Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,19 @@ heading is the version number.

## 0.3.1

Offline analysis
- New page **Offline analysis**: upload packet captures (.pcap, .pcapng
from Wireshark or tcpdump; up to 3 files of at most 50 MB). They are
turned into flows in a database of their own, apart from the live data.
**Analyse** shows them on every page (overview, Top 66, traffic details,
findings, flow paths, map, flow records) with an orange bar naming the
files; **Back to live data** returns. **Delete** removes the files and
their data.
- The detection rules run over the capture: scans, port scans and password
guessing are found in it.
- The demo includes an example capture with an attack.

Pages
- Traffic details opens on servers only; tabs switch to clients, both ends
side by side, and services (13 languages).

Expand Down
16 changes: 15 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -652,6 +652,7 @@ Pages:
| Geo & networks | A world map of traffic by country; the networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Flow records | How many flow records there were and when (a bar per interval), and the records themselves, newest first, page by page, with selectable columns |
| Offline analysis | Packet captures (pcap, pcapng) analysed apart from the live data ([more](#offline-analysis)) |
| Interface check | Traffic of every interface over time (ingress and egress, bits/s and packets/s), and flow numbers next to the interface counters, worst first, with reasons |
| Sources | Devices, sampling, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |

Expand Down Expand Up @@ -734,6 +735,19 @@ The same overview in Chinese; every page is available in 13 languages:

![Overview in Chinese](docs/images/overview-zh.png)

### Offline analysis

**Offline analysis** looks at packet captures from Wireshark or tcpdump with the same pages as the live data, without mixing them in:

1. **Upload capture files…**: `.pcap` or `.pcapng`, not compressed. Up to 3 files, each at most 50 MB. The files are turned into flows in a database of their own (`<data>/sandbox/`); the live data, its numbers and findings are not touched.
2. **Analyse**: every page (overview, Top 66, traffic details, findings, flow paths, map, flow records) now shows the capture files over their whole time. An orange bar names the files; **Back to live data** returns. Each file appears as a device, so the **Device** box shows one file at a time.
3. The detection rules run over the capture: scans, port scans and password guessing are listed under **Findings**. Rules that need a day of history (lateral movement, unusual uploads) do not apply to a capture.
4. **Delete** removes a file and its data; **Delete all** removes everything.

The demo includes an example capture with an attack in it.

![Offline analysis: capture files with their packets, flows and time](docs/images/sandbox.png)

