forked from Nicollas21/projeto-psd-rsi
-
Notifications
You must be signed in to change notification settings - Fork 0
/
ClassificaPkt.py
136 lines (112 loc) · 4.46 KB
/
ClassificaPkt.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
# -*- coding: utf-8 -*-
#!/usr/bin/env python
import pika
import sys
import pcap, dpkt, re
class ClassificaPkt():
protocols = {"bittorrent":"","dhcp":"","http":"","ssdp":"","ssh":"","ssl":""}
maxPkts = 100
cnt = {"bittorrent":0,"dhcp":0,"http":0,"ssdp":0,"ssh":0,"ssl":0,"unknown":0}
#contadores
cNonIP = 0
def get_arquivo(self,Dir):
file = open(Dir).readlines()
return file
def assinar_protocols(self, p1, p2, p3, p4, p5, p6):
expr = p1[1]
bittorrent = re.compile(expr)
expr = p2[1]
dhcp = re.compile(expr)
expr = p3[1]
http = re.compile(expr)
expr = p4[1]
ssdp = re.compile(expr)
expr = p5[1]
ssh = re.compile(expr)
expr = p6[1]
ssl = re.compile(expr)
self.protocols = {"bittorrent":bittorrent,"dhcp":dhcp,"http":http,"ssdp":ssdp,"ssh":ssh,"ssl":ssl}
def get_protocol_trans_tcp(self,app,eth,ts):
found = False
for p in self.protocols.items():
if p[1].search(app):
tamanho = len(eth)
tupla = tamanho,ts,"eth","ip","tcp",p[0]
self.modifier_tupla(tupla)
self.cnt[p[0]] += 1
found = True
if (not found):
self.cnt["unknown"] += 1
tupla = "unknown","tcp","sem info"
self.modifier_tupla(tupla)
def get_protocol_trans_udp(self,app,eth,ts):
found = False
for p in self.protocols.items():
if p[1].search(app):
tamanho = len(eth)
tupla = tamanho,ts,"eth","ip","udp",p[0]
self.modifier_tupla(tupla)
self.cnt[p[0]] += 1
found = True
if (not found):
self.cnt["unknown"] += 1
tupla = "unknown","udp","sem info"
self.modifier_tupla(tupla)
def classificar_protocol(self, protocols):
#nPkts=0
for ts, pkt in pcap.pcap('test-capture.pcap'):
#nPkts += 1
eth = dpkt.ethernet.Ethernet(pkt) #extraindo dados do pacote
ip = eth.data
if isinstance(ip,dpkt.ip.IP):
transp = ip.data
if isinstance(transp,dpkt.tcp.TCP):
app = transp.data.lower()
self.get_protocol_trans_tcp(app,eth,ts)
elif isinstance(transp,dpkt.udp.UDP):
app = transp.data.lower()
self.get_protocol_trans_udp(app,eth,ts)
else:
self.cNonIP += 1
tupla = "unknown","sem info"
self.modifier_tupla(tupla)
#if (nPkts == self.maxPkts):
#break
for p in self.cnt.items():
print(p[0]+" Pkts:"+str(p[1]))
print("Non IP Pkts:"+str(self.cNonIP))
def modifier_tupla(self,tupla):
#print type(tupla[0])
if type(tupla[0]) is int:
tupla = str(tupla)
tupla = tupla.replace(" ","")
tupla = tupla.replace("(","")
tupla = tupla.replace(")","")
teste = tupla.split(',')
nome_protocolo = str(teste[5].replace("'",""))
print nome_protocolo
#self.envia_tupla(nome_protocolo,teste)
else:
tupla = str(tupla)
tupla = tupla.replace(" ","")
tupla = tupla.replace("(","")
tupla = tupla.replace(")","")
teste = tupla.split(',')
nome_protocolo = str(teste[0].replace("'",""))
print nome_protocolo
#self.envia_tupla(nome_protocolo,teste)
def envia_tupla(nome_protocolo, msg):
credentials = pika.PlainCredentials('server', 'server123')
connection = pika.BlockingConnection(pika.ConnectionParameters(
'172.16.205.153', 5672, 'grupo1', credentials))
channel = connection.channel()
channel.exchange_declare(exchange='topic_logs',
type='topic')
routing_key = nome_protocolo if len(msg) > 1 else 'anonymous.info'
print routing_key
message = str(msg) or 'Hello World!'
channel.basic_publish(exchange='topic_logs',
routing_key=routing_key,
body=message)
print " [x] Sent %r:%r" % (routing_key, message)
connection.close()