Import from old repository

This commit is contained in:
Stefan 2020-04-06 18:44:45 +02:00
commit 5382fa57a4
204 changed files with 19878 additions and 0 deletions

674
LICENSE.txt Normal file
View File

@ -0,0 +1,674 @@
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this, the GPL assures that
patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and
modification follow.
TERMS AND CONDITIONS
0. Definitions.
"This License" refers to version 3 of the GNU General Public License.
"Copyright" also means copyright-like laws that apply to other kinds of
works, such as semiconductor masks.
"The Program" refers to any copyrightable work licensed under this
License. Each licensee is addressed as "you". "Licensees" and
"recipients" may be individuals or organizations.
To "modify" a work means to copy from or adapt all or part of the work
in a fashion requiring copyright permission, other than the making of an
exact copy. The resulting work is called a "modified version" of the
earlier work or a work "based on" the earlier work.
A "covered work" means either the unmodified Program or a work based
on the Program.
To "propagate" a work means to do anything with it that, without
permission, would make you directly or secondarily liable for
infringement under applicable copyright law, except executing it on a
computer or modifying a private copy. Propagation includes copying,
distribution (with or without modification), making available to the
public, and in some countries other activities as well.
To "convey" a work means any kind of propagation that enables other
parties to make or receive copies. Mere interaction with a user through
a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays "Appropriate Legal Notices"
to the extent that it includes a convenient and prominently visible
feature that (1) displays an appropriate copyright notice, and (2)
tells the user that there is no warranty for the work (except to the
extent that warranties are provided), that licensees may convey the
work under this License, and how to view a copy of this License. If
the interface presents a list of user commands or options, such as a
menu, a prominent item in the list meets this criterion.
1. Source Code.
The "source code" for a work means the preferred form of the work
for making modifications to it. "Object code" means any non-source
form of a work.
A "Standard Interface" means an interface that either is an official
standard defined by a recognized standards body, or, in the case of
interfaces specified for a particular programming language, one that
is widely used among developers working in that language.
The "System Libraries" of an executable work include anything, other
than the work as a whole, that (a) is included in the normal form of
packaging a Major Component, but which is not part of that Major
Component, and (b) serves only to enable use of the work with that
Major Component, or to implement a Standard Interface for which an
implementation is available to the public in source code form. A
"Major Component", in this context, means a major essential component
(kernel, window system, and so on) of the specific operating system
(if any) on which the executable work runs, or a compiler used to
produce the work, or an object code interpreter used to run it.
The "Corresponding Source" for a work in object code form means all
the source code needed to generate, install, and (for an executable
work) run the object code and to modify the work, including scripts to
control those activities. However, it does not include the work's
System Libraries, or general-purpose tools or generally available free
programs which are used unmodified in performing those activities but
which are not part of the work. For example, Corresponding Source
includes interface definition files associated with source files for
the work, and the source code for shared libraries and dynamically
linked subprograms that the work is specifically designed to require,
such as by intimate data communication or control flow between those
subprograms and other parts of the work.
The Corresponding Source need not include anything that users
can regenerate automatically from other parts of the Corresponding
Source.
The Corresponding Source for a work in source code form is that
same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of
copyright on the Program, and are irrevocable provided the stated
conditions are met. This License explicitly affirms your unlimited
permission to run the unmodified Program. The output from running a
covered work is covered by this License only if the output, given its
content, constitutes a covered work. This License acknowledges your
rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not
convey, without conditions so long as your license otherwise remains
in force. You may convey covered works to others for the sole purpose
of having them make modifications exclusively for you, or provide you
with facilities for running those works, provided that you comply with
the terms of this License in conveying all material for which you do
not control copyright. Those thus making or running the covered works
for you must do so exclusively on your behalf, under your direction
and control, on terms that prohibit them from making any copies of
your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under
the conditions stated below. Sublicensing is not allowed; section 10
makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological
measure under any applicable law fulfilling obligations under article
11 of the WIPO copyright treaty adopted on 20 December 1996, or
similar laws prohibiting or restricting circumvention of such
measures.
When you convey a covered work, you waive any legal power to forbid
circumvention of technological measures to the extent such circumvention
is effected by exercising rights under this License with respect to
the covered work, and you disclaim any intention to limit operation or
modification of the work as a means of enforcing, against the work's
users, your or third parties' legal rights to forbid circumvention of
technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you
receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice;
keep intact all notices stating that this License and any
non-permissive terms added in accord with section 7 apply to the code;
keep intact all notices of the absence of any warranty; and give all
recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey,
and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to
produce it from the Program, in the form of source code under the
terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified
it, and giving a relevant date.
b) The work must carry prominent notices stating that it is
released under this License and any conditions added under section
7. This requirement modifies the requirement in section 4 to
"keep intact all notices".
c) You must license the entire work, as a whole, under this
License to anyone who comes into possession of a copy. This
License will therefore apply, along with any applicable section 7
additional terms, to the whole of the work, and all its parts,
regardless of how they are packaged. This License gives no
permission to license the work in any other way, but it does not
invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display
Appropriate Legal Notices; however, if the Program has interactive
interfaces that do not display Appropriate Legal Notices, your
work need not make them do so.
A compilation of a covered work with other separate and independent
works, which are not by their nature extensions of the covered work,
and which are not combined with it such as to form a larger program,
in or on a volume of a storage or distribution medium, is called an
"aggregate" if the compilation and its resulting copyright are not
used to limit the access or legal rights of the compilation's users
beyond what the individual works permit. Inclusion of a covered work
in an aggregate does not cause this License to apply to the other
parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms
of sections 4 and 5, provided that you also convey the
machine-readable Corresponding Source under the terms of this License,
in one of these ways:
a) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by the
Corresponding Source fixed on a durable physical medium
customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by a
written offer, valid for at least three years and valid for as
long as you offer spare parts or customer support for that product
model, to give anyone who possesses the object code either (1) a
copy of the Corresponding Source for all the software in the
product that is covered by this License, on a durable physical
medium customarily used for software interchange, for a price no
more than your reasonable cost of physically performing this
conveying of source, or (2) access to copy the
Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the
written offer to provide the Corresponding Source. This
alternative is allowed only occasionally and noncommercially, and
only if you received the object code with such an offer, in accord
with subsection 6b.
d) Convey the object code by offering access from a designated
place (gratis or for a charge), and offer equivalent access to the
Corresponding Source in the same way through the same place at no
further charge. You need not require recipients to copy the
Corresponding Source along with the object code. If the place to
copy the object code is a network server, the Corresponding Source
may be on a different server (operated by you or a third party)
that supports equivalent copying facilities, provided you maintain
clear directions next to the object code saying where to find the
Corresponding Source. Regardless of what server hosts the
Corresponding Source, you remain obligated to ensure that it is
available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided
you inform other peers where the object code and Corresponding
Source of the work are being offered to the general public at no
charge under subsection 6d.
A separable portion of the object code, whose source code is excluded
from the Corresponding Source as a System Library, need not be
included in conveying the object code work.
A "User Product" is either (1) a "consumer product", which means any
tangible personal property which is normally used for personal, family,
or household purposes, or (2) anything designed or sold for incorporation
into a dwelling. In determining whether a product is a consumer product,
doubtful cases shall be resolved in favor of coverage. For a particular
product received by a particular user, "normally used" refers to a
typical or common use of that class of product, regardless of the status
of the particular user or of the way in which the particular user
actually uses, or expects or is expected to use, the product. A product
is a consumer product regardless of whether the product has substantial
commercial, industrial or non-consumer uses, unless such uses represent
the only significant mode of use of the product.
"Installation Information" for a User Product means any methods,
procedures, authorization keys, or other information required to install
and execute modified versions of a covered work in that User Product from
a modified version of its Corresponding Source. The information must
suffice to ensure that the continued functioning of the modified object
code is in no case prevented or interfered with solely because
modification has been made.
If you convey an object code work under this section in, or with, or
specifically for use in, a User Product, and the conveying occurs as
part of a transaction in which the right of possession and use of the
User Product is transferred to the recipient in perpetuity or for a
fixed term (regardless of how the transaction is characterized), the
Corresponding Source conveyed under this section must be accompanied
by the Installation Information. But this requirement does not apply
if neither you nor any third party retains the ability to install
modified object code on the User Product (for example, the work has
been installed in ROM).
The requirement to provide Installation Information does not include a
requirement to continue to provide support service, warranty, or updates
for a work that has been modified or installed by the recipient, or for
the User Product in which it has been modified or installed. Access to a
network may be denied when the modification itself materially and
adversely affects the operation of the network or violates the rules and
protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided,
in accord with this section must be in a format that is publicly
documented (and with an implementation available to the public in
source code form), and must require no special password or key for
unpacking, reading or copying.
7. Additional Terms.
"Additional permissions" are terms that supplement the terms of this
License by making exceptions from one or more of its conditions.
Additional permissions that are applicable to the entire Program shall
be treated as though they were included in this License, to the extent
that they are valid under applicable law. If additional permissions
apply only to part of the Program, that part may be used separately
under those permissions, but the entire Program remains governed by
this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option
remove any additional permissions from that copy, or from any part of
it. (Additional permissions may be written to require their own
removal in certain cases when you modify the work.) You may place
additional permissions on material, added by you to a covered work,
for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you
add to a covered work, you may (if authorized by the copyright holders of
that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the
terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or
author attributions in that material or in the Appropriate Legal
Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or
requiring that modified versions of such material be marked in
reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or
authors of the material; or
e) Declining to grant rights under trademark law for use of some
trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that
material by anyone who conveys the material (or modified versions of
it) with contractual assumptions of liability to the recipient, for
any liability that these contractual assumptions directly impose on
those licensors and authors.
All other non-permissive additional terms are considered "further
restrictions" within the meaning of section 10. If the Program as you
received it, or any part of it, contains a notice stating that it is
governed by this License along with a term that is a further
restriction, you may remove that term. If a license document contains
a further restriction but permits relicensing or conveying under this
License, you may add to a covered work material governed by the terms
of that license document, provided that the further restriction does
not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you
must place, in the relevant source files, a statement of the
additional terms that apply to those files, or a notice indicating
where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the
form of a separately written license, or stated as exceptions;
the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly
provided under this License. Any attempt otherwise to propagate or
modify it is void, and will automatically terminate your rights under
this License (including any patent licenses granted under the third
paragraph of section 11).
However, if you cease all violation of this License, then your
license from a particular copyright holder is reinstated (a)
provisionally, unless and until the copyright holder explicitly and
finally terminates your license, and (b) permanently, if the copyright
holder fails to notify you of the violation by some reasonable means
prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is
reinstated permanently if the copyright holder notifies you of the
violation by some reasonable means, this is the first time you have
received notice of violation of this License (for any work) from that
copyright holder, and you cure the violation prior to 30 days after
your receipt of the notice.
Termination of your rights under this section does not terminate the
licenses of parties who have received copies or rights from you under
this License. If your rights have been terminated and not permanently
reinstated, you do not qualify to receive new licenses for the same
material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or
run a copy of the Program. Ancillary propagation of a covered work
occurring solely as a consequence of using peer-to-peer transmission
to receive a copy likewise does not require acceptance. However,
nothing other than this License grants you permission to propagate or
modify any covered work. These actions infringe copyright if you do
not accept this License. Therefore, by modifying or propagating a
covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically
receives a license from the original licensors, to run, modify and
propagate that work, subject to this License. You are not responsible
for enforcing compliance by third parties with this License.
An "entity transaction" is a transaction transferring control of an
organization, or substantially all assets of one, or subdividing an
organization, or merging organizations. If propagation of a covered
work results from an entity transaction, each party to that
transaction who receives a copy of the work also receives whatever
licenses to the work the party's predecessor in interest had or could
give under the previous paragraph, plus a right to possession of the
Corresponding Source of the work from the predecessor in interest, if
the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the
rights granted or affirmed under this License. For example, you may
not impose a license fee, royalty, or other charge for exercise of
rights granted under this License, and you may not initiate litigation
(including a cross-claim or counterclaim in a lawsuit) alleging that
any patent claim is infringed by making, using, selling, offering for
sale, or importing the Program or any portion of it.
11. Patents.
A "contributor" is a copyright holder who authorizes use under this
License of the Program or a work on which the Program is based. The
work thus licensed is called the contributor's "contributor version".
A contributor's "essential patent claims" are all patent claims
owned or controlled by the contributor, whether already acquired or
hereafter acquired, that would be infringed by some manner, permitted
by this License, of making, using, or selling its contributor version,
but do not include claims that would be infringed only as a
consequence of further modification of the contributor version. For
purposes of this definition, "control" includes the right to grant
patent sublicenses in a manner consistent with the requirements of
this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free
patent license under the contributor's essential patent claims, to
make, use, sell, offer for sale, import and otherwise run, modify and
propagate the contents of its contributor version.
In the following three paragraphs, a "patent license" is any express
agreement or commitment, however denominated, not to enforce a patent
(such as an express permission to practice a patent or covenant not to
sue for patent infringement). To "grant" such a patent license to a
party means to make such an agreement or commitment not to enforce a
patent against the party.
If you convey a covered work, knowingly relying on a patent license,
and the Corresponding Source of the work is not available for anyone
to copy, free of charge and under the terms of this License, through a
publicly available network server or other readily accessible means,
then you must either (1) cause the Corresponding Source to be so
available, or (2) arrange to deprive yourself of the benefit of the
patent license for this particular work, or (3) arrange, in a manner
consistent with the requirements of this License, to extend the patent
license to downstream recipients. "Knowingly relying" means you have
actual knowledge that, but for the patent license, your conveying the
covered work in a country, or your recipient's use of the covered work
in a country, would infringe one or more identifiable patents in that
country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or
arrangement, you convey, or propagate by procuring conveyance of, a
covered work, and grant a patent license to some of the parties
receiving the covered work authorizing them to use, propagate, modify
or convey a specific copy of the covered work, then the patent license
you grant is automatically extended to all recipients of the covered
work and works based on it.
A patent license is "discriminatory" if it does not include within
the scope of its coverage, prohibits the exercise of, or is
conditioned on the non-exercise of one or more of the rights that are
specifically granted under this License. You may not convey a covered
work if you are a party to an arrangement with a third party that is
in the business of distributing software, under which you make payment
to the third party based on the extent of your activity of conveying
the work, and under which the third party grants, to any of the
parties who would receive the covered work from you, a discriminatory
patent license (a) in connection with copies of the covered work
conveyed by you (or copies made from those copies), or (b) primarily
for and in connection with specific products or compilations that
contain the covered work, unless you entered into that arrangement,
or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting
any implied license or other defenses to infringement that may
otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License. If you cannot convey a
covered work so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you may
not convey it at all. For example, if you agree to terms that obligate you
to collect a royalty for further conveying from those to whom you convey
the Program, the only way you could satisfy both those terms and this
License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have
permission to link or combine any covered work with a work licensed
under version 3 of the GNU Affero General Public License into a single
combined work, and to convey the resulting work. The terms of this
License will continue to apply to the part which is the covered work,
but the special requirements of the GNU Affero General Public License,
section 13, concerning interaction through a network will apply to the
combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of
the GNU General Public License from time to time. Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number. If the
Program specifies that a certain numbered version of the GNU General
Public License "or any later version" applies to it, you have the
option of following the terms and conditions either of that numbered
version or of any later version published by the Free Software
Foundation. If the Program does not specify a version number of the
GNU General Public License, you may choose any version ever published
by the Free Software Foundation.
If the Program specifies that a proxy can decide which future
versions of the GNU General Public License can be used, that proxy's
public statement of acceptance of a version permanently authorizes you
to choose that version for the Program.
Later license versions may give you additional or different
permissions. However, no additional obligations are imposed on any
author or copyright holder as a result of your choosing to follow a
later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided
above cannot be given local legal effect according to their terms,
reviewing courts shall apply local law that most closely approximates
an absolute waiver of all civil liability in connection with the
Program, unless a warranty or assumption of liability accompanies a
copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest
to attach them to the start of each source file to most effectively
state the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.
<one line to give the program's name and a brief idea of what it does.>
Copyright (C) <year> <name of author>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short
notice like this when it starts in an interactive mode:
<program> Copyright (C) <year> <name of author>
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it
under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License. Of course, your program's commands
might be different; for a GUI interface, you would use an "about box".
You should also get your employer (if you work as a programmer) or school,
if any, to sign a "copyright disclaimer" for the program, if necessary.
For more information on this, and how to apply and follow the GNU GPL, see
<http://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program
into proprietary programs. If your program is a subroutine library, you
may consider it more useful to permit linking proprietary applications with
the library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License. But first, please read
<http://www.gnu.org/philosophy/why-not-lgpl.html>.

