفظت بها.
تعمل الدول والشبكات (AS) فوراً: يتضمن traffic66 قاعدتَي DB-IP المجانيتين **IP to Country Lite** و**IP to ASN Lite** (الترخيص [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/)؛ "IP Geolocation by DB-IP"، [db-ip.com](https://db-ip.com)). تذكر الصفحات التي تعرض الدول والشبكات مصدر البيانات.

الملفات المقبولة:
النسخة المدمجة هي نسخة الإصدار الذي تشغّله. تنشر DB-IP نسخة جديدة كل شهر؛ و**المصادر ← قاعدة بيانات الدول والشبكات ← حدّث DB-IP Lite الآن** ينزّل أحدثها من db-ip.com (يحتاج الخادم الذي يشغّل traffic66 إلى الإنترنت، وتخبرك الواجهة إن فشل التنزيل).

| الملف | ما يقدّمه | من أين تحصل عليه |
|---|---|---|
| DB-IP Lite للدول أو ASN، `.mmdb` | الدولة، أو رقم AS واسمه | مجاني، دون حساب: [db-ip.com/db/lite.php](https://db-ip.com/db/lite.php) |
| MaxMind GeoLite2 Country أو ASN، `.mmdb` | الدولة، أو رقم AS واسمه | مجاني مع حساب MaxMind: [maxmind.com](https://www.maxmind.com/en/geolite2/signup) |
| جدول IP-to-ASN، `.tsv` أو `.tsv.gz` | رقم AS واسم AS والدولة | مجاني: [iptoasn.com](https://iptoasn.com) (`ip2asn-combined.tsv.gz`) |
يمكنك أيضاً استخدام قاعدة مجانية أخرى. نزّلها ثم ارفعها في الصفحة نفسها عبر **رفع ملف قاعدة بيانات…**. يُفحص الملف ويُحفظ في مجلد البيانات ويُستخدم للحركة الجديدة فوراً دون إعادة تشغيل. تحتفظ الحركة المخزنة بالدولة التي حُفظت بها.

| القاعدة | تعطي | الترخيص | من أين تحصل عليها |
|---|---|---|---|
| DB-IP Lite (مدمجة) | الدول؛ الشبكات | CC BY 4.0، بلا حساب | [db-ip.com/db/lite.php](https://db-ip.com/db/lite.php) |
| MaxMind GeoLite2 Country وASN، ‏`.mmdb` | الدول؛ الشبكات | GeoLite2 EULA، حساب مجاني | [maxmind.com](https://www.maxmind.com/en/geolite2/signup) |
| IPinfo Lite، ‏`ipinfo_lite.mmdb` | الدول والشبكات في ملف واحد | CC BY-SA 4.0، حساب مجاني | [ipinfo.io/lite](https://ipinfo.io/lite) |
| IPtoASN، ‏`ip2asn-combined.tsv.gz` | الشبكات ودولها | PDDL 1.0، بلا حساب | [iptoasn.com](https://iptoasn.com) |

تُستخدم ملفاتك أولاً، وتجيب DB-IP Lite المدمجة عمّا لا تغطيه. يعيدك زر **إزالة** بجانب الملف إلى البقية. تعرض الصفحة ما هو مستخدم وتاريخ كل قاعدة.

من دون واجهة الويب، انسخ الملف إلى مجلد البيانات باسم `country.mmdb` أو `asn.mmdb` أو `both.mmdb` (ملف فيه الدول والشبكات معاً مثل IPinfo Lite) أو `asn.tsv.gz` ثم أعد تشغيل traffic66.

ارفع قاعدة بيانات للدول وأخرى لـ ASN لتحصل على الاثنين معًا؛ وعند تحميل عدة
ملفات، تكون الأولوية لملفات `.mmdb` فيما تحتويه. تصدر نسخ جديدة كل شهر: ارفع
الملف الجديد بالطريقة نفسها ليحلّ محل القديم.
تعرض **الجغرافيا والشبكات** الحركة مع الدول الأخرى على خريطة العالم: كلما كان لون الدولة أغمق زادت الحركة. مرّر المؤشر على دولة لترى حركتها، وانقر عليها للتصفية أو لفتح سجلات التدفق. حدود الدول من [Natural Earth](https://www.naturalearthdata.com) (ملكية عامة).

دون واجهة الويب، انسخ الملف إلى دليل البيانات باسم `country.mmdb` أو
`asn.mmdb` أو `asn.tsv.gz` وأعد تشغيل traffic66.
![الجغرافيا والشبكات: الحركة الخارجية حسب الدولة على خريطة العالم](images/geo.png)

قوائم التهديدات ملفات نصية عادية فيها عنوان أو شبكة في كل سطر (يُتجاهل
النص بعد `#` أو `;`)، تُحفظ في `<data directory>/threats/<name>.txt`،
Expand Down Expand Up @@ -659,7 +660,7 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
| تفاصيل الحركة | العملاء والخوادم والخدمات عبر الزمن، بوحدة bits/s وpackets/s: أعلى 8 من كل منها، وكم كان عددها |
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| مسارات الحركة | أي مضيف يستخدم أي تطبيق نحو أي دولة: أكثر 8 مضيفات نشاطًا، والباقي ضمن «أخرى». ويعرض **العميل ← الخادم** العميل ← الخدمة ← الخادم؛ ويعرض **حسب المقطع** الشبكات بدل المضيفات |
| الجغرافيا والشبكات | الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| الجغرافيا والشبكات | خريطة العالم للحركة حسب الدولة؛ الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| سجلات التدفق | كم سجل تدفق كان هناك ومتى (شريط لكل فترة)، والسجلات نفسها، الأحدث أولًا، صفحةً صفحة، مع أعمدة قابلة للاختيار |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن (الدخول والخروج، bits/s وpackets/s)، وأرقام التدفقات بجوار عدّادات الواجهات، الأسوأ أولًا، مع الأسباب |
Expand Down Expand Up @@ -888,7 +889,7 @@ sudo traffic66 -capture en0
| `-sampling-wait` | `5m` | مدة انتظار السجلات لمعدّل أخذ العينات |
| `-capture` | | الالتقاط على واجهة محلية (يمكن تكراره) |
| `-inventory` | `<data>/inventory.txt` | ملف الأسماء |
| `-asn` | `<data>/asn.tsv.gz` | جدول IP-to-ASN (ملفات `.mmdb`: ارفعها، أو `<data>/country.mmdb` و`<data>/asn.mmdb`) |
| `-asn` | `<data>/asn.tsv.gz` | جدول IP-to-ASN (ملفات `.mmdb`: ارفعها، أو `<data>/country.mmdb` و`<data>/asn.mmdb`, `<data>/both.mmdb`) |
| `-threat` | `<data>/threats/*.txt` | قائمة تهديدات إضافية بصيغة `name=path` (يمكن تكراره) |
| `-dns-upstream` | محلّل النظام | خادم DNS لعرض أسماء المضيفات |
| `-dns-rate` | `20` | الحد الأقصى لاستعلامات DNS العكسية في الثانية |
Expand Down Expand Up @@ -916,7 +917,7 @@ traffic66 -data /var/lib/traffic66 -listen "sflow=:6343,netflow=:2055,ipfix=:473
| `password` | كلمات مرور تسجيل الدخول (مُجزّأة) |
| `inventory.txt` | الأسماء (**المصادر ← الأسماء**) |
| `logo.png` (أو `.svg`، `.jpg`، `.webp`، `.gif`) | شعارك (**المصادر ← الشعار**)، إن كنت قد رفعته |
| `country.mmdb`، `asn.mmdb`، `asn.tsv.gz`، `threats/` | قواعد بيانات الدول والشبكات وقوائم التهديدات التي أضفتها |
| `country.mmdb`، `asn.mmdb`، `both.mmdb`، `asn.tsv.gz`، `dbip-country.mmdb`، `dbip-asn.mmdb`، `threats/` | قواعد بيانات الدول والشبكات وقوائم التهديدات التي أضفتها |

**مدة الاحتفاظ بالبيانات**: تفاصيل التدفقات 30 يومًا، والملخصات (النظرة العامة والفترات الطويلة) 400 يوم.
تُحذف البيانات الأقدم تلقائيًا، ويُفحص ذلك كل 5 دقائق؛ لا يُحذف شيء غير ذلك ولا يوجد حد آخر. غيّر مدة التفاصيل
Expand Down
Loading
Loading