-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathgommunityid.go
91 lines (86 loc) · 2.47 KB
/
gommunityid.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
package main
import (
"flag"
"fmt"
"log"
"net"
"os"
"strconv"
"github.com/satta/gommunityid"
)
func main() {
pcapCmd := flag.NewFlagSet("pcap", flag.ExitOnError)
pcapVersion := pcapCmd.Uint("version", 1, "Community ID version")
pcapSeed := pcapCmd.Uint("seed", 0, "seed value (default 0)")
tupleCmd := flag.NewFlagSet("tuple", flag.ExitOnError)
tupleVersion := tupleCmd.Uint("version", 1, "Community ID version")
tupleSeed := tupleCmd.Uint("seed", 0, "seed value (default 0)")
if len(os.Args) < 2 {
fmt.Println("Usage: gommunityid <pcap|tuple> ...")
os.Exit(1)
}
switch os.Args[1] {
case "pcap":
pcapCmd.Parse(os.Args[2:])
if len(pcapCmd.Args()) == 0 {
fmt.Println("Usage: gommunityid pcap [options] <pcap-file>")
pcapCmd.PrintDefaults()
os.Exit(1)
}
ftChan, err := gommunityid.PcapFlowTupleSource(pcapCmd.Args()[0])
if err != nil {
log.Fatal(err)
}
cid, err := gommunityid.GetCommunityIDByVersion(*pcapVersion, uint16(*pcapSeed))
if err != nil {
log.Fatal(err)
}
for ft := range ftChan {
communityid := cid.CalcBase64(ft.FlowTuple)
fmt.Printf("%d%s | %s | %s %s %d %d %d\n",
ft.Metadata.Timestamp.Unix(),
ft.Metadata.Timestamp.Format(".000000"),
communityid,
ft.FlowTuple.Srcip, ft.FlowTuple.Dstip,
ft.FlowTuple.Proto,
ft.FlowTuple.Srcport, ft.FlowTuple.Dstport)
}
case "tuple":
tupleCmd.Parse(os.Args[2:])
if len(tupleCmd.Args()) != 5 {
fmt.Println("Usage: gommunityid tuple [options] <proto> <srcip> <dstip> <srcport> <dstport>")
tupleCmd.PrintDefaults()
os.Exit(1)
}
cid, err := gommunityid.GetCommunityIDByVersion(*tupleVersion, uint16(*tupleSeed))
if err != nil {
log.Fatal(err)
}
srcip := net.ParseIP(tupleCmd.Args()[1])
if srcip == nil {
log.Fatalf("%s is not a valid IP address", tupleCmd.Args()[1])
}
dstip := net.ParseIP(tupleCmd.Args()[2])
if dstip == nil {
log.Fatalf("%s is not a valid IP address", tupleCmd.Args()[2])
}
srcport, err := strconv.ParseUint(tupleCmd.Args()[3], 10, 16)
if err != nil {
log.Fatal(err)
}
dstport, err := strconv.ParseUint(tupleCmd.Args()[4], 10, 16)
if err != nil {
log.Fatal(err)
}
proto, err := strconv.ParseUint(tupleCmd.Args()[0], 10, 8)
if err != nil {
log.Fatal(err)
}
ft := gommunityid.MakeFlowTuple(srcip, dstip, uint16(srcport), uint16(dstport), uint8(proto))
communityid := cid.CalcBase64(ft)
fmt.Printf("%s\n", communityid)
default:
fmt.Println("expected 'pcap' or 'tuple' subcommands")
os.Exit(1)
}
}