/src/ntopng/src/flow_checks/BroadcastNonUDPTraffic.cpp
Line | Count | Source |
1 | | /* |
2 | | * |
3 | | * (C) 2013-24 - ntop.org |
4 | | * |
5 | | * |
6 | | * This program is free software; you can redistribute it and/or modify |
7 | | * it under the terms of the GNU General Public License as published by |
8 | | * the Free Software Foundation; either version 3 of the License, or |
9 | | * (at your option) any later version. |
10 | | * |
11 | | * This program is distributed in the hope that it will be useful, |
12 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
13 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
14 | | * GNU General Public License for more details. |
15 | | * |
16 | | * You should have received a copy of the GNU General Public License |
17 | | * along with this program; if not, write to the Free Software Foundation, |
18 | | * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. |
19 | | * |
20 | | */ |
21 | | |
22 | | #include "ntop_includes.h" |
23 | | #include "flow_checks_includes.h" |
24 | | |
25 | | /* ***************************************************** */ |
26 | | |
27 | 0 | void BroadcastNonUDPTraffic::flowBegin(Flow* f) { |
28 | 0 | const IpAddress* ip_addr = f->get_srv_ip_addr(); |
29 | 0 | Mac* mac_addr = f->get_srv_host() ? f->get_srv_host()->getMac() : NULL; |
30 | |
|
31 | 0 | if (ip_addr || mac_addr) { |
32 | 0 | bool launch_alert = false; |
33 | |
|
34 | 0 | if ((ip_addr) && (ip_addr->isBroadcastAddress()) && |
35 | 0 | (f->get_protocol() != IPPROTO_UDP /* The protocol MUST not be UDP*/)) |
36 | 0 | launch_alert = true; |
37 | |
|
38 | 0 | if ((mac_addr) && (mac_addr->isBroadcast()) && |
39 | 0 | (f->get_protocol() != IPPROTO_UDP /* The protocol MUST not be UDP*/)) |
40 | 0 | launch_alert = true; |
41 | | |
42 | | /* |
43 | | * This alert has to be triggered when we have traffic towards Broadcast |
44 | | * addresses and the l4 protocol is not UDP protocol (possible device scan |
45 | | * in a network) |
46 | | */ |
47 | 0 | if (launch_alert) { |
48 | 0 | FlowAlertType alert_type = BroadcastNonUDPTrafficAlert::getClassType(); |
49 | 0 | u_int8_t c_score, s_score; |
50 | |
|
51 | 0 | risk_percentage cli_score_pctg = CLIENT_HIGH_RISK_PERCENTAGE; |
52 | |
|
53 | 0 | computeCliSrvScore(ntop->getFlowAlertScore(alert_type.id), cli_score_pctg, |
54 | 0 | &c_score, &s_score); |
55 | |
|
56 | 0 | FlowAlert* alert = buildAlert(f); |
57 | 0 | alert->setCliSrvScores(c_score, s_score); |
58 | 0 | f->triggerAlert(alert); |
59 | 0 | } |
60 | 0 | } |
61 | 0 | } |
62 | | |
63 | | /* ***************************************************** */ |
64 | | |
65 | 0 | FlowAlert* BroadcastNonUDPTraffic::buildAlert(Flow* f) { |
66 | 0 | BroadcastNonUDPTrafficAlert* alert = |
67 | 0 | new (std::nothrow) BroadcastNonUDPTrafficAlert(this, f); |
68 | |
|
69 | 0 | if (alert) { |
70 | | /* The remote client is considered the attacker. The victim is the local |
71 | | * server */ |
72 | 0 | alert->setCliAttacker(); |
73 | 0 | } |
74 | |
|
75 | 0 | return alert; |
76 | 0 | } |
77 | | |
78 | | /* ***************************************************** */ |