New protocols for Amazon/AWS sub-classification (#2975)

Add:
* Cognito
* API Gateway
* Kinesis
* EC2
* EMR
* S3
* Cloudfront
* DynamoDB

Keep `NDPI_PROTOCOL_AMAZON_AWS` for generic AWS traffic
This commit is contained in:
Ivan Nardi 2025-10-02 11:48:25 +02:00 committed by GitHub
parent c9dfc946ff
commit 113170cca4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
93 changed files with 5121 additions and 826 deletions

View file

@ -30,5 +30,5 @@ System 6 380 6
2 UDP 123.212.25.229:49531 -> 171.47.173.23:623 [proto: 351/RMCP][Stack: RMCP][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/65 bytes -> 0 pkts/0 bytes][Goodput ratio: 35/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
3 UDP 127.36.88.103:34698 -> 164.114.97.252:623 [proto: 351/RMCP][Stack: RMCP][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/65 bytes -> 0 pkts/0 bytes][Goodput ratio: 35/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
4 UDP 129.222.153.30:58065 -> 190.219.142.148:623 [proto: 351/RMCP][Stack: RMCP][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/65 bytes -> 0 pkts/0 bytes][Goodput ratio: 35/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
5 UDP 54.229.154.152:59937 -> 14.85.79.172:623 [proto: 351/RMCP][Stack: RMCP][IP: 265/AmazonAWS][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/60 bytes -> 0 pkts/0 bytes][Goodput ratio: 20/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
5 UDP 54.229.154.152:59937 -> 14.85.79.172:623 [proto: 351/RMCP][Stack: RMCP][IP: 461/AWS_EC2][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/60 bytes -> 0 pkts/0 bytes][Goodput ratio: 20/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
6 UDP 137.141.61.18:59937 -> 82.132.4.178:623 [proto: 351/RMCP][Stack: RMCP][IP: 0/Unknown][ClearText][Confidence: DPI][FPC: 351/RMCP, Confidence: DPI][DPI packets: 1][cat: System/18][Breed: Safe][1 pkts/60 bytes -> 0 pkts/0 bytes][Goodput ratio: 20/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]