mirror of
https://github.com/ntop/ntopng.git
synced 2026-05-05 10:41:34 +00:00
parent
055fbd5589
commit
b1134b611f
7 changed files with 34 additions and 16 deletions
|
|
@ -13,7 +13,7 @@ local handler = {}
|
|||
-- #################################################################
|
||||
|
||||
-- @brief See risk_handler.lua
|
||||
function handler.handle_risk(risk_id, flow_score, cli_score, srv_score)
|
||||
function handler.handle_risk(conf, risk_id, flow_score, cli_score, srv_score)
|
||||
-- NDPI_BINARY_APPLICATION_TRANSFER
|
||||
-- scripts/lua/modules/alert_definitions/alert_suspicious_file_transfer.lua
|
||||
|
||||
|
|
@ -25,7 +25,7 @@ function handler.handle_risk(risk_id, flow_score, cli_score, srv_score)
|
|||
http_info
|
||||
)
|
||||
|
||||
alert:set_severity(alert_severities.error)
|
||||
alert:set_severity(conf.severity)
|
||||
|
||||
alert:trigger_status(cli_score or 0, srv_score or 0, flow_score or 0)
|
||||
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ local handler = {}
|
|||
-- #################################################################
|
||||
|
||||
-- @brief See risk_handler.lua
|
||||
function handler.handle_risk(risk_id, flow_score, cli_score, srv_score)
|
||||
function handler.handle_risk(conf, risk_id, flow_score, cli_score, srv_score)
|
||||
-- NDPI_KNOWN_PROTOCOL_ON_NON_STANDARD_PORT
|
||||
|
||||
-- Set the flow status and trigger an alert when a known protocol is found to use a non-standard port
|
||||
|
|
@ -21,7 +21,7 @@ function handler.handle_risk(risk_id, flow_score, cli_score, srv_score)
|
|||
flow.getInfo()
|
||||
)
|
||||
|
||||
alert:set_severity(alert_severities.info)
|
||||
alert:set_severity(conf.severity)
|
||||
|
||||
alert:trigger_status(cli_score or 0, srv_score or 0, flow_score or 0)
|
||||
|
||||
|
|
|
|||
|
|
@ -20,14 +20,14 @@ local handler = {}
|
|||
-- @param flow_score An integer score that will be added to the total flow score
|
||||
-- @param cli_score An integer score that will be added to the client score
|
||||
-- @param srv_score An integer score that will be added to the server score
|
||||
function handler.handle_risk(risk_id, flow_score, cli_score, srv_score)
|
||||
function handler.handle_risk(conf, risk_id, flow_score, cli_score, srv_score)
|
||||
-- Set a flow status for the generic flow_risk. This will also
|
||||
-- cause an alert to be generated.
|
||||
local alert = alert_consts.alert_types.alert_flow_risk.new(
|
||||
risk_id
|
||||
)
|
||||
|
||||
alert:set_severity(alert_severities.warning)
|
||||
alert:set_severity(conf.severity)
|
||||
|
||||
alert:trigger_status(cli_score or 0, srv_score or 0, flow_score or 0)
|
||||
end
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue