emanuele-f
|
8d7331e519
|
Improve ghost network alert message
|
2019-09-06 10:45:59 +02:00 |
|
Alfredo Cardigliano
|
240c7c0e84
|
Printing score only when > 0
|
2019-09-05 21:18:49 +02:00 |
|
emanuele-f
|
bd2bf91882
|
Use server name as MUD peer name when possible
|
2019-09-05 19:31:42 +02:00 |
|
emanuele-f
|
1029440083
|
Add MUD delete button
|
2019-09-05 19:11:11 +02:00 |
|
emanuele-f
|
d9a44d615a
|
Implement generic flow callbacks
|
2019-09-05 19:11:11 +02:00 |
|
Alfredo Cardigliano
|
38a53ec1fa
|
Transferring flows status bitmap to the client/server host. Added anomalous flows reasons to the host details page.
|
2019-09-05 17:55:00 +02:00 |
|
emanuele-f
|
1d248331f6
|
Implement optimized exists query in InfluxDB
This avoids returning too much results when using standard listSeries
|
2019-09-05 16:02:20 +02:00 |
|
Alfredo Cardigliano
|
48f07c0f73
|
Added flow score below the list of flow issues, added host score
|
2019-09-05 15:57:05 +02:00 |
|
Alfredo Cardigliano
|
e6ec8711d7
|
Setting also status_normal in the status bitmap, Flow Status fix
|
2019-09-05 15:23:11 +02:00 |
|
Simone Mainardi
|
f9a8ca8002
|
Uses getStatsUpdateFreq as min ts step for non-packet interfaces
|
2019-09-05 14:31:04 +02:00 |
|
Alfredo Cardigliano
|
3cdd9fdf4c
|
Printing all flow statuses in flow_details
|
2019-09-05 13:05:53 +02:00 |
|
Alfredo Cardigliano
|
871bb63b61
|
Added default relevance per flow status
|
2019-09-05 11:53:42 +02:00 |
|
emanuele-f
|
1443d46a28
|
Little fix for commit 7bf8b8b1e5
|
2019-09-05 11:30:35 +02:00 |
|
Alfredo Cardigliano
|
141622f151
|
Lua: created flow_consts module, getFlowStatusTypes has been replaced by flow_consts.flow_status_types, added flow.status_map to the Lua flow info
|
2019-09-04 22:20:51 +02:00 |
|
emanuele-f
|
7bf8b8b1e5
|
Use insertion_step when creating RRD files
|
2019-09-05 10:59:10 +02:00 |
|
emanuele-f
|
c97ef3d908
|
Implement host MUD recording and dump
|
2019-09-04 21:20:52 +02:00 |
|
Simone Mainardi
|
ca56f94cef
|
Implements per-interface updateStats variable frequency
|
2019-09-04 19:27:55 +02:00 |
|
emanuele-f
|
d630cce58a
|
Fix script failures in SNMP message formatters
|
2019-09-04 15:36:46 +02:00 |
|
Alfredo Cardigliano
|
40bf86a81d
|
Fix alert_endpoints/{syslog.lua,slack.lua} error 'attempt to index a nil value'
|
2019-09-04 12:57:57 +02:00 |
|
Alfredo Cardigliano
|
14c0338b64
|
Fix alert_endpoints_utils.lua error 'attempt to compare number with string' #2795
|
2019-09-04 12:44:53 +02:00 |
|
Simone Mainardi
|
5e914130af
|
Implements ghost broadcast domains logic in C
Fixes #2800
|
2019-09-04 12:41:28 +02:00 |
|
emanuele-f
|
b62e4183f0
|
Add ability to manually release an alert
|
2019-09-04 12:29:13 +02:00 |
|
Alfredo Cardigliano
|
2f935773d5
|
Suppressed debug message
|
2019-09-04 11:00:11 +02:00 |
|
Simone Mainardi
|
9924225473
|
Implements nDPIStats throughput calc for NetworkInterface
|
2019-09-04 10:21:21 +02:00 |
