Coverage Report

Created: 2026-09-04 06:51

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ntopng/include/HostStats.h
Line
Count
Source
1
/*
2
 *
3
 * (C) 2013-26 - ntop.org
4
 *
5
 *
6
 * This program is free software; you can redistribute it and/or modify
7
 * it under the terms of the GNU General Public License as published by
8
 * the Free Software Foundation; either version 3 of the License, or
9
 * (at your option) any later version.
10
 *
11
 * This program is distributed in the hope that it will be useful,
12
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14
 * GNU General Public License for more details.
15
 *
16
 * You should have received a copy of the GNU General Public License
17
 * along with this program; if not, write to the Free Software Foundation,
18
 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
19
 *
20
 */
21
22
#ifndef _HOST_STATS_H_
23
#define _HOST_STATS_H_
24
25
class Host;
26
27
class HostStats : public GenericTrafficElement {
28
 protected:
29
  Host* host;
30
31
  u_int8_t client_flows_anomaly : 1, server_flows_anomaly : 1,
32
      client_score_anomaly : 1, server_score_anomaly : 1, _notused : 4;
33
  u_int32_t total_alerts;
34
  u_int32_t unreachable_flows_as_client, unreachable_flows_as_server;
35
  /* Used concurrently in view interfaces, possibly removed after
36
   * https://github.com/ntop/ntopng/issues/4596 */
37
  u_int32_t alerted_flows_as_client, alerted_flows_as_server;
38
  u_int32_t host_unreachable_flows_as_client, host_unreachable_flows_as_server;
39
  u_int32_t total_num_flows_as_client, total_num_flows_as_server;
40
  u_int32_t num_flow_alerts;
41
  u_int64_t udp_sent_unicast, udp_sent_non_unicast;
42
  L4Stats l4stats;
43
44
  u_int8_t consecutive_high_score;
45
  time_t periodicUpdate, periodic_stats_update;
46
47
  /* *************************************** */
48
  /* Behavioural analysis regarding the host */
49
  DESCounter active_flows_srv, active_flows_cli, score_cli, score_srv;
50
51
  /* **************************************** */
52
53
  /* Written by NetworkInterface::periodicStatsUpdate thread */
54
  // NOTE: GenericTrafficElement inherited data is updated periodically too
55
  u_int32_t total_activity_time /* sec */;
56
  u_int32_t last_epoch_update; /* useful to avoid multiple updates */
57
58
#ifdef NTOPNG_PRO
59
  HostPoolStats *quota_enforcement_stats, *quota_enforcement_stats_shadow;
60
#endif
61
62
  /* Written by NetworkInterface::processPacket thread */
63
  PacketStats sent_stats, recv_stats;
64
65
  /* Used to store checkpoint data to build top talkers stats */
66
  struct {
67
    u_int64_t sent_bytes;
68
    u_int64_t rcvd_bytes;
69
  } checkpoints;
70
71
 public:
72
  HostStats(Host* _host);
73
  virtual ~HostStats();
74
75
  virtual void incStats(time_t when, u_int8_t l4_proto, u_int ndpi_proto,
76
                        ndpi_protocol_category_t ndpi_category,
77
                        custom_app_t custom_app, u_int64_t sent_packets,
78
                        u_int64_t sent_bytes, u_int64_t sent_goodput_bytes,
79
                        u_int64_t rcvd_packets, u_int64_t rcvd_bytes,
80
                        u_int64_t rcvd_goodput_bytes, bool peer_is_unicast,
81
      bool local_to_local_traffic);
82
  void checkpoint(lua_State* vm);
83
  virtual void getJSONObject(json_object* my_object,
84
                             DetailsLevel details_level);
85
  inline void incFlagStats(bool as_client, u_int8_t flags,
86
8.01k
                           bool cumulative_flags) {
87
8.01k
    if (as_client)
88
4.00k
      sent_stats.incFlagStats(flags, cumulative_flags);
89
4.00k
    else
90
4.00k
      recv_stats.incFlagStats(flags, cumulative_flags);
91
8.01k
  };
92
93
0
  virtual void computeAnomalyIndex(time_t when) {};
94
0
  virtual u_int32_t getResetFlow() { return (0); };
95
0
  virtual void incResetFlow() {};
96
9.89k
  inline Host* getHost() const { return (host); }
97
0
  inline void incNumAlertedFlows(bool as_client) {
98
0
    if (as_client)
99
0
      alerted_flows_as_client++;
100
0
    else
101
0
      alerted_flows_as_server++;
102
0
  };
103
104
  inline void incNumUnreachableFlows(bool as_server) {
104
104
    if (as_server)
