Source Code for network and port scanner, TRW algorithm, and reduction method implementations.

flow.txt 11KB

1
  1. {"flows": [{"sip": "silk.IPv4Addr("10.1.20.5")", "protocol": 17, "timeout_killed": False, "dport": 53, "output": 0, "packets": 1L, "bytes": 58L, "uniform_packets": False, "application": 53, "sensor_id": 0, "timeout_started": False, "classtype_id": 0, "stime": "datetime.datetime(2009, 4, 20, 12, 57, 2, 147000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": ""datetime.timedelta(0, 0, 3000)", "input": 0, "sport": 57592, "dip": "silk.IPv4Addr("10.1.60.5")", "finnoack": False}, {"sip": "silk.IPv4Addr("10.1.10.5")", "protocol": 17, "timeout_killed": True, "dport": 53, "output": 0, "packets": 31L, "bytes": 1918L, "uniform_packets": False, "application": 53, "sensor_id": 0, "timeout_started": True, "classtype_id": 0, "stime": ""datetime.datetime(2009, 4, 20, 12, 36, 9, 311000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": ""datetime.timedelta(0, 1622, 804000)", "input": 0, "sport": 1031, "dip": "silk.IPv4Addr("10.1.60.5")", "finnoack": False}, {"sip": "silk.IPv4Addr("10.1.80.5")", "protocol": 17, "timeout_killed": False, "dport": 53, "output": 0, "packets": 1L, "bytes": 58L, "uniform_packets": False, "application": 53, "sensor_id": 0, "timeout_started": False, "classtype_id": 0, "stime": "datetime.datetime(2009, 4, 20, 12, 58, 38, 179000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": "datetime.timedelta(0, 0, 2000)", "input": 0, "sport": 64589, "dip": "silk.IPv4Addr("10.1.60.5")", "finnoack": False}, {"sip": "silk.IPv4Addr("10.1.20.5")", "protocol": 17, "timeout_killed": False, "dport": 53, "output": 0, "packets": 1L, "bytes": 58L, "uniform_packets": False, "application": 53, "sensor_id": 0, "timeout_started": False, "classtype_id": 0, "stime": "datetime.datetime(2009, 4, 20, 12, 59, 2, 570000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": "datetime.timedelta(0, 0, 2000)", "input": 0, "sport": 54198, "dip": "silk.IPv4Addr("10.1.60.5")", "finnoack": False}, {"sip": "silk.IPv4Addr("10.1.10.5")", "protocol": 17, "timeout_killed": False, "dport": 123, "output": 0, "packets": 1L, "bytes": 76L, "uniform_packets": False, "application": 0, "sensor_id": 0, "timeout_started": False, "classtype_id": 0, "stime": "datetime.datetime(2009, 4, 20, 12, 59, 22, 389000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": "datetime.timedelta(0)", "input": 0, "sport": 123, "dip": "silk.IPv4Addr("10.1.60.153")", "finnoack": False}, {"sip": "silk.IPv4Addr("10.1.10.5")", "protocol": 17, "timeout_killed": False, "dport": 53, "output": 0, "packets": 10L, "bytes": 1213L, "uniform_packets": False, "application": 53, "sensor_id": 0, "timeout_started": False, "classtype_id": 0, "stime": "datetime.datetime(2009, 4, 20, 12, 40, 17, 668000)", "nhip": "silk.IPv4Addr("0.0.0.0")", "duration": "datetime.timedelta(0, 1200, 640000)", "input": 0, "sport": 53, "dip": "silk.IPv4Addr("10.1.60.5")", "finnoack": False}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 0, 34, 563000)", "packets": 1L, "dport": 1472, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 0, 35, 116000)", "packets": 1L, "dport": 1472, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 0, 35, 619000)", "packets": 1L, "dport": 1472, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 25, 264000)", "packets": 1L, "dport": 3778, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 25, 265000)", "packets": 1L, "dport": 3779, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 25, 807000)", "packets": 1L, "dport": 3779, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 25, 808000)", "packets": 1L, "dport": 3778, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 26, 354000)", "packets": 1L, "dport": 3779, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 26, 355000)", "packets": 1L, "dport": 3778, "output": 0, "dip": "silk.IPv4Addr("10.1.10.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 53, 335000)", "packets": 1L, "dport": 62517, "output": 0, "dip": "silk.IPv4Addr("10.1.20.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 53, 947000)", "packets": 1L, "dport": 55759, "output": 0, "dip": "silk.IPv4Addr("10.1.20.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 1, 54, 497000)", "packets": 1L, "dport": 52170, "output": 0, "dip": "silk.IPv4Addr("10.1.20.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 2, 34, 553000)", "packets": 1L, "dport": 1474, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 2, 35, 71000)", "packets": 1L, "dport": 1474, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}, {"sensor_id": 0, "protocol": 6, "bytes": 40L, "tcpflags": "silk.TCPFlags(" R A ")", "classtype_id": 1, "duration": "datetime.timedelta(0)", "nhip": "silk.IPv4Addr("0.0.0.0")", "sport": 53, "uniform_packets": False, "sip": "silk.IPv4Addr("10.1.60.5")", "timeout_killed": False, "timeout_started": False, "session_tcpflags": "silk.TCPFlags(" ")", "application": 0, "initial_tcpflags": "silk.TCPFlags(" R A ")", "input": 0, "finnoack": False, "stime": "datetime.datetime(2009, 4, 20, 12, 2, 35, 509000)", "packets": 1L, "dport": 1474, "output": 0, "dip": "silk.IPv4Addr("10.1.80.5")"}]}