## 10. Terminal UI

```
Expand Down Expand Up @@ -889,7 +903,7 @@ The data directory holds everything:
| `password` | login passwords (hashed) |
| `inventory.txt` | names (**Sources → Names**) |
| `logo.png` (or `.svg`, `.jpg`, `.webp`, `.gif`) | your logo (**Sources → Logo**), if you uploaded one |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/` | countries and networks databases you added or downloaded, and threat lists |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/`, `sandbox/` | countries and networks databases you added or downloaded, and threat lists |

**How long data is kept**: flow detail 30 days, summaries (overview and long
time ranges) 400 days. Older data is deleted automatically, checked every 5
Expand Down
26 changes: 26 additions & 0 deletions cmd/traffic66/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
package main

import (
"bytes"
"context"
"crypto/rand"
"encoding/hex"
Expand Down Expand Up @@ -32,6 +33,7 @@ import (
"github.com/githubflyideas/traffic66/internal/enrich"
"github.com/githubflyideas/traffic66/internal/flow"
"github.com/githubflyideas/traffic66/internal/pipeline"
"github.com/githubflyideas/traffic66/internal/sandbox"
"github.com/githubflyideas/traffic66/internal/sim"
"github.com/githubflyideas/traffic66/internal/snmp"
"github.com/githubflyideas/traffic66/internal/store"
Expand Down Expand Up @@ -387,6 +389,11 @@ func serve(args []string, demo bool) {
srv := &api.Server{Store: st, Pipe: pipe, Col: col, Inv: inv, ASN: asn, Thr: thr, DNS: dns, Det: det, Static: web.FS(), Version: version,
Demo: demo, Check: checker.Check, Exists: checker.Exists, LocalTok: tok, DataDir: f.data, Started: time.Now()}
srv.SNMP = poller.Status
srv.SB = sandbox.New(filepath.Join(f.data, "sandbox"), inv, asn, thr)
defer srv.SB.Close()
if demo {
demoSample(f.data, srv.SB)
}
srv.Capture = func() []api.CaptureInfo {
var out []api.CaptureInfo
for _, c := range caps {
Expand Down Expand Up @@ -480,6 +487,25 @@ func prepareDemo(dir string) {
write("threats/scanner.txt", scan)
}

// demoSample puts the example capture into the sandbox once, so that offline
// analysis can be tried at once; deleting it keeps it deleted.
func demoSample(dir string, sb *sandbox.Sandbox) {
mark := filepath.Join(dir, "sandbox-sample")
if _, err := os.Stat(mark); err == nil {
return
}
var buf bytes.Buffer
if err := sandbox.Sample(&buf, time.Now().Add(-2*time.Hour).Truncate(time.Minute)); err != nil {
log.Printf("demo: example capture: %v", err)
return
}
if _, err := sb.Add(sandbox.SampleName, &buf, true); err != nil {
log.Printf("demo: example capture: %v", err)
return
}
os.WriteFile(mark, nil, 0o644)
}

func backfillDemo(pipe *pipeline.Pipeline, st *store.Store) {
var n int64
st.DB.QueryRow(`SELECT (SELECT count(*) FROM hot) + (SELECT count(*) FROM segments)`).Scan(&n)
Expand Down
16 changes: 15 additions & 1 deletion docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -663,6 +663,7 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
| الجغرافيا والشبكات | خريطة العالم للحركة حسب الدولة؛ الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| سجلات التدفق | كم سجل تدفق كان هناك ومتى (شريط لكل فترة)، والسجلات نفسها، الأحدث أولًا، صفحةً صفحة، مع أعمدة قابلة للاختيار |
| التحليل دون اتصال | تحليل ملفات التقاط الحزم (pcap وpcapng) بمعزل عن البيانات الحية ([المزيد](#التحليل-دون-اتصال)) |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن (الدخول والخروج، bits/s وpackets/s)، وأرقام التدفقات بجوار عدّادات الواجهات، الأسوأ أولًا، مع الأسباب |
| المصادر | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |

Expand Down Expand Up @@ -747,6 +748,19 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

<a id="10-terminal-ui"></a>

### التحليل دون اتصال

يعرض **التحليل دون اتصال** ملفات التقاط Wireshark أو tcpdump بالصفحات نفسها المستخدمة للبيانات الحية، دون خلطها بها:

1. **رفع ملفات التقاط…**: ‎`.pcap` أو ‎`.pcapng` غير مضغوطة. حتى 3 ملفات، كل منها 50 MB كحد أقصى. تتحول الملفات إلى تدفقات في قاعدة بيانات خاصة بها (`<data>/sandbox/`)، فلا تتأثر البيانات الحية وأرقامها واكتشافاتها.
2. **تحليل**: تعرض كل الصفحات (نظرة عامة، أعلى 66، تفاصيل الحركة، الاكتشافات، مسارات الحركة، الخريطة، سجلات التدفق) الملفات على امتداد وقتها كله. يذكر شريط برتقالي أسماء الملفات، و**العودة إلى البيانات الحية** يعيدك. يظهر كل ملف كجهاز، فيعرض مربع **الجهاز** ملفاً واحداً في كل مرة.
3. تعمل قواعد الكشف على الالتقاط: تظهر عمليات المسح ومسح المنافذ وتخمين كلمات المرور في **الاكتشافات**. القواعد التي تحتاج إلى يوم من السجل (الحركة الجانبية، الرفع غير المعتاد) لا تنطبق على الالتقاط.
4. **حذف** يحذف ملفاً وبياناته، و**حذف الكل** يحذف كل شيء.

يتضمن العرض التجريبي ملف التقاط نموذجياً فيه هجوم.

![التحليل دون اتصال: ملفات الالتقاط مع حزمها وتدفقاتها ووقتها](images/sandbox.png)

## 10. الواجهة الطرفية

```
Expand Down Expand Up @@ -917,7 +931,7 @@ traffic66 -data /var/lib/traffic66 -listen "sflow=:6343,netflow=:2055,ipfix=:473
| `password` | كلمات مرور تسجيل الدخول (مُجزّأة) |
| `inventory.txt` | الأسماء (**المصادر ← الأسماء**) |
| `logo.png` (أو `.svg`، `.jpg`، `.webp`، `.gif`) | شعارك (**المصادر ← الشعار**)، إن كنت قد رفعته |
| `country.mmdb`، `asn.mmdb`، `both.mmdb`، `asn.tsv.gz`، `dbip-country.mmdb`، `dbip-asn.mmdb`، `threats/` | قواعد بيانات الدول والشبكات وقوائم التهديدات التي أضفتها |
| `country.mmdb`، `asn.mmdb`، `both.mmdb`، `asn.tsv.gz`، `dbip-country.mmdb`، `dbip-asn.mmdb`، `threats/`، `sandbox/` | قواعد بيانات الدول والشبكات وقوائم التهديدات التي أضفتها |