105
52
      unreachable_flows_as_server++;
106
52
    else
107
52
      unreachable_flows_as_client++;
108
104
  }
109
2
  inline void incNumHostUnreachableFlows(bool as_server) {
110
2
    if (as_server)
111
1
      host_unreachable_flows_as_server++;
112
1
    else
113
1
      host_unreachable_flows_as_client++;
114
2
  };
115
0
  inline void incNumFlowAlerts() { num_flow_alerts++; };
116
0
  inline void incTotalAlerts() { total_alerts++; };
117
0
  inline u_int32_t getTotalAlertedNumFlowsAsClient() const {
118
0
    return (alerted_flows_as_client);
119
0
  };
120
0
  inline u_int32_t getTotalAlertedNumFlowsAsServer() const {
121
0
    return (alerted_flows_as_server);
122
0
  };
123
0
  inline u_int32_t getTotalUnreachableNumFlowsAsClient() const {
124
0
    return (unreachable_flows_as_client);
125
0
  };
126
0
  inline u_int32_t getTotalUnreachableNumFlowsAsServer() const {
127
0
    return (unreachable_flows_as_server);
128
0
  };
129
0
  inline u_int32_t getTotalHostUnreachableNumFlowsAsClient() const {
130
0
    return (host_unreachable_flows_as_client);
131
0
  };
132
0
  inline u_int32_t getTotalHostUnreachableNumFlowsAsServer() const {
133
0
    return (host_unreachable_flows_as_server);
134
0
  };
135
0
  u_int32_t getTotalAlerts() const { return (total_alerts); };
136
0
  inline u_int32_t getNumFlowAlerts() const { return (num_flow_alerts); };
137
  void luaNdpiStats(lua_State* vm);
138
  void luaActiveFlowsBehaviour(lua_State* vm);
139
  void luaScoreBehaviour(lua_State* vm);
140
  void luaStats(lua_State* vm, NetworkInterface* iface, bool host_details,
141
                bool verbose, bool tsLua = false);
142
0
  virtual u_int16_t getNumActiveContactsAsClient() { return 0; }
143
0
  virtual u_int16_t getNumActiveContactsAsServer() { return 0; }
144
0
  virtual void resetTopSitesData() {};
145
0
  virtual void addContactedDomainName(char* domain_name) {}
146
0
  virtual u_int32_t getDomainNamesCardinality() { return (u_int32_t)-1; }
147
0
  virtual void resetDomainNamesCardinality() {}
148
149
7.22k
  inline void incSentStats(u_int num_pkts, u_int pkt_len) {
150
7.22k
    sent_stats.incStats(num_pkts, pkt_len);
151
7.22k
  };
152
7.22k
  inline void incRecvStats(u_int num_pkts, u_int pkt_len) {
153
7.22k
    recv_stats.incStats(num_pkts, pkt_len);
154
7.22k
  };
155
11.7k
  inline void incnDPIFlows(u_int16_t l7_protocol) {
156
11.7k
    if (ndpiStats) ndpiStats->incFlowsStats(l7_protocol);
157
11.7k
  };
158
0
  inline void incrConsecutiveHighScore() { consecutive_high_score++; };
159
0
  inline void resetConsecutiveHighScore() { consecutive_high_score = 0; };
160
0
  inline u_int8_t getConsecutiveHighScore() {
161
0
    return (consecutive_high_score);
162
0
  };
163
0
  inline u_int32_t getTotalNumFlowsAsClient() const {
164
0
    return (total_num_flows_as_client);
165
0
  };
166
0
  inline u_int32_t getTotalNumFlowsAsServer() const {
167
0
    return (total_num_flows_as_server);
168
0
  };
169
0
  inline u_int32_t getTotalActivityTime() const {
170
0
    return (total_activity_time);
171
0
  };
172
12.8k
  virtual void incNumFlows(bool as_client) {
173
12.8k
    if (as_client)
174
6.42k
      total_num_flows_as_client++;
175
6.42k
    else
176
6.42k
      total_num_flows_as_server++;
177
12.8k
  };
178
179
0
  virtual void luaPeers(lua_State* vm) {};
180
  virtual void lua(lua_State* vm, bool mask_host, DetailsLevel details_level);
181
  void updateStats(const struct timeval* tv);
182
  virtual void luaHostBehaviour(lua_State* vm);
183
#ifdef NTOPNG_PRO
184
  inline void incQuotaEnforcementStats(time_t when, u_int16_t ndpi_proto,
185
                                       u_int64_t sent_packets,
186
                                       u_int64_t sent_bytes,
187
                                       u_int64_t rcvd_packets,
188
                                       u_int64_t rcvd_bytes) {
189
    if (quota_enforcement_stats)
190
      quota_enforcement_stats->incStats(when, ndpi_proto, sent_packets,
191
                                        sent_bytes, rcvd_packets, rcvd_bytes);
192
  };
193
  inline void incQuotaEnforcementCategoryStats(
194
      time_t when, ndpi_protocol_category_t category_id, u_int64_t sent_bytes,
