/src/ntopng/include/HostStats.h
Line | Count | Source |
1 | | /* |
2 | | * |
3 | | * (C) 2013-26 - ntop.org |
4 | | * |
5 | | * |
6 | | * This program is free software; you can redistribute it and/or modify |
7 | | * it under the terms of the GNU General Public License as published by |
8 | | * the Free Software Foundation; either version 3 of the License, or |
9 | | * (at your option) any later version. |
10 | | * |
11 | | * This program is distributed in the hope that it will be useful, |
12 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
13 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
14 | | * GNU General Public License for more details. |
15 | | * |
16 | | * You should have received a copy of the GNU General Public License |
17 | | * along with this program; if not, write to the Free Software Foundation, |
18 | | * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. |
19 | | * |
20 | | */ |
21 | | |
22 | | #ifndef _HOST_STATS_H_ |
23 | | #define _HOST_STATS_H_ |
24 | | |
25 | | class Host; |
26 | | |
27 | | class HostStats : public GenericTrafficElement { |
28 | | protected: |
29 | | Host* host; |
30 | | |
31 | | u_int8_t client_flows_anomaly : 1, server_flows_anomaly : 1, |
32 | | client_score_anomaly : 1, server_score_anomaly : 1, _notused : 4; |
33 | | u_int32_t total_alerts; |
34 | | u_int32_t unreachable_flows_as_client, unreachable_flows_as_server; |
35 | | /* Used concurrently in view interfaces, possibly removed after |
36 | | * https://github.com/ntop/ntopng/issues/4596 */ |
37 | | u_int32_t alerted_flows_as_client, alerted_flows_as_server; |
38 | | u_int32_t host_unreachable_flows_as_client, host_unreachable_flows_as_server; |
39 | | u_int32_t total_num_flows_as_client, total_num_flows_as_server; |
40 | | u_int32_t num_flow_alerts; |
41 | | u_int64_t udp_sent_unicast, udp_sent_non_unicast; |
42 | | L4Stats l4stats; |
43 | | |
44 | | u_int8_t consecutive_high_score; |
45 | | time_t periodicUpdate, periodic_stats_update; |
46 | | |
47 | | /* *************************************** */ |
48 | | /* Behavioural analysis regarding the host */ |
49 | | DESCounter active_flows_srv, active_flows_cli, score_cli, score_srv; |
50 | | |
51 | | /* **************************************** */ |
52 | | |
53 | | /* Written by NetworkInterface::periodicStatsUpdate thread */ |
54 | | // NOTE: GenericTrafficElement inherited data is updated periodically too |
55 | | u_int32_t total_activity_time /* sec */; |
56 | | u_int32_t last_epoch_update; /* useful to avoid multiple updates */ |
57 | | |
58 | | #ifdef NTOPNG_PRO |
59 | | HostPoolStats *quota_enforcement_stats, *quota_enforcement_stats_shadow; |
60 | | #endif |
61 | | |
62 | | /* Written by NetworkInterface::processPacket thread */ |
63 | | PacketStats sent_stats, recv_stats; |
64 | | |
65 | | /* Used to store checkpoint data to build top talkers stats */ |
66 | | struct { |
67 | | u_int64_t sent_bytes; |
68 | | u_int64_t rcvd_bytes; |
69 | | } checkpoints; |
70 | | |
71 | | public: |
72 | | HostStats(Host* _host); |
73 | | virtual ~HostStats(); |
74 | | |
75 | | virtual void incStats(time_t when, u_int8_t l4_proto, u_int ndpi_proto, |
76 | | ndpi_protocol_category_t ndpi_category, |
77 | | custom_app_t custom_app, u_int64_t sent_packets, |