|
emanuele-f
|
74f761d18b
|
Allow calls to alerts_api.trigger/alerts_api.release outside periodic scripts
|
2019-09-03 19:20:50 +02:00 |
|
emanuele-f
|
08e616a5d4
|
Fix "Could not retrieve alert information" on pcap dump interfaces
|
2019-09-03 18:59:19 +02:00 |
|
Simone Mainardi
|
b86378bca3
|
Implements ul/dl thpts in C and reworks the footer to use them
|
2019-09-03 18:56:23 +02:00 |
|
emanuele-f
|
8e6cd5962a
|
Fix blacklisted host alerts not generated when reading from PCAP dump
|
2019-09-03 17:50:08 +02:00 |
|
Simone Mainardi
|
a5b5510290
|
Adds bytes and packets throughput to NetworkInterface
|
2019-09-03 17:16:47 +02:00 |
|
emanuele-f
|
fbb66951b5
|
Add alert score on hosts
|
2019-09-03 13:36:27 +02:00 |
|
Simone Mainardi
|
3bfedf8f4c
|
Implements ThroughputStats and reworks GenericTrafficElement
|
2019-09-03 11:07:21 +02:00 |
|
Luca Deri
|
ffcfe398cc
|
Reworked flow stats defining InterarrivalStats
Fixed ms/timeval diffrence functions
|
2019-09-02 23:58:34 +02:00 |
|
emanuele-f
|
a0d8cd7595
|
Add l4_proto_to_id
|
2019-09-02 20:08:38 +02:00 |
|
Alfredo Cardigliano
|
3c930d0514
|
Code cleanup
|
2019-09-02 11:51:44 +02:00 |
|
emanuele-f
|
a58cd6a7d9
|
Add country flag in flow peers
|
2019-09-02 10:58:43 +02:00 |
|
emanuele-f
|
2d02de6cc1
|
Implement initial flow score support
|
2019-08-30 17:16:11 +02:00 |
|
Simone Mainardi
|
d2fc1f3b0b
|
Add proper axes labels to udp flow collection drops chart
|
2019-08-30 16:34:41 +02:00 |
|
Simone Mainardi
|
2e67a69cb7
|
Implements redis health and keys used monitoring
|
2019-08-30 16:19:33 +02:00 |
|
Simone Mainardi
|
24cf71a70d
|
Parses and charts UDP socket drops from nProbe
|
2019-08-30 12:54:41 +02:00 |
|
emanuele-f
|
e3ae0747c8
|
Properly handle disabled vs hidden graphs menu entries
Fixes #2710
|
2019-08-30 12:12:18 +02:00 |
|
Alfredo Cardigliano
|
13d032d185
|
Formatting IDS alerts
|
2019-08-29 11:20:41 +02:00 |
|
Simone Mainardi
|
6ae30f0604
|
Initial implementation of the Redis monitoring probe
|
2019-08-28 19:30:52 +02:00 |
|
emanuele-f
|
a37bb425ea
|
Add JA3 signature link in alerts
|
2019-08-28 18:41:17 +02:00 |
|
emanuele-f
|
b66b71fd7e
|
Implement alert on JA3 malicious signatures
Closes #2788
|
2019-08-28 18:33:13 +02:00 |
|
emanuele-f
|
a8cb972e7d
|
Implement ghost networks alerts
|
2019-08-28 16:42:18 +02:00 |
|
Simone Mainardi
|
1b189001f3
|
Fixes captive portal redirection URL not working
Fixes #2750
|
2019-08-27 18:17:44 +02:00 |
|
emanuele-f
|
3bf6ed1ecd
|
Add syn-vs-rst and misbehaving-vs-total-flows alerts
|
2019-08-27 16:33:53 +02:00 |
|
Simone Mainardi
|
606e681d8e
|
Fixes flow alerts exploration
Fixes #2782
|
2019-08-27 15:42:35 +02:00 |
|
Simone Mainardi
|
f96743569d
|
Adds alert menu also for view interfaces
|
2019-08-27 14:54:55 +02:00 |
|
Simone Mainardi
|
a0e4fe43da
|
Fixes missing alerts lists when only past alerts available
|
2019-08-27 14:54:19 +02:00 |
|