99
README.md Normal file
View File

@ -0,0 +1,99 @@
### Compiling the project
In order to compile this project the following prerequisites must be fulfilled:
- Java Development Kit v1.8 must be installed
(see http://www.oracle.com/technetwork/java/javase/downloads or http://openjdk.java.net/ )
- Apache Maven must be installed (see https://maven.apache.org/, version 3.2.3 was used during development).
The compilation process will not execute the provided test cases by default, nevertheless this behaviour
may be changed but additional prerequisites must be fulfilled first, please refer to the README file located in the test
resources directory (usually `src/test/resources/`).
Afterwards, within the projects top level directory (containing the file `pom.xml`) execute:
```sh
$ mvn clean install
```
This will create the new directory `target`, containing:
- **rubanetra-0.0.6-distribution.zip**
This archive represents the final binary project files, including default configuration files (`./conf/`
and dependencies (`./lib/`).
Use/unpack this archive to install the project on the target machine, however, please refer to the runtime
requirements listed below first. Ultimately, this archive should contain:
- **rubanetra-0.0.6.jar**
The compiled project binary.
- **rubanetra-0.0.6-(test-)sources.jar**
This archive contains the projects (test-)source code, including generated (test-)sources
and default configuration files.
- **rubanetra-0.0.6-javadoc.jar**
This archive contains the projects Java documentation.
- the directory `lib`, which contains all compiled third-party java-dependencies.
- the directory `conf`, which contains modifiable project specific configuration files.
- **rubanetra-0.0.6-package.zip**
This archive contains all sources needed to compile the project from scratch using maven.
It does not contain any binary dependencies.
### Running the project
In order to run this project it must be ensured that
- jNetPcap/libpcap/WinPcap (platform dependent) native libraries are accessible via Java classpath.
- the main configuration file (defaults to `./conf/rubanetra.conf`) is available/accessible and adjusted accordingly.
The path to this file may alternatively be provided via command line argument `-c`).
- the Drools configuration folder (defaults to `./conf/META-INF`) is available/accessible and adjusted accordingly.
Note that for the current version 0.0.6, the actual Drools configuration folder must be
named `META-INF` and contain the file `kmodule.xml`, which represents the Drools knowledge base configuration
and is looked up/compiled by Drools during runtime. This allows to adjust the Knowledge-Base,
i.e. rule modifications/additions/deletions before each invocation without the need to compile a separate JAR.
- the SLF4J-logback logging configuration file (defaults to `./conf/logback.xml`) is available/accessible and
adjusted accordingly.
- the project was successfully compiled and Maven was able to resolve all dependencies.
Additionally, it is recommended to compile the Rubanetra binding for the plaso project (http://plaso.kiddaland.net/) as
well, which is currently available at http://gitlab.swerk.priv.at/stefan/plaso-rubanetra.
For compilation instructions please follow the *Developers Guide* chapter
at https://github.com/log2timeline/plaso/wiki/Developers-Guide.
The frontend main method for the project may then be invoked from the terminal by executing:
```sh
$ java -jar rubanetra-0.0.6.jar
```
To provide the native libraries via `/usr/lib`:
```sh
$ java -cp /usr/lib -jar rubanetra-0.0.6.jar
```
To provide a custom configuration directory (e.g. `/etc/rubanetra/conf`) and
native libraries via `/usr/lib`(substitute `:` with the underlying system path separator):
```sh
$ java -cp "/etc/rubanetra/conf:/usr/lib" -jar rubanetra-0.0.6.jar
```
### Dependencies
This project utilizes jNetPcap (http://jnetpcap.com/) and therefore libpcap/WinPcap as PCAP-library.
Please follow the installation instructions of the jNetPcap-library (project was compiled with version
1.4.r1425-1d), especially the native library section and adjust the Java-Classpath accordingly.
As an alternative, the required native file classpath may be included in the final jar-Archive manifest by adjusting
the projects `pom.xml` property section (i.e. `library.directory` and `native.lib.classpath` properties) first
and recompiling afterwards.
For a list of all utilized (including transitive) third party libraries refer to file `THIRD-PARTY.txt`.
### Bugs
Please report bugs concerning this project to:
http://gitlab.swerk.priv.at/stefan/rubanetra/issues
### Version control / project home
The latest version of this project may be obtained via git:
```sh
$ git clone http://gitlab.swerk.priv.at/stefan/rubanetra.git
```
or by pointing a browser to http://gitlab.swerk.priv.at/stefan/rubanetra.
### Hints
If a runtime exception like the following
> java.lang.UnsatisfiedLinkError: com.slytechs.library.NativeLibrary.dlopen(Ljava/lang/String;)
is encountered, the JNetPcap-library (Java) was unable to locate the native library in the classpath, i.e.
either the JNetPcap native binding or libpcap is missing (see above).
Special note for Ubuntu 12.04/14.04: The package `libpcap-dev` must be installed.

97
README.txt Normal file
View File

@ -0,0 +1,97 @@
###########################
# Compiling the project #
###########################
In order to compile this project the following prerequisites must be fulfilled:
- Java Development Kit v1.8 must be installed
(see http://www.oracle.com/technetwork/java/javase/downloads or http://openjdk.java.net/ )
- Apache Maven must be installed (see https://maven.apache.org/, version 3.2.3 was used during development).
The compilation process will not execute the provided test cases by default, nevertheless this behaviour
may be changed but additional prerequisites must be fulfilled first, please refer to the README file located in the test
resources directory (usually 'src/test/resources/').
Afterwards, within the projects top level directory (containing the file 'pom.xml') execute:
$ mvn clean install
This will create the new directory 'target', containing:
- "rubanetra-0.0.6-distribution.zip"
This archive represents the final binary project files, including default configuration files ('./conf/'
and dependencies ('./lib/').
Use/unpack this archive to install the project on the target machine, however, please refer to the runtime
requirements listed below first. Ultimately, this archive should contain:
* "rubanetra-0.0.6.jar"
The compiled project binary.
* "rubanetra-0.0.6-(test-)sources.jar"
This archive contains the projects (test-)source code, including generated (test-)sources
and default configuration files.
* "rubanetra-0.0.6-javadoc.jar"
This archive contains the projects Java documentation.
* the directory 'lib', which contains all compiled third-party java-dependencies.
* the directory 'conf', which contains modifiable project specific configuration files.
- "rubanetra-0.0.6-package.zip"
This archive contains all sources needed to compile the project from scratch using maven.
It does not contain any binary dependencies.
#######################
# Running the project #
#######################
In order to run this project it must be ensured that
- jNetPcap/libpcap/WinPcap (platform dependent) native libraries are accessible via Java classpath.
- the main configuration file (defaults to './conf/rubanetra.conf') is available/accessible and adjusted accordingly.
The path to this file may alternatively be provided via command line argument '-c').
- the Drools configuration folder (defaults to './conf/META-INF') is available/accessible and adjusted accordingly.
Note that for the current version 0.0.6, the actual Drools configuration folder must be
named 'META-INF' and contain the file 'kmodule.xml', which represents the Drools knowledge base configuration
and is looked up/compiled by Drools during runtime. This allows to adjust the Knowledge-Base,
i.e. rule modifications/additions/deletions before each invocation without the need to compile a separate JAR.
- the SLF4J-logback logging configuration file (defaults to './conf/logback.xml') is available/accessible and
adjusted accordingly.
- the project was successfully compiled and Maven was able to resolve all dependencies.
Additionally, it is recommended to compile the Rubanetra binding for the plaso project (http://plaso.kiddaland.net/) as
well, which is currently available at http://gitlab.swerk.priv.at/stefan/plaso-rubanetra.
For compilation instructions please follow the "Developers Guide - How to build plaso from scratch" chapter
at https://github.com/log2timeline/plaso/wiki/Developers-Guide.
The frontend main method for the project may then be invoked from the terminal by executing:
$ java -jar rubanetra-0.0.6.jar
To provide the native libraries via '/usr/lib':
$ java -cp /usr/lib -jar rubanetra-0.0.6.jar
To provide a custom configuration directory (e.g. '/etc/rubanetra/conf') and
native libraries via '/usr/lib'(substitute ':' with the underlying system path separator):
$ java -cp "/etc/rubanetra/conf:/usr/lib" -jar rubanetra-0.0.6.jar
################
# Dependencies #
################
This project utilizes jNetPcap (http://jnetpcap.com/) and therefore libpcap/WinPcap as PCAP-library.
Please follow the installation instructions of the jNetPcap-library (project was compiled with version 1.4.r1425-1d),
especially the native library section and adjust the Java-Classpath accordingly.
As an alternative the required native file classpath may be included in the final jar-Archive manifest by adjusting
the projects 'pom.xml' property section (i.e. 'library.directory' and 'native.lib.classpath' properties) first
and recompiling afterwards.
For a list of all utilized (including transitive) third party libraries refer to file 'THIRD-PARTY.txt'.
########
# Bugs #
########
Please report bugs concerning this project to:
http://gitlab.swerk.priv.at/stefan/rubanetra/issues
##################################
# Version control / project home #
##################################
The latest version of this project may be obtained via git:
git clone http://gitlab.swerk.priv.at/stefan/rubanetra.git
or by pointing a browser to:
http://gitlab.swerk.priv.at/stefan/rubanetra
#########
# Hints #
#########
If a runtime exception like the following
java.lang.UnsatisfiedLinkError: com.slytechs.library.NativeLibrary.dlopen(Ljava/lang/String;)
is encountered, the JNetPcap-library (Java) was unable to locate the native library in the classpath, i.e.
either the JNetPcap native binding or libpcap is missing (see above).
Special note for Ubuntu 12.04: The package 'libpcap-dev' must be installed.

51
THIRD-PARTY.txt Normal file
View File

@ -0,0 +1,51 @@
Lists of 49 third-party dependencies.
(Eclipse Public License - v 1.0) (GNU Lesser General Public License) Logback Classic Module (ch.qos.logback:logback-classic:1.1.1 - http://logback.qos.ch)
(Eclipse Public License - v 1.0) (GNU Lesser General Public License) Logback Core Module (ch.qos.logback:logback-core:1.1.1 - http://logback.qos.ch)
(The Apache Software License, Version 2.0) Jackson-annotations (com.fasterxml.jackson.core:jackson-annotations:2.5.0 - http://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) Jackson-core (com.fasterxml.jackson.core:jackson-core:2.5.3 - https://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) jackson-databind (com.fasterxml.jackson.core:jackson-databind:2.5.3 - http://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) Jackson-dataformat-XML (com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.5.3 - http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding)
(The Apache Software License, Version 2.0) Jackson-module-JAXB-annotations (com.fasterxml.jackson.module:jackson-module-jaxb-annotations:2.5.3 - http://wiki.fasterxml.com/JacksonJAXBAnnotations)
(New BSD license) Protocol Buffer Java API (com.google.protobuf:protobuf-java:2.5.0 - http://code.google.com/p/protobuf)
(BSD style) XStream Core (com.thoughtworks.xstream:xstream:1.4.7 - http://codehaus.org/xstream-parent/xstream/)
(The Apache Software License, Version 2.0) Commons CLI (commons-cli:commons-cli:1.2 - http://commons.apache.org/cli/)
(The Apache Software License, Version 2.0) Commons Codec (commons-codec:commons-codec:1.6 - http://commons.apache.org/codec/)
(The Apache Software License, Version 2.0) Commons Logging (commons-logging:commons-logging:1.1.3 - http://commons.apache.org/proper/commons-logging/)
(BSD 2-Clause license) dnsjava (dnsjava:dnsjava:2.1.7 - http://www.dnsjava.org)
(CDDL) (GPLv2+CE) JavaMail API (compat) (javax.mail:mail:1.4.7 - http://kenai.com/projects/javamail/mail)
(COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0) (GNU General Public Library) Streaming API for XML (javax.xml.stream:stax-api:1.0-2 - no url defined)
(GNU Lesser General Public License (LGPL) Version 3) jnetpcap (jnetpcap:jnetpcap:1.4.r1425-1d - no url defined)
(Common Public License Version 1.0) JUnit (junit:junit:4.11 - http://junit.org)
(BSD 3-Clause "New" or "Revised" License (BSD-3-Clause)) abego TreeLayout Core (org.abego.treelayout:org.abego.treelayout.core:1.0.1 - http://code.google.com/p/treelayout/)
(BSD licence) ANTLR 3 Runtime (org.antlr:antlr-runtime:3.5 - http://www.antlr.org)
(BSD 3-Clause License) ANTLR 4 Runtime (org.antlr:antlr4-runtime:4.5 - http://www.antlr.org)
(The Apache Software License, Version 2.0) Apache Commons CSV (org.apache.commons:commons-csv:1.0 - http://commons.apache.org/proper/commons-csv/)
(Apache License, Version 2.0) Apache HttpClient (org.apache.httpcomponents:httpclient:4.3.3 - http://hc.apache.org/httpcomponents-client)
(Apache License, Version 2.0) Apache HttpCore (org.apache.httpcomponents:httpcore:4.3.2 - http://hc.apache.org/httpcomponents-core-ga)
(The BSD License) Stax2 API (org.codehaus.woodstox:stax2-api:3.1.4 - http://wiki.fasterxml.com/WoodstoxStax2)
(The Apache Software License, Version 2.0) Woodstox (org.codehaus.woodstox:woodstox-core-asl:4.3.0 - http://woodstox.codehaus.org)
(The Apache Software License, Version 2.0) Drools :: Compiler (org.drools:drools-compiler:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/drools-multiproject/drools-compiler)
(The Apache Software License, Version 2.0) Drools :: Core (org.drools:drools-core:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/drools-multiproject/drools-core)
(Eclipse Public License v1.0) Eclipse ECJ (org.eclipse.jdt.core.compiler:ecj:4.3.1 - http://www.eclipse.org/jdt/)
(New BSD License) Hamcrest Core (org.hamcrest:hamcrest-core:1.3 - https://github.com/hamcrest/JavaHamcrest/hamcrest-core)
(The Apache Software License, Version 2.0) KIE API (org.kie:kie-api:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/kie-api-parent/kie-api)
(The Apache Software License, Version 2.0) KIE Internal (org.kie:kie-internal:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/kie-api-parent/kie-internal)
(Apache Software License 2) Kraken API (org.krakenapps:kraken-api:2.1.1 - http://maven.apache.org)
(Apache Software License 2) Kraken DHCP Decoder (org.krakenapps:kraken-dhcp-decoder:1.0.1 - http://krakenapps.org/kraken-pcap-pom/kraken-dhcp-decoder)
(Apache Software License 2) Kraken FTP Decoder (org.krakenapps:kraken-ftp-decoder:1.2.0 - http://krakenapps.org/kraken-pcap-pom/kraken-ftp-decoder)
(Apache Software License 2) Kraken HTTP Decoder (org.krakenapps:kraken-http-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-http-decoder)
(Apache Software License 2) Kraken JSON (org.krakenapps:kraken-json:1.1.1 - http://krakenapps.org/kraken-format-pom/kraken-json)
(Apache Software License 2) Kraken Mime (org.krakenapps:kraken-mime:1.0.0 - http://krakenapps.org/kraken-format-pom/kraken-mime)
(Apache Software License 2) Kraken MSN Decoder (org.krakenapps:kraken-msn-decoder:1.2.0 - http://krakenapps.org/kraken-pcap-pom/kraken-msn-decoder)
(Apache Software License 2) Kraken Netbios Decoder (org.krakenapps:kraken-netbios-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-netbios-decoder)
(Apache Software License 2) Kraken PCAP (org.krakenapps:kraken-pcap:1.7.1 - http://krakenapps.org/kraken-pcap-pom/kraken-pcap)
(Apache Software License 2) Kraken POP3 Decoder (org.krakenapps:kraken-pop3-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-pop3-decoder)
(Apache Software License 2) Kraken SMTP Decoder (org.krakenapps:kraken-smtp-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-smtp-decoder)
(Apache Software License 2) Kraken SNMP Decoder (org.krakenapps:kraken-snmp-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-snmp-decoder)
(Apache Software License 2) Kraken Telnet Decoder (org.krakenapps:kraken-telnet-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-telnet-decoder)
(The Apache Software License, Version 2.0) mvel (org.mvel:mvel2:2.2.1.Final - http://mvel.codehaus.org/)
(MIT License) JCL 1.1.1 implemented over SLF4J (org.slf4j:jcl-over-slf4j:1.7.6 - http://www.slf4j.org)
(MIT License) SLF4J API Module (org.slf4j:slf4j-api:1.7.6 - http://www.slf4j.org)
(Public Domain) XML Pull Parsing API (xmlpull:xmlpull:1.1.3.1 - http://www.xmlpull.org)
(Indiana University Extreme! Lab Software License, vesion 1.1.1) (Public Domain) MXP1: Xml Pull Parser 3rd Edition (XPP3) (xpp3:xpp3_min:1.1.4c - http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/)

748
pom.xml Normal file
View File

@ -0,0 +1,748 @@
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns="http://maven.apache.org/POM/4.0.0"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>at.jku.fim</groupId>
<artifactId>rubanetra</artifactId>
<version>0.0.6</version>
<name>Rubanetra</name>
<inceptionYear>2013</inceptionYear>
<licenses>
<license>
<name>GNU General Public License, Version 3</name>
<url>https://gnu.org/licenses/gpl-3.0.txt</url>
<distribution>repo</distribution>
</license>
</licenses>
<organization>
<name>Institute of networks and security</name>
<url>https://ins.jku.at</url>
</organization>
<developers>
<developer>
<id>stefan</id>
<name>Stefan Swerk</name>
<email>stefan_rubanetra@swerk.priv.at</email>
<roles>
<role>developer</role>
</roles>
<timezone>+1</timezone>
</developer>
</developers>
<scm>
<connection>scm:git:http://gitlab.swerk.priv.at/stefan/rubanetra.git</connection>
<url>http://gitlab.swerk.priv.at/stefan/rubanetra</url>
</scm>
<issueManagement>
<system>Gitlab</system>
<url>http://gitlab.swerk.priv.at/stefan/rubanetra/issues</url>
</issueManagement>
<properties>
<!-- the default settings to use in the final configuration files -->
<droolsKnowledgeBase>DefaultKnowledgeBase</droolsKnowledgeBase>
<droolsSessionName>DefaultSession</droolsSessionName>
<fnaInputFormat>pcap</fnaInputFormat>
<fnaOutputFile>stdout</fnaOutputFile>
<fnaOutputFormat>plaso</fnaOutputFormat>
<logLevel>info</logLevel>
<logDirectory>./logs</logDirectory>
<library.directory>./lib</library.directory>
<config.directory>./conf</config.directory>
<native.lib.classpath>/usr/lib</native.lib.classpath>
<!-- general settings -->
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
<antlr4.visitor>false</antlr4.visitor>
<antlr4.listener>true</antlr4.listener>
<archive.output.directory>${project.build.directory}/archive</archive.output.directory>
<recentYears>2014</recentYears>
<!-- main library versions to use -->
<jnetpcap.version>1.4.r1425-1d</jnetpcap.version>
<jnetpcap.native.lib.dirname>libjnetpcap</jnetpcap.native.lib.dirname>
<krakenpcap.version>1.7.1</krakenpcap.version>
<antlr.version>4.5</antlr.version>
<drools.version>6.1.0.Final</drools.version>
<apachehttpclient.version>4.3.3</apachehttpclient.version>
<dnsjava.version>2.1.7</dnsjava.version>
<junit.version>4.11</junit.version>
<jackson.version>2.5.3</jackson.version>
<slf4j.version>1.7.6</slf4j.version>
</properties>
<repositories>
<!--This repository contains the required Kraken Pcap modules, it may be disabled as soon as the
actual krakenapps.org repository (see below) is up again.-->
<repository>
<id>OpenSOC-Kraken-Repo</id>
<name>OpenSOC Kraken Repository</name>
<url>https://raw.github.com/opensoc/kraken/mvn-repo</url>
</repository>
<!--The following repository is currently down (03.2015), it should be enabled if possible.-->
<!--<repository>-->
<!--<id>krakenapps.org</id>-->
<!--<name>Kraken Repository</name>-->
<!--<url>http://download.krakenapps.org/</url>-->
<!--</repository>-->
<!--The following repository serves as workaround for the missing kraken-pcap-pom dependency problem,
See also https://github.com/nchovy/kraken/issues/4 .
In case the repository location as specified below does not exist, delete the following repository entry,
acquire the kraken-pcap-pom file and execute
$ mvn install:install-file -DlocalRepositoryPath=kraken-workaround-repository \
-DcreateChecksum=true -Dpackaging=pom -Dfile=<PATH-TO_KRAKEN-PCAP-POM.pom> \
-DgroupId=org.krakenapps -DartifactId=kraken-pcap-pom -Dversion=1.0.0
As soon as the underlying issue is resolved upstream, this repository entry may be deleted.-->
<repository>
<id>krakenapps.org - workaround</id>
<releases>
<enabled>true</enabled>
<checksumPolicy>ignore</checksumPolicy>
</releases>
<snapshots>
<enabled>false</enabled>
</snapshots>
<url>file://${project.basedir}/src/main/resources/kraken-workaround-repository</url>
</repository>
<repository>
<id>jboss-public-repository-group</id>
<name>JBoss Public Maven Repository Group</name>
<url>http://repository.jboss.org/nexus/content/groups/public/</url>
<layout>default</layout>
<releases>
<enabled>true</enabled>
<updatePolicy>always</updatePolicy>
</releases>
<snapshots>
<enabled>true</enabled>
<updatePolicy>always</updatePolicy>
</snapshots>
</repository>
<repository>
<id>central</id>
<name>Central Maven Repository</name>
<layout>default</layout>
<url>http://repo1.maven.org/maven2</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</repository>
<repository>
<id>clojars.org</id>
<name>Clojars Community Maven Repository</name>
<url>http://clojars.org/repo</url>
</repository>
</repositories>
<pluginRepositories>
<pluginRepository>
<id>jboss-public-repository-group</id>
<name>JBoss Public Maven Repository Group</name>
<url>http://repository.jboss.org/nexus/content/groups/public/</url>
<layout>default</layout>
</pluginRepository>
<pluginRepository>
<id>central</id>
<name>Central Maven Repository</name>
<layout>default</layout>
<url>http://repo1.maven.org/maven2</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</pluginRepository>
</pluginRepositories>
<dependencies>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>${junit.version}</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>slf4j-api</artifactId>
<version>${slf4j.version}</version>
</dependency>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>jcl-over-slf4j</artifactId>
<version>${slf4j.version}</version>
</dependency>
<dependency>
<groupId>ch.qos.logback</groupId>
<artifactId>logback-classic</artifactId>
<version>1.1.1</version>
</dependency>
<dependency>
<groupId>commons-logging</groupId>
<artifactId>commons-logging</artifactId>
<version>1.1.3</version>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>${jackson.version}</version>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.dataformat</groupId>
<artifactId>jackson-dataformat-xml</artifactId>
<version>${jackson.version}</version>
</dependency>
<dependency>
<groupId>org.codehaus.woodstox</groupId>
<artifactId>woodstox-core-asl</artifactId>
<version>4.3.0</version>
</dependency>
<dependency>
<groupId>javax.mail</groupId>
<artifactId>mail</artifactId>
<version>1.4.7</version>
<exclusions>
<exclusion>
<artifactId>activation</artifactId>
<groupId>javax.activation</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-pcap</artifactId>
<version>${krakenpcap.version}</version>
<exclusions>
<exclusion>
<artifactId>slf4j-simple</artifactId>
<groupId>org.slf4j</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-http-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-smtp-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>activation</artifactId>
<groupId>javax.activation</groupId>
</exclusion>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-ftp-decoder</artifactId>
<version>1.2.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-msn-decoder</artifactId>
<version>1.2.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-netbios-decoder</artifactId>
<version>1.0.0</version>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-pop3-decoder</artifactId>
<version>1.0.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-dhcp-decoder</artifactId>
<version>1.0.1</version>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-snmp-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-telnet-decoder</artifactId>
<version>1.0.0</version>
</dependency>
<dependency>
<groupId>jnetpcap</groupId>
<artifactId>jnetpcap</artifactId>
<version>${jnetpcap.version}</version>
</dependency>
<dependency>
<groupId>org.antlr</groupId>
<artifactId>antlr4-runtime</artifactId>
<version>${antlr.version}</version>
</dependency>
<dependency>
<groupId>org.drools</groupId>
<artifactId>drools-core</artifactId>
<version>${drools.version}</version>
</dependency>
<dependency>
<groupId>org.drools</groupId>
<artifactId>drools-compiler</artifactId>
<version>${drools.version}</version>
</dependency>
<dependency>
<groupId>org.kie</groupId>
<artifactId>kie-api</artifactId>
<version>${drools.version}</version>
</dependency>
<dependency>
<groupId>org.apache.httpcomponents</groupId>
<artifactId>httpclient</artifactId>
<version>${apachehttpclient.version}</version>
</dependency>
<dependency>
<groupId>commons-cli</groupId>
<artifactId>commons-cli</artifactId>
<version>1.2</version>
</dependency>
<dependency>
<groupId>org.apache.commons</groupId>
<artifactId>commons-csv</artifactId>
<version>1.0</version>
</dependency>
<dependency>
<groupId>dnsjava</groupId>
<artifactId>dnsjava</artifactId>
<version>${dnsjava.version}</version>
</dependency>
</dependencies>
<build>
<resources>
<resource>
<directory>src/main/resources</directory>
<filtering>true</filtering>
</resource>
</resources>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<version>3.1</version>
<configuration>
<source>1.8</source>
<target>1.8</target>
<showWarnings>true</showWarnings>
<showDeprecation>true</showDeprecation>
<compilerArgument>-proc:none</compilerArgument>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-javadoc-plugin</artifactId>
<version>2.9.1</version>
<configuration>
<quiet>false</quiet>
<jarOutputDirectory>${archive.output.directory}</jarOutputDirectory>
<additionalparam>-Xdoclint:none</additionalparam>
</configuration>
<executions>
<execution>
<id>attach-javadocs</id>
<phase>prepare-package</phase>
<goals>
<goal>jar</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-surefire-plugin</artifactId>
<version>2.16</version>
<configuration>
<skip>true</skip>
<systemPropertyVariables>
<logDirectory>${project.build.directory}/logs</logDirectory>
<logLevel>DEBUG</logLevel>
</systemPropertyVariables>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-assembly-plugin</artifactId>
<version>2.4</version>
<executions>
<execution>
<phase>package</phase>
<goals>
<goal>single</goal>
</goals>
</execution>
</executions>
<configuration>
<descriptors>
<descriptor>src/main/assembly/distribution-zip.xml</descriptor>
<descriptor>src/main/assembly/package-zip.xml</descriptor>
</descriptors>
<tarLongFileMode>gnu</tarLongFileMode>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-jar-plugin</artifactId>
<version>2.4</version>
<configuration>
<outputDirectory>${archive.output.directory}</outputDirectory>
<archive>
<manifest>
<addClasspath>true</addClasspath>
<!-- Workaround for Maven bug #MJAR-156 (https://jira.codehaus.org/browse/MJAR-156) -->
<useUniqueVersions>false</useUniqueVersions>
<classpathPrefix>${library.directory}/</classpathPrefix>
<addExtensions>false</addExtensions>
<mainClass>at.jku.fim.rubanetra.config.ConfigurationController</mainClass>
<addDefaultImplementationEntries>true</addDefaultImplementationEntries>
</manifest>
<manifestEntries>
<Class-Path>${config.directory}/ ${native.lib.classpath}/</Class-Path>
<Build-Java>${java.version}</Build-Java>
<Build-OS>${os.name}</Build-OS>
<Build-Arch>${os.arch}</Build-Arch>
<License-Short-Name>GPLv3</License-Short-Name>
<License-Long-Name>GNU General Public License, Version 3</License-Long-Name>
<License-Url>https://gnu.org/licenses/gpl-3.0.txt</License-Url>
<License-Short-Header>This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
</License-Short-Header>
<License-Inception-Year>${project.inceptionYear}</License-Inception-Year>
<License-Recent-Years>${recentYears}</License-Recent-Years>
<Copyright-Owner>Stefan Swerk (stefan_rubanetra@swerk.priv.at)</Copyright-Owner>
<Issue-Management>${project.issueManagement.url}</Issue-Management>
<Project-Home>${project.scm.url}</Project-Home>
</manifestEntries>
</archive>
<excludes>
<exclude>**/*.properties</exclude>
<exclude>**/*.drl</exclude>
<exclude>**/*.xml</exclude>
<exclude>**/*.conf</exclude>
<exclude>kraken-workaround-repository/**</exclude>
<exclude>${droolsKnowledgeBase}/**</exclude>
</excludes>
</configuration>
<executions>
<execution>
<phase>prepare-package</phase>
<goals>
<goal>jar</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-source-plugin</artifactId>
<version>2.2.1</version>
<configuration>
<includePom>true</includePom>
<outputDirectory>${archive.output.directory}</outputDirectory>
</configuration>
<executions>
<execution>
<id>attach-sources</id>
<phase>prepare-package</phase>
<goals>
<goal>jar-no-fork</goal>
</goals>
</execution>
<execution>
<id>attach-test-sources</id>
<phase>prepare-package</phase>
<goals>
<goal>test-jar-no-fork</goal>
</goals>
<configuration>
<excludes>
<exclude>**/captures/**</exclude>
</excludes>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>build-helper-maven-plugin</artifactId>
<version>1.8</version>
<executions>
<execution>
<phase>generate-sources</phase>
<goals>
<goal>add-source</goal>
</goals>
<configuration>
<sources>
<source>${project.build.directory}/generated-sources/antlr4</source>
</sources>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.antlr</groupId>
<artifactId>antlr4-maven-plugin</artifactId>
<version>${antlr.version}</version>
<executions>
<execution>
<id>antlr</id>
<phase>generate-sources</phase>
<goals>
<goal>antlr4</goal>
</goals>
<configuration>
<!-- This options is currently not required, since this plugin looks for ANTLR grammars
in the directory 'main/antlr4' anyway-->
<!--<sourceDirectory>${basedir}/src/main/java</sourceDirectory> -->
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.kie</groupId>
<artifactId>kie-maven-plugin</artifactId>
<version>${drools.version}</version>
<extensions>true</extensions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-dependency-plugin</artifactId>
<version>2.8</version>
<executions>
<execution>
<id>copy-dependencies</id>
<phase>prepare-package</phase>
<goals>
<goal>copy-dependencies</goal>
</goals>
<configuration>
<outputDirectory>${project.build.directory}/lib</outputDirectory>
<overWriteReleases>false</overWriteReleases>
<overWriteSnapshots>false</overWriteSnapshots>
<overWriteIfNewer>true</overWriteIfNewer>
<useBaseVersion>true</useBaseVersion>
</configuration>
</execution>
<execution>
<id>unpack</id>
<phase>compile</phase>
<goals>
<goal>unpack</goal>
</goals>
<configuration>
<artifactItems>
<artifactItem>
<groupId>jnetpcap</groupId>
<artifactId>jnetpcap</artifactId>
<version>${jnetpcap.version}</version>
<type>jar</type>
<overWrite>false</overWrite>
<outputDirectory>${project.build.directory}/lib/${jnetpcap.native.lib.dirname}
</outputDirectory>
</artifactItem>
</artifactItems>
<includes>native/**</includes>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>license-maven-plugin</artifactId>
<version>1.6</version>
<configuration>
<licenseName>gpl_v3</licenseName>
<copyrightOwners>Stefan Swerk (stefan_rubanetra@swerk.priv.at)</copyrightOwners>
<useMissingFile>true</useMissingFile>
<useRepositoryMissingFiles>true</useRepositoryMissingFiles>
<licenseMerges>
<licenseMerge>The Apache Software License, Version 2.0|Apache 2</licenseMerge>
<licenseMerge>The Apache Software License, Version 2.0|Apache
License
</licenseMerge>
<licenseMerge>The Apache Software License, Version 2.0|Apache
License, Version 2.0
</licenseMerge>
</licenseMerges>
</configuration>
<executions>
<execution>
<id>add-third-party</id>
<goals>
<goal>add-third-party</goal>
</goals>
<phase>process-sources</phase>
</execution>
<!--<execution>-->
<!--<id>download-licenses</id>-->
<!--<goals>-->
<!--<goal>download-licenses</goal>-->
<!--</goals>-->
<!--<phase>process-sources</phase>-->
<!--</execution>-->
<execution>
<id>update-project-license</id>
<goals>
<goal>update-project-license</goal>
</goals>
<phase>process-sources</phase>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-install-plugin</artifactId>
<version>2.5.1</version>
<configuration>
<createChecksum>true</createChecksum>
</configuration>
</plugin>
<plugin>
<groupId>net.ju-n.maven.plugins</groupId>
<artifactId>checksum-maven-plugin</artifactId>
<version>1.2</version>
<executions>
<execution>
<goals>
<goal>artifacts</goal>
</goals>
</execution>
</executions>
<configuration>
<algorithms>
<algorithm>MD5</algorithm>
<algorithm>SHA-1</algorithm>
<algorithm>SHA-256</algorithm>
</algorithms>
</configuration>
</plugin>
<plugin>
<groupId>com.mycila</groupId>
<artifactId>license-maven-plugin</artifactId>
<version>2.6</version>
<configuration>
<header>src/license/gpl_v3/header.txt</header>
<properties>
<owner>Stefan Swerk</owner>
<year>${project.inceptionYear}</year>
<recentYears>${recentYears}</recentYears>
<currentYear>${maven.build.timestamp}</currentYear>
<email>stefan_rubanetra@swerk.priv.at</email>
</properties>
<useDefaultExcludes>true</useDefaultExcludes>
<mapping>
<drl>JAVADOC_STYLE</drl>
<g4>JAVADOC_STYLE</g4>
<conf>JAVADOC_STYLE</conf>
</mapping>
</configuration>
<executions>
<execution>
<id>license-basedir</id>
<phase>process-sources</phase>
<goals>
<goal>format</goal>
</goals>
<configuration>
<basedir>${project.basedir}</basedir>
<excludes>
<exclude>**/README*</exclude>
<exclude>**/LICENSE*</exclude>
<exclude>src/license/gpl_v3/**</exclude>
<exclude>src/main/resources/kraken-workaround-repository/**</exclude>
<exclude>src/test/resources/captures/**</exclude>
</excludes>
<includes>
<include>pom.xml</include>
<include>src/**</include>
</includes>
</configuration>
</execution>
<execution>
<id>license-gen-src</id>
<phase>process-sources</phase>
<goals>
<goal>format</goal>
</goals>
<configuration>
<basedir>${project.build.directory}/generated-sources/antlr4</basedir>
<excludes>
<exclude>**/README*</exclude>
<exclude>**/LICENSE*</exclude>
<exclude>**/*.tokens</exclude>
</excludes>
</configuration>
</execution>
</executions>
</plugin>
</plugins>
</build>
</project>

View File

@ -0,0 +1,674 @@
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this, the GPL assures that
patents cannot be used to render the program non-free.
The precise terms and conditions for copying, distribution and
modification follow.
TERMS AND CONDITIONS
0. Definitions.
"This License" refers to version 3 of the GNU General Public License.
"Copyright" also means copyright-like laws that apply to other kinds of
works, such as semiconductor masks.
"The Program" refers to any copyrightable work licensed under this
License. Each licensee is addressed as "you". "Licensees" and
"recipients" may be individuals or organizations.
To "modify" a work means to copy from or adapt all or part of the work
in a fashion requiring copyright permission, other than the making of an
exact copy. The resulting work is called a "modified version" of the
earlier work or a work "based on" the earlier work.
A "covered work" means either the unmodified Program or a work based
on the Program.
To "propagate" a work means to do anything with it that, without
permission, would make you directly or secondarily liable for
infringement under applicable copyright law, except executing it on a
computer or modifying a private copy. Propagation includes copying,
distribution (with or without modification), making available to the
public, and in some countries other activities as well.
To "convey" a work means any kind of propagation that enables other
parties to make or receive copies. Mere interaction with a user through
a computer network, with no transfer of a copy, is not conveying.
An interactive user interface displays "Appropriate Legal Notices"
to the extent that it includes a convenient and prominently visible
feature that (1) displays an appropriate copyright notice, and (2)
tells the user that there is no warranty for the work (except to the
extent that warranties are provided), that licensees may convey the
work under this License, and how to view a copy of this License. If
the interface presents a list of user commands or options, such as a
menu, a prominent item in the list meets this criterion.
1. Source Code.
The "source code" for a work means the preferred form of the work
for making modifications to it. "Object code" means any non-source
form of a work.
A "Standard Interface" means an interface that either is an official
standard defined by a recognized standards body, or, in the case of
interfaces specified for a particular programming language, one that
is widely used among developers working in that language.
The "System Libraries" of an executable work include anything, other
than the work as a whole, that (a) is included in the normal form of
packaging a Major Component, but which is not part of that Major
Component, and (b) serves only to enable use of the work with that
Major Component, or to implement a Standard Interface for which an
implementation is available to the public in source code form. A
"Major Component", in this context, means a major essential component
(kernel, window system, and so on) of the specific operating system
(if any) on which the executable work runs, or a compiler used to
produce the work, or an object code interpreter used to run it.
The "Corresponding Source" for a work in object code form means all
the source code needed to generate, install, and (for an executable
work) run the object code and to modify the work, including scripts to
control those activities. However, it does not include the work's
System Libraries, or general-purpose tools or generally available free
programs which are used unmodified in performing those activities but
which are not part of the work. For example, Corresponding Source
includes interface definition files associated with source files for
the work, and the source code for shared libraries and dynamically
linked subprograms that the work is specifically designed to require,
such as by intimate data communication or control flow between those
subprograms and other parts of the work.
The Corresponding Source need not include anything that users
can regenerate automatically from other parts of the Corresponding
Source.
The Corresponding Source for a work in source code form is that
same work.
2. Basic Permissions.
All rights granted under this License are granted for the term of
copyright on the Program, and are irrevocable provided the stated
conditions are met. This License explicitly affirms your unlimited
permission to run the unmodified Program. The output from running a
covered work is covered by this License only if the output, given its
content, constitutes a covered work. This License acknowledges your
rights of fair use or other equivalent, as provided by copyright law.
You may make, run and propagate covered works that you do not
convey, without conditions so long as your license otherwise remains
in force. You may convey covered works to others for the sole purpose
of having them make modifications exclusively for you, or provide you
with facilities for running those works, provided that you comply with
the terms of this License in conveying all material for which you do
not control copyright. Those thus making or running the covered works
for you must do so exclusively on your behalf, under your direction
and control, on terms that prohibit them from making any copies of
your copyrighted material outside their relationship with you.
Conveying under any other circumstances is permitted solely under
the conditions stated below. Sublicensing is not allowed; section 10
makes it unnecessary.
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
No covered work shall be deemed part of an effective technological
measure under any applicable law fulfilling obligations under article
11 of the WIPO copyright treaty adopted on 20 December 1996, or
similar laws prohibiting or restricting circumvention of such
measures.
When you convey a covered work, you waive any legal power to forbid
circumvention of technological measures to the extent such circumvention
is effected by exercising rights under this License with respect to
the covered work, and you disclaim any intention to limit operation or
modification of the work as a means of enforcing, against the work's
users, your or third parties' legal rights to forbid circumvention of
technological measures.
4. Conveying Verbatim Copies.
You may convey verbatim copies of the Program's source code as you
receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice;
keep intact all notices stating that this License and any
non-permissive terms added in accord with section 7 apply to the code;
keep intact all notices of the absence of any warranty; and give all
recipients a copy of this License along with the Program.
You may charge any price or no price for each copy that you convey,
and you may offer support or warranty protection for a fee.
5. Conveying Modified Source Versions.
You may convey a work based on the Program, or the modifications to
produce it from the Program, in the form of source code under the
terms of section 4, provided that you also meet all of these conditions:
a) The work must carry prominent notices stating that you modified
it, and giving a relevant date.
b) The work must carry prominent notices stating that it is
released under this License and any conditions added under section
7. This requirement modifies the requirement in section 4 to
"keep intact all notices".
c) You must license the entire work, as a whole, under this
License to anyone who comes into possession of a copy. This
License will therefore apply, along with any applicable section 7
additional terms, to the whole of the work, and all its parts,
regardless of how they are packaged. This License gives no
permission to license the work in any other way, but it does not
invalidate such permission if you have separately received it.
d) If the work has interactive user interfaces, each must display
Appropriate Legal Notices; however, if the Program has interactive
interfaces that do not display Appropriate Legal Notices, your
work need not make them do so.
A compilation of a covered work with other separate and independent
works, which are not by their nature extensions of the covered work,
and which are not combined with it such as to form a larger program,
in or on a volume of a storage or distribution medium, is called an
"aggregate" if the compilation and its resulting copyright are not
used to limit the access or legal rights of the compilation's users
beyond what the individual works permit. Inclusion of a covered work
in an aggregate does not cause this License to apply to the other
parts of the aggregate.
6. Conveying Non-Source Forms.
You may convey a covered work in object code form under the terms
of sections 4 and 5, provided that you also convey the
machine-readable Corresponding Source under the terms of this License,
in one of these ways:
a) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by the
Corresponding Source fixed on a durable physical medium
customarily used for software interchange.
b) Convey the object code in, or embodied in, a physical product
(including a physical distribution medium), accompanied by a
written offer, valid for at least three years and valid for as
long as you offer spare parts or customer support for that product
model, to give anyone who possesses the object code either (1) a
copy of the Corresponding Source for all the software in the
product that is covered by this License, on a durable physical
medium customarily used for software interchange, for a price no
more than your reasonable cost of physically performing this
conveying of source, or (2) access to copy the
Corresponding Source from a network server at no charge.
c) Convey individual copies of the object code with a copy of the
written offer to provide the Corresponding Source. This
alternative is allowed only occasionally and noncommercially, and
only if you received the object code with such an offer, in accord
with subsection 6b.
d) Convey the object code by offering access from a designated
place (gratis or for a charge), and offer equivalent access to the
Corresponding Source in the same way through the same place at no
further charge. You need not require recipients to copy the
Corresponding Source along with the object code. If the place to
copy the object code is a network server, the Corresponding Source
may be on a different server (operated by you or a third party)
that supports equivalent copying facilities, provided you maintain
clear directions next to the object code saying where to find the
Corresponding Source. Regardless of what server hosts the
Corresponding Source, you remain obligated to ensure that it is
available for as long as needed to satisfy these requirements.
e) Convey the object code using peer-to-peer transmission, provided
you inform other peers where the object code and Corresponding
Source of the work are being offered to the general public at no
charge under subsection 6d.
A separable portion of the object code, whose source code is excluded
from the Corresponding Source as a System Library, need not be
included in conveying the object code work.
A "User Product" is either (1) a "consumer product", which means any
tangible personal property which is normally used for personal, family,
or household purposes, or (2) anything designed or sold for incorporation
into a dwelling. In determining whether a product is a consumer product,
doubtful cases shall be resolved in favor of coverage. For a particular
product received by a particular user, "normally used" refers to a
typical or common use of that class of product, regardless of the status
of the particular user or of the way in which the particular user
actually uses, or expects or is expected to use, the product. A product
is a consumer product regardless of whether the product has substantial
commercial, industrial or non-consumer uses, unless such uses represent
the only significant mode of use of the product.
"Installation Information" for a User Product means any methods,
procedures, authorization keys, or other information required to install
and execute modified versions of a covered work in that User Product from
a modified version of its Corresponding Source. The information must
suffice to ensure that the continued functioning of the modified object
code is in no case prevented or interfered with solely because
modification has been made.
If you convey an object code work under this section in, or with, or
specifically for use in, a User Product, and the conveying occurs as
part of a transaction in which the right of possession and use of the
User Product is transferred to the recipient in perpetuity or for a
fixed term (regardless of how the transaction is characterized), the
Corresponding Source conveyed under this section must be accompanied
by the Installation Information. But this requirement does not apply
if neither you nor any third party retains the ability to install
modified object code on the User Product (for example, the work has
been installed in ROM).
The requirement to provide Installation Information does not include a
requirement to continue to provide support service, warranty, or updates
for a work that has been modified or installed by the recipient, or for
the User Product in which it has been modified or installed. Access to a
network may be denied when the modification itself materially and
adversely affects the operation of the network or violates the rules and
protocols for communication across the network.
Corresponding Source conveyed, and Installation Information provided,
in accord with this section must be in a format that is publicly
documented (and with an implementation available to the public in
source code form), and must require no special password or key for
unpacking, reading or copying.
7. Additional Terms.
"Additional permissions" are terms that supplement the terms of this
License by making exceptions from one or more of its conditions.
Additional permissions that are applicable to the entire Program shall
be treated as though they were included in this License, to the extent
that they are valid under applicable law. If additional permissions
apply only to part of the Program, that part may be used separately
under those permissions, but the entire Program remains governed by
this License without regard to the additional permissions.
When you convey a copy of a covered work, you may at your option
remove any additional permissions from that copy, or from any part of
it. (Additional permissions may be written to require their own
removal in certain cases when you modify the work.) You may place
additional permissions on material, added by you to a covered work,
for which you have or can give appropriate copyright permission.
Notwithstanding any other provision of this License, for material you
add to a covered work, you may (if authorized by the copyright holders of
that material) supplement the terms of this License with terms:
a) Disclaiming warranty or limiting liability differently from the
terms of sections 15 and 16 of this License; or
b) Requiring preservation of specified reasonable legal notices or
author attributions in that material or in the Appropriate Legal
Notices displayed by works containing it; or
c) Prohibiting misrepresentation of the origin of that material, or
requiring that modified versions of such material be marked in
reasonable ways as different from the original version; or
d) Limiting the use for publicity purposes of names of licensors or
authors of the material; or
e) Declining to grant rights under trademark law for use of some
trade names, trademarks, or service marks; or
f) Requiring indemnification of licensors and authors of that
material by anyone who conveys the material (or modified versions of
it) with contractual assumptions of liability to the recipient, for
any liability that these contractual assumptions directly impose on
those licensors and authors.
All other non-permissive additional terms are considered "further
restrictions" within the meaning of section 10. If the Program as you
received it, or any part of it, contains a notice stating that it is
governed by this License along with a term that is a further
restriction, you may remove that term. If a license document contains
a further restriction but permits relicensing or conveying under this
License, you may add to a covered work material governed by the terms
of that license document, provided that the further restriction does
not survive such relicensing or conveying.
If you add terms to a covered work in accord with this section, you
must place, in the relevant source files, a statement of the
additional terms that apply to those files, or a notice indicating
where to find the applicable terms.
Additional terms, permissive or non-permissive, may be stated in the
form of a separately written license, or stated as exceptions;
the above requirements apply either way.
8. Termination.
You may not propagate or modify a covered work except as expressly
provided under this License. Any attempt otherwise to propagate or
modify it is void, and will automatically terminate your rights under
this License (including any patent licenses granted under the third
paragraph of section 11).
However, if you cease all violation of this License, then your
license from a particular copyright holder is reinstated (a)
provisionally, unless and until the copyright holder explicitly and
finally terminates your license, and (b) permanently, if the copyright
holder fails to notify you of the violation by some reasonable means
prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is
reinstated permanently if the copyright holder notifies you of the
violation by some reasonable means, this is the first time you have
received notice of violation of this License (for any work) from that
copyright holder, and you cure the violation prior to 30 days after
your receipt of the notice.
Termination of your rights under this section does not terminate the
licenses of parties who have received copies or rights from you under
this License. If your rights have been terminated and not permanently
reinstated, you do not qualify to receive new licenses for the same
material under section 10.
9. Acceptance Not Required for Having Copies.
You are not required to accept this License in order to receive or
run a copy of the Program. Ancillary propagation of a covered work
occurring solely as a consequence of using peer-to-peer transmission
to receive a copy likewise does not require acceptance. However,
nothing other than this License grants you permission to propagate or
modify any covered work. These actions infringe copyright if you do
not accept this License. Therefore, by modifying or propagating a
covered work, you indicate your acceptance of this License to do so.
10. Automatic Licensing of Downstream Recipients.
Each time you convey a covered work, the recipient automatically
receives a license from the original licensors, to run, modify and
propagate that work, subject to this License. You are not responsible
for enforcing compliance by third parties with this License.
An "entity transaction" is a transaction transferring control of an
organization, or substantially all assets of one, or subdividing an
organization, or merging organizations. If propagation of a covered
work results from an entity transaction, each party to that
transaction who receives a copy of the work also receives whatever
licenses to the work the party's predecessor in interest had or could
give under the previous paragraph, plus a right to possession of the
Corresponding Source of the work from the predecessor in interest, if
the predecessor has it or can get it with reasonable efforts.
You may not impose any further restrictions on the exercise of the
rights granted or affirmed under this License. For example, you may
not impose a license fee, royalty, or other charge for exercise of
rights granted under this License, and you may not initiate litigation
(including a cross-claim or counterclaim in a lawsuit) alleging that
any patent claim is infringed by making, using, selling, offering for
sale, or importing the Program or any portion of it.
11. Patents.
A "contributor" is a copyright holder who authorizes use under this
License of the Program or a work on which the Program is based. The
work thus licensed is called the contributor's "contributor version".
A contributor's "essential patent claims" are all patent claims
owned or controlled by the contributor, whether already acquired or
hereafter acquired, that would be infringed by some manner, permitted
by this License, of making, using, or selling its contributor version,
but do not include claims that would be infringed only as a
consequence of further modification of the contributor version. For
purposes of this definition, "control" includes the right to grant
patent sublicenses in a manner consistent with the requirements of
this License.
Each contributor grants you a non-exclusive, worldwide, royalty-free
patent license under the contributor's essential patent claims, to
make, use, sell, offer for sale, import and otherwise run, modify and
propagate the contents of its contributor version.
In the following three paragraphs, a "patent license" is any express
agreement or commitment, however denominated, not to enforce a patent
(such as an express permission to practice a patent or covenant not to
sue for patent infringement). To "grant" such a patent license to a
party means to make such an agreement or commitment not to enforce a
patent against the party.
If you convey a covered work, knowingly relying on a patent license,
and the Corresponding Source of the work is not available for anyone
to copy, free of charge and under the terms of this License, through a
publicly available network server or other readily accessible means,
then you must either (1) cause the Corresponding Source to be so
available, or (2) arrange to deprive yourself of the benefit of the
patent license for this particular work, or (3) arrange, in a manner
consistent with the requirements of this License, to extend the patent
license to downstream recipients. "Knowingly relying" means you have
actual knowledge that, but for the patent license, your conveying the
covered work in a country, or your recipient's use of the covered work
in a country, would infringe one or more identifiable patents in that
country that you have reason to believe are valid.
If, pursuant to or in connection with a single transaction or
arrangement, you convey, or propagate by procuring conveyance of, a
covered work, and grant a patent license to some of the parties
receiving the covered work authorizing them to use, propagate, modify
or convey a specific copy of the covered work, then the patent license
you grant is automatically extended to all recipients of the covered
work and works based on it.
A patent license is "discriminatory" if it does not include within
the scope of its coverage, prohibits the exercise of, or is
conditioned on the non-exercise of one or more of the rights that are
specifically granted under this License. You may not convey a covered
work if you are a party to an arrangement with a third party that is
in the business of distributing software, under which you make payment
to the third party based on the extent of your activity of conveying
the work, and under which the third party grants, to any of the
parties who would receive the covered work from you, a discriminatory
patent license (a) in connection with copies of the covered work
conveyed by you (or copies made from those copies), or (b) primarily
for and in connection with specific products or compilations that
contain the covered work, unless you entered into that arrangement,
or that patent license was granted, prior to 28 March 2007.
Nothing in this License shall be construed as excluding or limiting
any implied license or other defenses to infringement that may
otherwise be available to you under applicable patent law.
12. No Surrender of Others' Freedom.
If conditions are imposed on you (whether by court order, agreement or
otherwise) that contradict the conditions of this License, they do not
excuse you from the conditions of this License. If you cannot convey a
covered work so as to satisfy simultaneously your obligations under this
License and any other pertinent obligations, then as a consequence you may
not convey it at all. For example, if you agree to terms that obligate you
to collect a royalty for further conveying from those to whom you convey
the Program, the only way you could satisfy both those terms and this
License would be to refrain entirely from conveying the Program.
13. Use with the GNU Affero General Public License.
Notwithstanding any other provision of this License, you have
permission to link or combine any covered work with a work licensed
under version 3 of the GNU Affero General Public License into a single
combined work, and to convey the resulting work. The terms of this
License will continue to apply to the part which is the covered work,
but the special requirements of the GNU Affero General Public License,
section 13, concerning interaction through a network will apply to the
combination as such.
14. Revised Versions of this License.
The Free Software Foundation may publish revised and/or new versions of
the GNU General Public License from time to time. Such new versions will
be similar in spirit to the present version, but may differ in detail to
address new problems or concerns.
Each version is given a distinguishing version number. If the
Program specifies that a certain numbered version of the GNU General
Public License "or any later version" applies to it, you have the
option of following the terms and conditions either of that numbered
version or of any later version published by the Free Software
Foundation. If the Program does not specify a version number of the
GNU General Public License, you may choose any version ever published
by the Free Software Foundation.
If the Program specifies that a proxy can decide which future
versions of the GNU General Public License can be used, that proxy's
public statement of acceptance of a version permanently authorizes you
to choose that version for the Program.
Later license versions may give you additional or different
permissions. However, no additional obligations are imposed on any
author or copyright holder as a result of your choosing to follow a
later version.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
17. Interpretation of Sections 15 and 16.
If the disclaimer of warranty and limitation of liability provided
above cannot be given local legal effect according to their terms,
reviewing courts shall apply local law that most closely approximates
an absolute waiver of all civil liability in connection with the
Program, unless a warranty or assumption of liability accompanies a
copy of the Program in return for a fee.
END OF TERMS AND CONDITIONS
How to Apply These Terms to Your New Programs
If you develop a new program, and you want it to be of the greatest
possible use to the public, the best way to achieve this is to make it
free software which everyone can redistribute and change under these terms.
To do so, attach the following notices to the program. It is safest
to attach them to the start of each source file to most effectively
state the exclusion of warranty; and each file should have at least
the "copyright" line and a pointer to where the full notice is found.
<one line to give the program's name and a brief idea of what it does.>
Copyright (C) <year> <name of author>
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
If the program does terminal interaction, make it output a short
notice like this when it starts in an interactive mode:
<program> Copyright (C) <year> <name of author>
This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
This is free software, and you are welcome to redistribute it
under certain conditions; type `show c' for details.
The hypothetical commands `show w' and `show c' should show the appropriate
parts of the General Public License. Of course, your program's commands
might be different; for a GUI interface, you would use an "about box".
You should also get your employer (if you work as a programmer) or school,
if any, to sign a "copyright disclaimer" for the program, if necessary.
For more information on this, and how to apply and follow the GNU GPL, see
<http://www.gnu.org/licenses/>.
The GNU General Public License does not permit incorporating your program
into proprietary programs. If your program is a subroutine library, you
may consider it more useful to permit linking proprietary applications with
the library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License. But first, please read
<http://www.gnu.org/philosophy/why-not-lgpl.html>.