78 | | u_int64_t sent_bytes, u_int64_t sent_goodput_bytes, |
79 | | u_int64_t rcvd_packets, u_int64_t rcvd_bytes, |
80 | | u_int64_t rcvd_goodput_bytes, bool peer_is_unicast, |
81 | | bool local_to_local_traffic); |
82 | | void checkpoint(lua_State* vm); |
83 | | virtual void getJSONObject(json_object* my_object, |
84 | | DetailsLevel details_level); |
85 | | inline void incFlagStats(bool as_client, u_int8_t flags, |
86 | 8.01k | bool cumulative_flags) { |
87 | 8.01k | if (as_client) |
88 | 4.00k | sent_stats.incFlagStats(flags, cumulative_flags); |
89 | 4.00k | else |
90 | 4.00k | recv_stats.incFlagStats(flags, cumulative_flags); |
91 | 8.01k | }; |
92 | | |
93 | 0 | virtual void computeAnomalyIndex(time_t when) {}; |
94 | 0 | virtual u_int32_t getResetFlow() { return (0); }; |
95 | 0 | virtual void incResetFlow() {}; |
96 | 9.89k | inline Host* getHost() const { return (host); } |
97 | 0 | inline void incNumAlertedFlows(bool as_client) { |
98 | 0 | if (as_client) |
99 | 0 | alerted_flows_as_client++; |
100 | 0 | else |
101 | 0 | alerted_flows_as_server++; |
102 | 0 | }; |
103 | 104 | inline void incNumUnreachableFlows(bool as_server) { |
104 | 104 | if (as_server) |
105 | 52 | unreachable_flows_as_server++; |
106 | 52 | else |
107 | 52 | unreachable_flows_as_client++; |
108 | 104 | } |
109 | 2 | inline void incNumHostUnreachableFlows(bool as_server) { |
110 | 2 | if (as_server) |
111 | 1 | host_unreachable_flows_as_server++; |
112 | 1 | else |
113 | 1 | host_unreachable_flows_as_client++; |
114 | 2 | }; |
115 | 0 | inline void incNumFlowAlerts() { num_flow_alerts++; }; |
116 | 0 | inline void incTotalAlerts() { total_alerts++; }; |
117 | 0 | inline u_int32_t getTotalAlertedNumFlowsAsClient() const { |
118 | 0 | return (alerted_flows_as_client); |
119 | 0 | }; |
120 | 0 | inline u_int32_t getTotalAlertedNumFlowsAsServer() const { |
121 | 0 | return (alerted_flows_as_server); |
122 | 0 | }; |
123 | 0 | inline u_int32_t getTotalUnreachableNumFlowsAsClient() const { |
124 | 0 | return (unreachable_flows_as_client); |
125 | 0 | }; |
126 | 0 | inline u_int32_t getTotalUnreachableNumFlowsAsServer() const { |
127 | 0 | return (unreachable_flows_as_server); |
128 | 0 | }; |
129 | 0 | inline u_int32_t getTotalHostUnreachableNumFlowsAsClient() const { |
130 | 0 | return (host_unreachable_flows_as_client); |
131 | 0 | }; |
132 | 0 | inline u_int32_t getTotalHostUnreachableNumFlowsAsServer() const { |
133 | 0 | return (host_unreachable_flows_as_server); |
134 | 0 | }; |
135 | 0 | u_int32_t getTotalAlerts() const { return (total_alerts); }; |
136 | 0 | inline u_int32_t getNumFlowAlerts() const { return (num_flow_alerts); }; |
137 | | void luaNdpiStats(lua_State* vm); |
138 | | void luaActiveFlowsBehaviour(lua_State* vm); |
139 | | void luaScoreBehaviour(lua_State* vm); |
140 | | void luaStats(lua_State* vm, NetworkInterface* iface, bool host_details, |
141 | | bool verbose, bool tsLua = false); |
142 | 0 | virtual u_int16_t getNumActiveContactsAsClient() { return 0; } |
143 | 0 | virtual u_int16_t getNumActiveContactsAsServer() { return 0; } |
144 | 0 | virtual void resetTopSitesData() {}; |
145 | 0 | virtual void addContactedDomainName(char* domain_name) {} |
146 | 0 | virtual u_int32_t getDomainNamesCardinality() { return (u_int32_t)-1; } |
147 | 0 | virtual void resetDomainNamesCardinality() {} |
