Fix FPC confidence with custom rules (#3008)

This commit is contained in:
Ivan Nardi 2025-10-23 12:29:39 +02:00 committed by GitHub
parent 01836e0071
commit 1fdb6df2b1
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
10 changed files with 460 additions and 449 deletions

View file

@ -41,12 +41,12 @@ Acceptable 7 4128 6
Unspecified 8 4446 7
1 UDP [247f:855b:5e16:3caf:3f2c:4134:9592:661b]:100 -> [21bc:b273:7f68:88d7:77a8:585:3990:927b]:1991 [proto: 2048/CustomProtocolE][Stack: CustomProtocolE][IP: 2048/CustomProtocolE][ClearText][Confidence: Match by custom rule][FPC: 2048/CustomProtocolE, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/1287 bytes -> 0 pkts/0 bytes][Goodput ratio: 95/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No client to server traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0]
2 UDP [247f:855b:5e16:3caf:3f2c:4134:9592:661b]:36098 -> [21bc:b273:7f68:88d7:77a8:585:3990:927b]:50621 [proto: 2049/CustomProtocolF][Stack: CustomProtocolF][IP: 2049/CustomProtocolF][ClearText][Confidence: Match by custom rule][FPC: 2049/CustomProtocolF, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/1287 bytes -> 0 pkts/0 bytes][Goodput ratio: 95/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0]
3 UDP [3ffe:507::1:200:86ff:fe05:80da]:21554 <-> [3ffe:501:4819::42]:5333 [proto: 1024/CustomProtocolD][Stack: CustomProtocolD][IP: 1024/CustomProtocolD][ClearText][Confidence: Match by custom rule][FPC: 1024/CustomProtocolD, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/90 bytes <-> 1 pkts/510 bytes][Goodput ratio: 31/88][0.07 sec][PLAIN TEXT (itojun)][Plen Bins: 50,0,0,0,0,0,0,0,0,0,0,0,0,0,50,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
4 UDP [fe80::76ac:b9ff:fe6c:c124]:12717 -> [ff02::1]:64315 [proto: 2050/CustomProtocolG][Stack: CustomProtocolG][IP: 2050/CustomProtocolG][ClearText][Confidence: Match by custom rule][FPC: 2050/CustomProtocolG, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
5 UDP [fe80::76ac:b9ff:fe6c:c124]:12718 -> [ff02::1]:26993 [proto: 65535/CustomProtocolH][Stack: CustomProtocolH][IP: 65535/CustomProtocolH][ClearText][Confidence: Match by custom rule][FPC: 65535/CustomProtocolH, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
6 UDP [fe80::76ac:b9ff:fe6c:c124]:12719 -> [ff02::1]:26993 [proto: 65534/CustomProtocolI][Stack: CustomProtocolI][IP: 65534/CustomProtocolI][ClearText][Confidence: Match by custom rule][FPC: 65534/CustomProtocolI, Confidence: DPI][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
1 UDP [247f:855b:5e16:3caf:3f2c:4134:9592:661b]:100 -> [21bc:b273:7f68:88d7:77a8:585:3990:927b]:1991 [proto: 2048/CustomProtocolE][Stack: CustomProtocolE][IP: 2048/CustomProtocolE][ClearText][Confidence: Match by custom rule][FPC: 2048/CustomProtocolE, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/1287 bytes -> 0 pkts/0 bytes][Goodput ratio: 95/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No client to server traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0]
2 UDP [247f:855b:5e16:3caf:3f2c:4134:9592:661b]:36098 -> [21bc:b273:7f68:88d7:77a8:585:3990:927b]:50621 [proto: 2049/CustomProtocolF][Stack: CustomProtocolF][IP: 2049/CustomProtocolF][ClearText][Confidence: Match by custom rule][FPC: 2049/CustomProtocolF, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/1287 bytes -> 0 pkts/0 bytes][Goodput ratio: 95/0][< 1 sec][Risk: ** Unidirectional Traffic **][Risk Score: 10][Risk Info: No server to client traffic][Plen Bins: 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0]
3 UDP [3ffe:507::1:200:86ff:fe05:80da]:21554 <-> [3ffe:501:4819::42]:5333 [proto: 1024/CustomProtocolD][Stack: CustomProtocolD][IP: 1024/CustomProtocolD][ClearText][Confidence: Match by custom rule][FPC: 1024/CustomProtocolD, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/90 bytes <-> 1 pkts/510 bytes][Goodput ratio: 31/88][0.07 sec][PLAIN TEXT (itojun)][Plen Bins: 50,0,0,0,0,0,0,0,0,0,0,0,0,0,50,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
4 UDP [fe80::76ac:b9ff:fe6c:c124]:12717 -> [ff02::1]:64315 [proto: 2050/CustomProtocolG][Stack: CustomProtocolG][IP: 2050/CustomProtocolG][ClearText][Confidence: Match by custom rule][FPC: 2050/CustomProtocolG, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
5 UDP [fe80::76ac:b9ff:fe6c:c124]:12718 -> [ff02::1]:26993 [proto: 65535/CustomProtocolH][Stack: CustomProtocolH][IP: 65535/CustomProtocolH][ClearText][Confidence: Match by custom rule][FPC: 65535/CustomProtocolH, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
6 UDP [fe80::76ac:b9ff:fe6c:c124]:12719 -> [ff02::1]:26993 [proto: 65534/CustomProtocolI][Stack: CustomProtocolI][IP: 65534/CustomProtocolI][ClearText][Confidence: Match by custom rule][FPC: 65534/CustomProtocolI, Confidence: Match by custom rule][DPI packets: 1][Breed: Acceptable][1 pkts/318 bytes -> 0 pkts/0 bytes][Goodput ratio: 80/0][< 1 sec][PLAIN TEXT (BZ.qca956)][Plen Bins: 0,0,0,0,0,0,0,0,100,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0]
Undetected flows: