Fixes flow checks not found

This commit is contained in:
MatteoBiscosi 2022-11-21 10:59:55 +01:00
parent 6ea5cfbba1
commit ef01259354
5 changed files with 91 additions and 0 deletions

View file

@ -0,0 +1,50 @@
--
-- (C) 2019-22 - ntop.org
--
-- ##############################################
local flow_alert_keys = require "flow_alert_keys"
-- Import the classes library.
local classes = require "classes"
-- Make sure to import the Superclass!
local alert = require "alert"
-- ##############################################
local alert_potentially_dangerous_protocol = classes.class(alert)
-- ##############################################
alert_potentially_dangerous_protocol.meta = {
alert_key = flow_alert_keys.flow_alert_potentially_dangerous,
i18n_title = "flow_details.potentially_dangerous_protocol",
icon = "fas fa-fw fa-exclamation",
has_victim = true,
has_attacker = true,
}
-- ##############################################
-- @brief Prepare an alert table used to generate the alert
-- @return A table with the alert built
function alert_potentially_dangerous_protocol:init()
-- Call the parent constructor
self.super:init()
end
-- #######################################################
-- @brief Format an alert into a human-readable string
-- @param ifid The integer interface id of the generated alert
-- @param alert The alert description table, including alert data such as the generating entity, timestamp, granularity, type
-- @param alert_type_params Table `alert_type_params` as built in the `:init` method
-- @return A human-readable string
function alert_potentially_dangerous_protocol.format(ifid, alert, alert_type_params)
return i18n("flow_details.potentially_dangerous_protocol")
end
-- #######################################################
return alert_potentially_dangerous_protocol

View file

@ -0,0 +1,42 @@
--
-- (C) 2019-22 - ntop.org
--
local checks = require("checks")
local alert_consts = require "alert_consts"
local alerts_api = require "alerts_api"
local flow_alert_keys = require "flow_alert_keys"
-- #################################################################
local script = {
-- Script category
category = checks.check_categories.security,
-- This script is only for alerts generation
alert_id = flow_alert_keys.flow_alert_potentially_dangerous,
default_value = {
},
gui = {
i18n_title = "flow_checks_config.potentially_dangerous_protocol",
i18n_description = "flow_checks_config.potentially_dangerous_protocol_description",
}
}
-- #################################################################
function script.setup()
-- IMPORTANT: this check is essential to prevent users from running enterprise
-- scripts from pro
if(not ntop.isEnterpriseM()) then
return false
end
return true
end
-- #################################################################
return script