View File

@ -0,0 +1,99 @@
### Compiling the project
In order to compile this project the following prerequisites must be fulfilled:
- Java Development Kit v1.8 must be installed
(see http://www.oracle.com/technetwork/java/javase/downloads or http://openjdk.java.net/ )
- Apache Maven must be installed (see https://maven.apache.org/, version 3.2.3 was used during development).
The compilation process will not execute the provided test cases by default, nevertheless this behaviour
may be changed but additional prerequisites must be fulfilled first, please refer to the README file located in the test
resources directory (usually `src/test/resources/`).
Afterwards, within the projects top level directory (containing the file `pom.xml`) execute:
```sh
$ mvn clean install
```
This will create the new directory `target`, containing:
- **rubanetra-0.0.6-distribution.zip**
This archive represents the final binary project files, including default configuration files (`./conf/`
and dependencies (`./lib/`).
Use/unpack this archive to install the project on the target machine, however, please refer to the runtime
requirements listed below first. Ultimately, this archive should contain:
- **rubanetra-0.0.6.jar**
The compiled project binary.
- **rubanetra-0.0.6-(test-)sources.jar**
This archive contains the projects (test-)source code, including generated (test-)sources
and default configuration files.
- **rubanetra-0.0.6-javadoc.jar**
This archive contains the projects Java documentation.
- the directory `lib`, which contains all compiled third-party java-dependencies.
- the directory `conf`, which contains modifiable project specific configuration files.
- **rubanetra-0.0.6-package.zip**
This archive contains all sources needed to compile the project from scratch using maven.
It does not contain any binary dependencies.
### Running the project
In order to run this project it must be ensured that
- jNetPcap/libpcap/WinPcap (platform dependent) native libraries are accessible via Java classpath.
- the main configuration file (defaults to `./conf/rubanetra.conf`) is available/accessible and adjusted accordingly.
The path to this file may alternatively be provided via command line argument `-c`).
- the Drools configuration folder (defaults to `./conf/META-INF`) is available/accessible and adjusted accordingly.
Note that for the current version 0.0.6, the actual Drools configuration folder must be
named `META-INF` and contain the file `kmodule.xml`, which represents the Drools knowledge base configuration
and is looked up/compiled by Drools during runtime. This allows to adjust the Knowledge-Base,
i.e. rule modifications/additions/deletions before each invocation without the need to compile a separate JAR.
- the SLF4J-logback logging configuration file (defaults to `./conf/logback.xml`) is available/accessible and
adjusted accordingly.
- the project was successfully compiled and Maven was able to resolve all dependencies.
Additionally, it is recommended to compile the Rubanetra binding for the plaso project (http://plaso.kiddaland.net/) as
well, which is currently available at http://gitlab.swerk.priv.at/stefan/plaso-rubanetra.
For compilation instructions please follow the *Developers Guide* chapter
at https://github.com/log2timeline/plaso/wiki/Developers-Guide.
The frontend main method for the project may then be invoked from the terminal by executing:
```sh
$ java -jar rubanetra-0.0.6.jar
```
To provide the native libraries via `/usr/lib`:
```sh
$ java -cp /usr/lib -jar rubanetra-0.0.6.jar
```
To provide a custom configuration directory (e.g. `/etc/rubanetra/conf`) and
native libraries via `/usr/lib`(substitute `:` with the underlying system path separator):
```sh
$ java -cp "/etc/rubanetra/conf:/usr/lib" -jar rubanetra-0.0.6.jar
```
### Dependencies
This project utilizes jNetPcap (http://jnetpcap.com/) and therefore libpcap/WinPcap as PCAP-library.
Please follow the installation instructions of the jNetPcap-library (project was compiled with version
1.4.r1425-1d), especially the native library section and adjust the Java-Classpath accordingly.
As an alternative, the required native file classpath may be included in the final jar-Archive manifest by adjusting
the projects `pom.xml` property section (i.e. `library.directory` and `native.lib.classpath` properties) first
and recompiling afterwards.
For a list of all utilized (including transitive) third party libraries refer to file `THIRD-PARTY.txt`.
### Bugs
Please report bugs concerning this project to:
http://gitlab.swerk.priv.at/stefan/rubanetra/issues
### Version control / project home
The latest version of this project may be obtained via git:
```sh
$ git clone http://gitlab.swerk.priv.at/stefan/rubanetra.git
```
or by pointing a browser to http://gitlab.swerk.priv.at/stefan/rubanetra.
### Hints
If a runtime exception like the following
> java.lang.UnsatisfiedLinkError: com.slytechs.library.NativeLibrary.dlopen(Ljava/lang/String;)
is encountered, the JNetPcap-library (Java) was unable to locate the native library in the classpath, i.e.
either the JNetPcap native binding or libpcap is missing (see above).
Special note for Ubuntu 12.04/14.04: The package `libpcap-dev` must be installed.