**مدة الاحتفاظ بالبيانات**: تفاصيل التدفقات 30 يومًا، والملخصات (النظرة العامة والفترات الطويلة) 400 يوم.
تُحذف البيانات الأقدم تلقائيًا، ويُفحص ذلك كل 5 دقائق؛ لا يُحذف شيء غير ذلك ولا يوجد حد آخر. غيّر مدة التفاصيل
Expand Down
16 changes: 15 additions & 1 deletion docs/README.bn.md
Original file line number Diff line number Diff line change
Expand Up @@ -670,6 +670,7 @@ application, দেশ, ডিভাইস — ক্লিক করা যা
| ভূগোল ও নেটওয়ার্ক | দেশ অনুযায়ী ট্রাফিকের বিশ্ব মানচিত্র; যেসব নেটওয়ার্ক (AS) থেকে ট্রাফিক এসেছে ও যেখানে গেছে, সময়ের সাথে bits/s ও packets/s-এ; দেশ ও নেটওয়ার্ক অনুযায়ী ট্রাফিক |
| হুমকির তথ্য | যেসব host আপনার threat list-এর address-এর সাথে কথা বলেছে, এবং কতটা পাঠিয়েছে |
| ফ্লো রেকর্ড | কতগুলো flow record ছিল এবং কখন (প্রতি interval-এ একটি bar), আর record-গুলো নিজেই, নতুনগুলো আগে, পেজ ধরে ধরে, বেছে নেওয়া যায় এমন column সহ |
| অফলাইন বিশ্লেষণ | pcap, pcapng ক্যাপচার লাইভ ডেটা থেকে আলাদা করে বিশ্লেষণ ([আরও](#অফলাইন-বিশ্লেষণ)) |
| ইন্টারফেস মিলানো | সময়ের সাথে প্রতিটি interface-এর ট্রাফিক (ingress ও egress, bits/s ও packets/s), আর interface counter-এর পাশে flow-এর সংখ্যা, সবচেয়ে খারাপগুলো আগে, কারণসহ |
| উৎস | ডিভাইস, sampling, loss, collector, SNMP, দেশ ও নেটওয়ার্ক ডেটাবেস, লোগো, এবং **নাম** |

Expand Down Expand Up @@ -755,6 +756,19 @@ packet পাঠায় যে দেখা যায় না। ডেম

<a id="10-terminal-ui"></a>

### অফলাইন বিশ্লেষণ

**অফলাইন বিশ্লেষণ** Wireshark বা tcpdump-এর ক্যাপচার লাইভ ডেটার মতো একই পেজে দেখায়, তবে মেশায় না:

1. **ক্যাপচার ফাইল আপলোড করুন…**: `.pcap` বা `.pcapng`, সংকুচিত নয়। সর্বোচ্চ 3টি ফাইল, প্রতিটি 50 MB পর্যন্ত। ফাইলগুলো ফ্লো-তে রূপান্তরিত হয়ে আলাদা ডেটাবেসে (`<data>/sandbox/`) যায়; লাইভ ডেটা, তার হিসাব ও ফলাফল বদলায় না।
2. **বিশ্লেষণ**: সব পেজ (সংক্ষেপ, Top 66, ট্রাফিকের বিস্তারিত, ফলাফল, ফ্লো পথ, মানচিত্র, ফ্লো রেকর্ড) ক্যাপচারের পুরো সময় দেখায়। কমলা ব্যানারে ফাইলের নাম থাকে; **লাইভ ডেটায় ফিরুন** দিয়ে ফিরুন। প্রতিটি ফাইল একটি ডিভাইস হিসেবে দেখায়, তাই **ডিভাইস** বক্সে একটি করে ফাইল দেখা যায়।
3. শনাক্তকরণের নিয়মগুলো ক্যাপচারেও চলে: স্ক্যান, পোর্ট স্ক্যান ও পাসওয়ার্ড অনুমান **সন্দেহজনক কার্যকলাপ**-এ আসে। যেসব নিয়মে এক দিনের ইতিহাস লাগে (ল্যাটারাল মুভমেন্ট, অস্বাভাবিক আপলোড) সেগুলো ক্যাপচারে প্রযোজ্য নয়।
4. **মুছুন** একটি ফাইল ও তার ডেটা মুছে দেয়; **সব মুছুন** সব মুছে দেয়।

ডেমোতে আক্রমণসহ একটি উদাহরণ ক্যাপচার আছে।

![অফলাইন বিশ্লেষণ: ক্যাপচার ফাইল, তাদের প্যাকেট, ফ্লো ও সময়](images/sandbox.png)

## 10. Terminal UI

```
Expand Down Expand Up @@ -924,7 +938,7 @@ traffic66 -data /var/lib/traffic66 -listen "sflow=:6343,netflow=:2055,ipfix=:473
| `password` | login পাসওয়ার্ড (hashed) |
| `inventory.txt` | নাম (**উৎস → নাম**) |
| `logo.png` (বা `.svg`, `.jpg`, `.webp`, `.gif`) | আপনার লোগো (**উৎস → লোগো**), যদি আপলোড করে থাকেন |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/` | আপনার যোগ করা দেশ ও নেটওয়ার্ক database এবং threat list |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/`, `sandbox/` | আপনার যোগ করা দেশ ও নেটওয়ার্ক database এবং threat list |

**ডেটা কতদিন রাখা হয়**: flow detail 30 দিন, summary (overview ও দীর্ঘ সময়সীমা) 400 দিন। এর চেয়ে পুরোনো ডেটা
নিজে থেকেই মুছে যায়, প্রতি 5 মিনিটে যাচাই হয়; এ ছাড়া কিছু মোছা হয় না এবং অন্য কোনো সীমা নেই। detail-এর মেয়াদ
Expand Down
16 changes: 15 additions & 1 deletion docs/README.es.md
Original file line number Diff line number Diff line change
Expand Up @@ -686,6 +686,7 @@ Páginas:
| Geografía y redes | Un mapa del mundo del tráfico por país; las redes (AS) de las que vino y a las que fue el tráfico, en el tiempo en bits/s y paquetes/s; tráfico por país y por red |
| Inteligencia de amenazas | Hosts que hablaron con direcciones de sus listas de amenazas y cuánto enviaron |
| Registros de flujo | Cuántos registros de flujo hubo y cuándo (una barra por intervalo), y los registros mismos, del más reciente al más antiguo, página a página, con columnas seleccionables |
| Análisis offline | Capturas de paquetes (pcap, pcapng) analizadas aparte de los datos en vivo ([más](#análisis-offline)) |
| Verificación de interfaces | Tráfico de cada interfaz en el tiempo (entrada y salida, bits/s y paquetes/s), y cifras de flujo junto a los contadores de interfaz, de peor a mejor, con motivos |
| Fuentes | Equipos, muestreo, pérdidas, colectores, SNMP, la base de datos de países y redes, el logotipo y **Nombres** |

Expand Down Expand Up @@ -775,6 +776,19 @@ El mismo resumen en chino; todas las páginas están disponibles en 13 idiomas:

<a id="10-terminal-ui"></a>

### Análisis offline

**Análisis offline** muestra capturas de Wireshark o tcpdump con las mismas páginas que los datos en vivo, sin mezclarlas:

1. **Subir archivos de captura…**: `.pcap` o `.pcapng`, sin comprimir. Hasta 3 archivos, cada uno de 50 MB como máximo. Los archivos se convierten en flujos en una base de datos propia (`<data>/sandbox/`); los datos en vivo, sus cifras y hallazgos no se tocan.
2. **Analizar**: todas las páginas (resumen, Top 66, detalles del tráfico, hallazgos, rutas, mapa, registros de flujo) muestran los archivos durante todo su tiempo. Una barra naranja nombra los archivos; **Volver a los datos en vivo** vuelve. Cada archivo aparece como un dispositivo, así que el cuadro **Dispositivo** muestra un archivo cada vez.
3. Las reglas de detección se aplican a la captura: barridos, escaneos de puertos y adivinación de contraseñas aparecen en **Hallazgos**. Las reglas que necesitan un día de historial (movimiento lateral, subidas inusuales) no se aplican a una captura.
4. **Eliminar** borra un archivo y sus datos; **Eliminar todo** lo borra todo.

La demo incluye una captura de ejemplo con un ataque.

![Análisis offline: archivos de captura con sus paquetes, flujos y tiempo](images/sandbox.png)

## 10. Interfaz de terminal

```
Expand Down Expand Up @@ -948,7 +962,7 @@ El directorio de datos lo contiene todo:
| `password` | contraseñas de acceso (con hash) |
| `inventory.txt` | nombres (**Fuentes → Nombres**) |
| `logo.png` (o `.svg`, `.jpg`, `.webp`, `.gif`) | su logotipo (**Fuentes → Logotipo**), si subió uno |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/` | bases de datos de países y redes y listas de amenazas que haya añadido |
| `country.mmdb`, `asn.mmdb`, `both.mmdb`, `asn.tsv.gz`, `dbip-country.mmdb`, `dbip-asn.mmdb`, `threats/`, `sandbox/` | bases de datos de países y redes y listas de amenazas que haya añadido |

**Cuánto tiempo se guardan los datos**: el detalle de flujos 30 días; los resúmenes (vista general y periodos largos)
400 días. Lo más antiguo se borra automáticamente, con una comprobación cada 5 minutos; no se borra nada más ni hay
Expand Down
Loading
Loading