Coverage Report

Created: 2026-07-25 06:24

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ntopng/src/flow_checks/BroadcastNonUDPTraffic.cpp
Line
Count
Source
1
/*
2
 *
3
 * (C) 2013-24 - ntop.org
4
 *
5
 *
6
 * This program is free software; you can redistribute it and/or modify
7
 * it under the terms of the GNU General Public License as published by
8
 * the Free Software Foundation; either version 3 of the License, or
9
 * (at your option) any later version.
10
 *
11
 * This program is distributed in the hope that it will be useful,
12
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14
 * GNU General Public License for more details.
15
 *
16
 * You should have received a copy of the GNU General Public License
17
 * along with this program; if not, write to the Free Software Foundation,
18
 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
19
 *
20
 */
21
22
#include "ntop_includes.h"
23
#include "flow_checks_includes.h"
24
25
/* ***************************************************** */
26
27
0
void BroadcastNonUDPTraffic::flowBegin(Flow* f) {
28
0
  const IpAddress* ip_addr = f->get_srv_ip_addr();
29
0
  Mac* mac_addr = f->get_srv_host() ? f->get_srv_host()->getMac() : NULL;
30
31
0
  if (ip_addr || mac_addr) {
32
0
    bool launch_alert = false;
33
34
0
    if ((ip_addr) && (ip_addr->isBroadcastAddress()) &&
35
0
        (f->get_protocol() != IPPROTO_UDP /* The protocol MUST not be UDP*/))
36
0
      launch_alert = true;
37
38
0
    if ((mac_addr) && (mac_addr->isBroadcast()) &&
39
0
        (f->get_protocol() != IPPROTO_UDP /* The protocol MUST not be UDP*/))
40
0
      launch_alert = true;
41
42
    /*
43
     * This alert has to be triggered when we have traffic towards Broadcast
44
     * addresses and the l4 protocol is not UDP protocol (possible device scan
45
     * in a network)
46
     */
47
0
    if (launch_alert) {
48
0
      FlowAlertType alert_type = BroadcastNonUDPTrafficAlert::getClassType();
49
0
      u_int8_t c_score, s_score;
50
51
0
      risk_percentage cli_score_pctg = CLIENT_HIGH_RISK_PERCENTAGE;
52
53
0
      computeCliSrvScore(ntop->getFlowAlertScore(alert_type.id), cli_score_pctg,
54
0
                         &c_score, &s_score);
55
56
0
      FlowAlert* alert = buildAlert(f);
57
0
      alert->setCliSrvScores(c_score, s_score);
58
0
      f->triggerAlert(alert);
59
0
    }
60
0
  }
61
0
}
62
63
/* ***************************************************** */
64
65
0
FlowAlert* BroadcastNonUDPTraffic::buildAlert(Flow* f) {
66
0
  BroadcastNonUDPTrafficAlert* alert =
67
0
      new (std::nothrow) BroadcastNonUDPTrafficAlert(this, f);
68
69
0
  if (alert) {
70
    /* The remote client is considered the attacker. The victim is the local
71
     * server */
72
0
    alert->setCliAttacker();
73
0
  }
74
75
0
  return alert;
76
0
}
77
78
/* ***************************************************** */