148 | | |
149 | 7.22k | inline void incSentStats(u_int num_pkts, u_int pkt_len) { |
150 | 7.22k | sent_stats.incStats(num_pkts, pkt_len); |
151 | 7.22k | }; |
152 | 7.22k | inline void incRecvStats(u_int num_pkts, u_int pkt_len) { |
153 | 7.22k | recv_stats.incStats(num_pkts, pkt_len); |
154 | 7.22k | }; |
155 | 11.7k | inline void incnDPIFlows(u_int16_t l7_protocol) { |
156 | 11.7k | if (ndpiStats) ndpiStats->incFlowsStats(l7_protocol); |
157 | 11.7k | }; |
158 | 0 | inline void incrConsecutiveHighScore() { consecutive_high_score++; }; |
159 | 0 | inline void resetConsecutiveHighScore() { consecutive_high_score = 0; }; |
160 | 0 | inline u_int8_t getConsecutiveHighScore() { |
161 | 0 | return (consecutive_high_score); |
162 | 0 | }; |
163 | 0 | inline u_int32_t getTotalNumFlowsAsClient() const { |
164 | 0 | return (total_num_flows_as_client); |
165 | 0 | }; |
166 | 0 | inline u_int32_t getTotalNumFlowsAsServer() const { |
167 | 0 | return (total_num_flows_as_server); |
168 | 0 | }; |
169 | 0 | inline u_int32_t getTotalActivityTime() const { |
170 | 0 | return (total_activity_time); |
171 | 0 | }; |
172 | 12.8k | virtual void incNumFlows(bool as_client) { |
173 | 12.8k | if (as_client) |
174 | 6.42k | total_num_flows_as_client++; |
175 | 6.42k | else |
176 | 6.42k | total_num_flows_as_server++; |
177 | 12.8k | }; |
178 | | |
179 | 0 | virtual void luaPeers(lua_State* vm) {}; |
180 | | virtual void lua(lua_State* vm, bool mask_host, DetailsLevel details_level); |
181 | | void updateStats(const struct timeval* tv); |
182 | | virtual void luaHostBehaviour(lua_State* vm); |
183 | | #ifdef NTOPNG_PRO |
184 | | inline void incQuotaEnforcementStats(time_t when, u_int16_t ndpi_proto, |
185 | | u_int64_t sent_packets, |
186 | | u_int64_t sent_bytes, |
187 | | u_int64_t rcvd_packets, |
188 | | u_int64_t rcvd_bytes) { |
189 | | if (quota_enforcement_stats) |
190 | | quota_enforcement_stats->incStats(when, ndpi_proto, sent_packets, |
191 | | sent_bytes, rcvd_packets, rcvd_bytes); |
192 | | }; |
193 | | inline void incQuotaEnforcementCategoryStats( |
194 | | time_t when, ndpi_protocol_category_t category_id, u_int64_t sent_bytes, |
195 | | u_int64_t rcvd_bytes) { |
196 | | if (quota_enforcement_stats) |
197 | | quota_enforcement_stats->incCategoryStats(when, category_id, sent_bytes, |
198 | | rcvd_bytes); |
199 | | } |
200 | | inline void resetQuotaStats() { |
201 | | if (quota_enforcement_stats) quota_enforcement_stats->resetStats(); |
202 | | }; |
203 | | |
204 | | void allocateQuotaEnforcementStats(); |
205 | | void deleteQuotaEnforcementStats(); |
206 | | inline HostPoolStats* getQuotaEnforcementStats() { |
207 | | return (quota_enforcement_stats); |
208 | | } |
209 | | #endif |
210 | | |
211 | 0 | virtual void luaHTTP(lua_State* vm) {} |
212 | 0 | virtual void luaDNS(lua_State* vm, bool verbose) {} |
213 | 0 | virtual void luaICMP(lua_State* vm, bool isV4, bool verbose) {} |
214 | 0 | virtual void incrVisitedWebSite(char* hostname) {} |
215 | 0 | virtual HTTPstats* getHTTPstats() { return (NULL); } |
216 | 0 | virtual DnsStats* getDNSstats() { return (NULL); } |
217 | 0 | virtual ICMPstats* getICMPstats() { return (NULL); } |
218 | | |
219 | 5.87k | virtual void incCliContactedPorts(u_int16_t port) { ; } |