195
      u_int64_t rcvd_bytes) {
196
    if (quota_enforcement_stats)
197
      quota_enforcement_stats->incCategoryStats(when, category_id, sent_bytes,
198
                                                rcvd_bytes);
199
  }
200
  inline void resetQuotaStats() {
201
    if (quota_enforcement_stats) quota_enforcement_stats->resetStats();
202
  };
203
204
  void allocateQuotaEnforcementStats();
205
  void deleteQuotaEnforcementStats();
206
  inline HostPoolStats* getQuotaEnforcementStats() {
207
    return (quota_enforcement_stats);
208
  }
209
#endif
210
211
0
  virtual void luaHTTP(lua_State* vm) {}
212
0
  virtual void luaDNS(lua_State* vm, bool verbose) {}
213
0
  virtual void luaICMP(lua_State* vm, bool isV4, bool verbose) {}
214
0
  virtual void incrVisitedWebSite(char* hostname) {}
215
0
  virtual HTTPstats* getHTTPstats() { return (NULL); }
216
0
  virtual DnsStats* getDNSstats() { return (NULL); }
217
0
  virtual ICMPstats* getICMPstats() { return (NULL); }
218
219
5.87k
  virtual void incCliContactedPorts(u_int16_t port) { ; }
220
5.87k
  virtual void incSrvPortsContacts(u_int16_t port) { ; }
221
70
  virtual void incContactedService(char* name) { ; }
222
9.75k
  virtual void incCliContactedHosts(IpAddress* peer) { ; }
223
13.6k
  virtual void incSrvHostContacts(IpAddress* peer) { ; }
224
0
  virtual void incContactedHosts(char* hostname) { ; }
225
0
  virtual void incCountriesContacts(char* country) { ; }
226
227
0
  virtual void resetCountriesContacts() { ; }
228
0
  virtual void resetContactedHosts() { ; }
229
230
0
  virtual u_int16_t getCountriesContactsCardinality() {
231
0
    return ((u_int16_t)-1);
232
0
  }
233
0
  virtual u_int16_t getContactedHostsCardinality() { return ((u_int16_t)-1); }
234
235
0
  virtual u_int32_t getNTPContactCardinality() { return ((u_int32_t)-1); }
236
0
  virtual u_int32_t getDNSContactCardinality() { return ((u_int32_t)-1); }
237
0
  virtual u_int32_t getSMTPContactCardinality() { return ((u_int32_t)-1); }
238
0
  virtual u_int32_t getIMAPContactCardinality() { return ((u_int32_t)-1); }
239
0
  virtual u_int32_t getPOPContactCardinality() { return ((u_int32_t)-1); }
240
241
0
  virtual bool incNTPContactCardinality(Host* h) { return (false); }
242
0
  virtual bool incDNSContactCardinality(Host* h) { return (false); }
243
0
  virtual bool incSMTPContactCardinality(Host* h) { return (false); }
244
0
  virtual bool incIMAPContactCardinality(Host* h) { return (false); }
245
0
  virtual bool incPOPContactCardinality(Host* h) { return (false); }
246
247
0
  inline bool has_flows_anomaly(bool as_client) {
248
0
    return (as_client ? client_flows_anomaly : server_flows_anomaly);
249
0
  }
250
0
  inline u_int64_t value_flows_anomaly(bool as_client) {
251
0
    return (as_client ? active_flows_cli.getLastValue()
252
0
                      : active_flows_srv.getLastValue());
253
0
  }
254
0
  inline u_int64_t lower_bound_flows_anomaly(bool as_client) {
255
0
    return (as_client ? active_flows_cli.getLastLowerBound()
256
0
                      : active_flows_srv.getLastLowerBound());
257
0
  }
258
0
  inline u_int64_t upper_bound_flows_anomaly(bool as_client) {
259
0
    return (as_client ? active_flows_cli.getLastUpperBound()
260
0
                      : active_flows_srv.getLastUpperBound());
261
0
  }
262
263
0
  inline bool has_score_anomaly(bool as_client) {
264
0
    return (as_client ? client_score_anomaly : server_score_anomaly);
265
0
  }
266
0
  inline u_int64_t lower_bound_score_anomaly(bool as_client) {
267
0
    return (as_client ? score_cli.getLastLowerBound()
268
0
                      : score_srv.getLastLowerBound());
269
0
  }
270
0
  inline u_int64_t upper_bound_score_anomaly(bool as_client) {
271
0
    return (as_client ? score_cli.getLastUpperBound()
272
0
                      : score_srv.getLastUpperBound());
273
0
  }
274
275
0
  inline PacketStats* getSentStats() { return (&sent_stats); }
276
0
  inline PacketStats* getRecvStats() { return (&recv_stats); }
277
0
  inline L4Stats* getL4Stats() { return (&l4stats); }
278
9.21k
  inline bool isReceiveOnly() {
279
9.21k
    return ((getNumPktsSent() > 0) ? false : true);
280
9.21k
  }
281
};
282
283
#endif