Skip to content

traffic66 0.2.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:40
5e69fbd

Findings

  • traffic66 now looks through the flows every 5 minutes and lists what
    needs attention on a new Findings page: scans, port scans, password
    guessing, lateral movement inside the network, unusual uploads to new
    destinations, floods and traffic with addresses on threat lists. Each
    finding is a sentence (who did what to whom, when, for how long) with the
    numbers behind it and how the data was sampled.
  • The rules work on sampled sFlow and NetFlow. Tested with the demo's
    attack sent through a switch sampling 1:4096: every step is found, each
    as one finding; a day of normal traffic gives no findings apart from the
    internet scanner.
  • Dealt with and Not a problem close a finding; "not a problem" is
    never reported again. The overview shows the open findings first, a
    host's details page lists the findings about it, and the side menu shows
    how many high and medium findings are open.

Fixes

  • A host's details page counted only part of the internal hosts it talked
    to (the servers of internal conversations were missed).
  • Arabic and Urdu: ports read backwards ("tcp/445") and names ran into
    their addresses.

Drill-down and naming

  • Show details on any host, device or service opens a page about it:
    traffic over time by application, who it talks to, services or clients,
    countries and the latest flows. Everything on it can be clicked again to
    keep drilling down; the browser's Back button returns.
  • Name it… on any host or device names it on the spot; the name is
    saved and shown everywhere. The Names box on Sources now shows examples.

Countries and networks database

  • Upload a database on the Sources page: MaxMind GeoLite2 or DB-IP Lite
    .mmdb files (country or ASN) or an IP-to-ASN table (.tsv, .tsv.gz).
    It is checked, saved and used for new traffic at once, without a
    restart. The .mmdb reader was checked against MaxMind's own reader on
    60,000 lookups in six DB-IP databases with no difference.

Simpler pages

  • Top-N is one table: conversations (client, server, service, country) by
    default; Group by switches the grouping. Every column sorts, and
    the number columns (traffic, packets, average packet size, flows) rank
    all traffic in the range rather than re-ordering the rows shown: the
    smallest average packet size finds scanners and floods. The row of
    eleven tabs is gone.
  • "Who grew" is gone from the overview (web and terminal UI).
  • Flow paths: labels, bars and flows can all be clicked; before, only the
    thin bars could.
  • The side menu no longer shows group headings that looked like buttons;
    "Log out" no longer wraps.
  • Disk in the side menu shows used and free space; hovering over the free
    space shows how much the kept days of detail need at the current rate.
    The old "days left" figure was an unreliable extrapolation.

Capture

  • Windows local capture by name: -capture Wi-Fi, -capture Ethernet or
    the number from traffic66 interfaces, which now shows each adapter's
    Windows connection name and address.
  • Commands copied from a web page or chat work: full-width spaces, quotes,
    full-width dashes and a trailing full stop around words are ignored, and
    a mistyped command gets a "did you mean" hint.

Documentation

  • README (13 languages): drill-down, naming, the database upload, local
    capture step by step for Windows, Linux and macOS including what Wi-Fi
    can and cannot see, new screenshots.
  • This changelog; releases take their notes from it.

Downloads and installation: see the README.