220 | 5.87k | virtual void incSrvPortsContacts(u_int16_t port) { ; } |
221 | 70 | virtual void incContactedService(char* name) { ; } |
222 | 9.75k | virtual void incCliContactedHosts(IpAddress* peer) { ; } |
223 | 13.6k | virtual void incSrvHostContacts(IpAddress* peer) { ; } |
224 | 0 | virtual void incContactedHosts(char* hostname) { ; } |
225 | 0 | virtual void incCountriesContacts(char* country) { ; } |
226 | | |
227 | 0 | virtual void resetCountriesContacts() { ; } |
228 | 0 | virtual void resetContactedHosts() { ; } |
229 | | |
230 | 0 | virtual u_int16_t getCountriesContactsCardinality() { |
231 | 0 | return ((u_int16_t)-1); |
232 | 0 | } |
233 | 0 | virtual u_int16_t getContactedHostsCardinality() { return ((u_int16_t)-1); } |
234 | | |
235 | 0 | virtual u_int32_t getNTPContactCardinality() { return ((u_int32_t)-1); } |
236 | 0 | virtual u_int32_t getDNSContactCardinality() { return ((u_int32_t)-1); } |
237 | 0 | virtual u_int32_t getSMTPContactCardinality() { return ((u_int32_t)-1); } |
238 | 0 | virtual u_int32_t getIMAPContactCardinality() { return ((u_int32_t)-1); } |
239 | 0 | virtual u_int32_t getPOPContactCardinality() { return ((u_int32_t)-1); } |
240 | | |
241 | 0 | virtual bool incNTPContactCardinality(Host* h) { return (false); } |
242 | 0 | virtual bool incDNSContactCardinality(Host* h) { return (false); } |
243 | 0 | virtual bool incSMTPContactCardinality(Host* h) { return (false); } |
244 | 0 | virtual bool incIMAPContactCardinality(Host* h) { return (false); } |
245 | 0 | virtual bool incPOPContactCardinality(Host* h) { return (false); } |
246 | | |
247 | 0 | inline bool has_flows_anomaly(bool as_client) { |
248 | 0 | return (as_client ? client_flows_anomaly : server_flows_anomaly); |
249 | 0 | } |
250 | 0 | inline u_int64_t value_flows_anomaly(bool as_client) { |
251 | 0 | return (as_client ? active_flows_cli.getLastValue() |
252 | 0 | : active_flows_srv.getLastValue()); |
253 | 0 | } |
254 | 0 | inline u_int64_t lower_bound_flows_anomaly(bool as_client) { |
255 | 0 | return (as_client ? active_flows_cli.getLastLowerBound() |
256 | 0 | : active_flows_srv.getLastLowerBound()); |
257 | 0 | } |
258 | 0 | inline u_int64_t upper_bound_flows_anomaly(bool as_client) { |
259 | 0 | return (as_client ? active_flows_cli.getLastUpperBound() |
260 | 0 | : active_flows_srv.getLastUpperBound()); |
261 | 0 | } |
262 | | |
263 | 0 | inline bool has_score_anomaly(bool as_client) { |
264 | 0 | return (as_client ? client_score_anomaly : server_score_anomaly); |
265 | 0 | } |
266 | 0 | inline u_int64_t lower_bound_score_anomaly(bool as_client) { |
267 | 0 | return (as_client ? score_cli.getLastLowerBound() |
268 | 0 | : score_srv.getLastLowerBound()); |
269 | 0 | } |
270 | 0 | inline u_int64_t upper_bound_score_anomaly(bool as_client) { |
271 | 0 | return (as_client ? score_cli.getLastUpperBound() |
272 | 0 | : score_srv.getLastUpperBound()); |
273 | 0 | } |
274 | | |
275 | 0 | inline PacketStats* getSentStats() { return (&sent_stats); } |
276 | 0 | inline PacketStats* getRecvStats() { return (&recv_stats); } |
277 | 0 | inline L4Stats* getL4Stats() { return (&l4stats); } |
278 | 9.21k | inline bool isReceiveOnly() { |
279 | 9.21k | return ((getNumPktsSent() > 0) ? false : true); |
280 | 9.21k | } |
281 | | }; |
282 | | |
283 | | #endif |