View File

@ -0,0 +1,97 @@
###########################
# Compiling the project #
###########################
In order to compile this project the following prerequisites must be fulfilled:
- Java Development Kit v1.8 must be installed
(see http://www.oracle.com/technetwork/java/javase/downloads or http://openjdk.java.net/ )
- Apache Maven must be installed (see https://maven.apache.org/, version 3.2.3 was used during development).
The compilation process will not execute the provided test cases by default, nevertheless this behaviour
may be changed but additional prerequisites must be fulfilled first, please refer to the README file located in the test
resources directory (usually 'src/test/resources/').
Afterwards, within the projects top level directory (containing the file 'pom.xml') execute:
$ mvn clean install
This will create the new directory 'target', containing:
- "rubanetra-0.0.6-distribution.zip"
This archive represents the final binary project files, including default configuration files ('./conf/'
and dependencies ('./lib/').
Use/unpack this archive to install the project on the target machine, however, please refer to the runtime
requirements listed below first. Ultimately, this archive should contain:
* "rubanetra-0.0.6.jar"
The compiled project binary.
* "rubanetra-0.0.6-(test-)sources.jar"
This archive contains the projects (test-)source code, including generated (test-)sources
and default configuration files.
* "rubanetra-0.0.6-javadoc.jar"
This archive contains the projects Java documentation.
* the directory 'lib', which contains all compiled third-party java-dependencies.
* the directory 'conf', which contains modifiable project specific configuration files.
- "rubanetra-0.0.6-package.zip"
This archive contains all sources needed to compile the project from scratch using maven.
It does not contain any binary dependencies.
#######################
# Running the project #
#######################
In order to run this project it must be ensured that
- jNetPcap/libpcap/WinPcap (platform dependent) native libraries are accessible via Java classpath.
- the main configuration file (defaults to './conf/rubanetra.conf') is available/accessible and adjusted accordingly.
The path to this file may alternatively be provided via command line argument '-c').
- the Drools configuration folder (defaults to './conf/META-INF') is available/accessible and adjusted accordingly.
Note that for the current version 0.0.6, the actual Drools configuration folder must be
named 'META-INF' and contain the file 'kmodule.xml', which represents the Drools knowledge base configuration
and is looked up/compiled by Drools during runtime. This allows to adjust the Knowledge-Base,
i.e. rule modifications/additions/deletions before each invocation without the need to compile a separate JAR.
- the SLF4J-logback logging configuration file (defaults to './conf/logback.xml') is available/accessible and
adjusted accordingly.
- the project was successfully compiled and Maven was able to resolve all dependencies.
Additionally, it is recommended to compile the Rubanetra binding for the plaso project (http://plaso.kiddaland.net/) as
well, which is currently available at http://gitlab.swerk.priv.at/stefan/plaso-rubanetra.
For compilation instructions please follow the "Developers Guide - How to build plaso from scratch" chapter
at https://github.com/log2timeline/plaso/wiki/Developers-Guide.
The frontend main method for the project may then be invoked from the terminal by executing:
$ java -jar rubanetra-0.0.6.jar
To provide the native libraries via '/usr/lib':
$ java -cp /usr/lib -jar rubanetra-0.0.6.jar
To provide a custom configuration directory (e.g. '/etc/rubanetra/conf') and
native libraries via '/usr/lib'(substitute ':' with the underlying system path separator):
$ java -cp "/etc/rubanetra/conf:/usr/lib" -jar rubanetra-0.0.6.jar
################
# Dependencies #
################
This project utilizes jNetPcap (http://jnetpcap.com/) and therefore libpcap/WinPcap as PCAP-library.
Please follow the installation instructions of the jNetPcap-library (project was compiled with version 1.4.r1425-1d),
especially the native library section and adjust the Java-Classpath accordingly.
As an alternative the required native file classpath may be included in the final jar-Archive manifest by adjusting
the projects 'pom.xml' property section (i.e. 'library.directory' and 'native.lib.classpath' properties) first
and recompiling afterwards.
For a list of all utilized (including transitive) third party libraries refer to file 'THIRD-PARTY.txt'.
########
# Bugs #
########
Please report bugs concerning this project to:
http://gitlab.swerk.priv.at/stefan/rubanetra/issues
##################################
# Version control / project home #
##################################
The latest version of this project may be obtained via git:
git clone http://gitlab.swerk.priv.at/stefan/rubanetra.git
or by pointing a browser to:
http://gitlab.swerk.priv.at/stefan/rubanetra
#########
# Hints #
#########
If a runtime exception like the following
java.lang.UnsatisfiedLinkError: com.slytechs.library.NativeLibrary.dlopen(Ljava/lang/String;)
is encountered, the JNetPcap-library (Java) was unable to locate the native library in the classpath, i.e.
either the JNetPcap native binding or libpcap is missing (see above).
Special note for Ubuntu 12.04: The package 'libpcap-dev' must be installed.

View File

@ -0,0 +1,51 @@
Lists of 49 third-party dependencies.
(Eclipse Public License - v 1.0) (GNU Lesser General Public License) Logback Classic Module (ch.qos.logback:logback-classic:1.1.1 - http://logback.qos.ch)
(Eclipse Public License - v 1.0) (GNU Lesser General Public License) Logback Core Module (ch.qos.logback:logback-core:1.1.1 - http://logback.qos.ch)
(The Apache Software License, Version 2.0) Jackson-annotations (com.fasterxml.jackson.core:jackson-annotations:2.5.0 - http://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) Jackson-core (com.fasterxml.jackson.core:jackson-core:2.5.3 - https://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) jackson-databind (com.fasterxml.jackson.core:jackson-databind:2.5.3 - http://github.com/FasterXML/jackson)
(The Apache Software License, Version 2.0) Jackson-dataformat-XML (com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.5.3 - http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding)
(The Apache Software License, Version 2.0) Jackson-module-JAXB-annotations (com.fasterxml.jackson.module:jackson-module-jaxb-annotations:2.5.3 - http://wiki.fasterxml.com/JacksonJAXBAnnotations)
(New BSD license) Protocol Buffer Java API (com.google.protobuf:protobuf-java:2.5.0 - http://code.google.com/p/protobuf)
(BSD style) XStream Core (com.thoughtworks.xstream:xstream:1.4.7 - http://codehaus.org/xstream-parent/xstream/)
(The Apache Software License, Version 2.0) Commons CLI (commons-cli:commons-cli:1.2 - http://commons.apache.org/cli/)
(The Apache Software License, Version 2.0) Commons Codec (commons-codec:commons-codec:1.6 - http://commons.apache.org/codec/)
(The Apache Software License, Version 2.0) Commons Logging (commons-logging:commons-logging:1.1.3 - http://commons.apache.org/proper/commons-logging/)
(BSD 2-Clause license) dnsjava (dnsjava:dnsjava:2.1.7 - http://www.dnsjava.org)
(CDDL) (GPLv2+CE) JavaMail API (compat) (javax.mail:mail:1.4.7 - http://kenai.com/projects/javamail/mail)
(COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0) (GNU General Public Library) Streaming API for XML (javax.xml.stream:stax-api:1.0-2 - no url defined)
(GNU Lesser General Public License (LGPL) Version 3) jnetpcap (jnetpcap:jnetpcap:1.4.r1425-1d - no url defined)
(Common Public License Version 1.0) JUnit (junit:junit:4.11 - http://junit.org)
(BSD 3-Clause "New" or "Revised" License (BSD-3-Clause)) abego TreeLayout Core (org.abego.treelayout:org.abego.treelayout.core:1.0.1 - http://code.google.com/p/treelayout/)
(BSD licence) ANTLR 3 Runtime (org.antlr:antlr-runtime:3.5 - http://www.antlr.org)
(BSD 3-Clause License) ANTLR 4 Runtime (org.antlr:antlr4-runtime:4.5 - http://www.antlr.org)
(The Apache Software License, Version 2.0) Apache Commons CSV (org.apache.commons:commons-csv:1.0 - http://commons.apache.org/proper/commons-csv/)
(Apache License, Version 2.0) Apache HttpClient (org.apache.httpcomponents:httpclient:4.3.3 - http://hc.apache.org/httpcomponents-client)
(Apache License, Version 2.0) Apache HttpCore (org.apache.httpcomponents:httpcore:4.3.2 - http://hc.apache.org/httpcomponents-core-ga)
(The BSD License) Stax2 API (org.codehaus.woodstox:stax2-api:3.1.4 - http://wiki.fasterxml.com/WoodstoxStax2)
(The Apache Software License, Version 2.0) Woodstox (org.codehaus.woodstox:woodstox-core-asl:4.3.0 - http://woodstox.codehaus.org)
(The Apache Software License, Version 2.0) Drools :: Compiler (org.drools:drools-compiler:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/drools-multiproject/drools-compiler)
(The Apache Software License, Version 2.0) Drools :: Core (org.drools:drools-core:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/drools-multiproject/drools-core)
(Eclipse Public License v1.0) Eclipse ECJ (org.eclipse.jdt.core.compiler:ecj:4.3.1 - http://www.eclipse.org/jdt/)
(New BSD License) Hamcrest Core (org.hamcrest:hamcrest-core:1.3 - https://github.com/hamcrest/JavaHamcrest/hamcrest-core)
(The Apache Software License, Version 2.0) KIE API (org.kie:kie-api:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/kie-api-parent/kie-api)
(The Apache Software License, Version 2.0) KIE Internal (org.kie:kie-internal:6.1.0.Final - http://www.jboss.org/drools/kie-parent-with-dependencies/kie-api-parent/kie-internal)
(Apache Software License 2) Kraken API (org.krakenapps:kraken-api:2.1.1 - http://maven.apache.org)
(Apache Software License 2) Kraken DHCP Decoder (org.krakenapps:kraken-dhcp-decoder:1.0.1 - http://krakenapps.org/kraken-pcap-pom/kraken-dhcp-decoder)
(Apache Software License 2) Kraken FTP Decoder (org.krakenapps:kraken-ftp-decoder:1.2.0 - http://krakenapps.org/kraken-pcap-pom/kraken-ftp-decoder)
(Apache Software License 2) Kraken HTTP Decoder (org.krakenapps:kraken-http-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-http-decoder)
(Apache Software License 2) Kraken JSON (org.krakenapps:kraken-json:1.1.1 - http://krakenapps.org/kraken-format-pom/kraken-json)
(Apache Software License 2) Kraken Mime (org.krakenapps:kraken-mime:1.0.0 - http://krakenapps.org/kraken-format-pom/kraken-mime)
(Apache Software License 2) Kraken MSN Decoder (org.krakenapps:kraken-msn-decoder:1.2.0 - http://krakenapps.org/kraken-pcap-pom/kraken-msn-decoder)
(Apache Software License 2) Kraken Netbios Decoder (org.krakenapps:kraken-netbios-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-netbios-decoder)
(Apache Software License 2) Kraken PCAP (org.krakenapps:kraken-pcap:1.7.1 - http://krakenapps.org/kraken-pcap-pom/kraken-pcap)
(Apache Software License 2) Kraken POP3 Decoder (org.krakenapps:kraken-pop3-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-pop3-decoder)
(Apache Software License 2) Kraken SMTP Decoder (org.krakenapps:kraken-smtp-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-smtp-decoder)
(Apache Software License 2) Kraken SNMP Decoder (org.krakenapps:kraken-snmp-decoder:1.1.0 - http://krakenapps.org/kraken-pcap-pom/kraken-snmp-decoder)
(Apache Software License 2) Kraken Telnet Decoder (org.krakenapps:kraken-telnet-decoder:1.0.0 - http://krakenapps.org/kraken-pcap-pom/kraken-telnet-decoder)
(The Apache Software License, Version 2.0) mvel (org.mvel:mvel2:2.2.1.Final - http://mvel.codehaus.org/)
(MIT License) JCL 1.1.1 implemented over SLF4J (org.slf4j:jcl-over-slf4j:1.7.6 - http://www.slf4j.org)
(MIT License) SLF4J API Module (org.slf4j:slf4j-api:1.7.6 - http://www.slf4j.org)
(Public Domain) XML Pull Parsing API (xmlpull:xmlpull:1.1.3.1 - http://www.xmlpull.org)
(Indiana University Extreme! Lab Software License, vesion 1.1.1) (Public Domain) MXP1: Xml Pull Parser 3rd Edition (XPP3) (xpp3:xpp3_min:1.1.4c - http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/)

View File

@ -0,0 +1,85 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.arp.*;
import at.jku.fim.rubanetra.protocol.activity.dhcp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import at.jku.fim.rubanetra.protocol.activity.ethernet.*;
import at.jku.fim.rubanetra.protocol.activity.ftp.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.msn.*;
import at.jku.fim.rubanetra.protocol.activity.netbios.*;
import at.jku.fim.rubanetra.protocol.activity.pop3.*;
import at.jku.fim.rubanetra.protocol.activity.skype.*;
import at.jku.fim.rubanetra.protocol.activity.smtp.*;
import at.jku.fim.rubanetra.protocol.activity.snmp.*;
import at.jku.fim.rubanetra.protocol.activity.tcp.*;
import at.jku.fim.rubanetra.protocol.activity.telnet.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.udp.*;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* The following statements declare the metadata of already existing Java abstract classes/interfaces of the
* at.jku.fim.rubanetra.protocol.activity package.
* Specifically it defines these classes as events using the start-timestamp of the activity itself
* as the actual timestamp (used for reasoning) and sets the expiration time of the individual objects.
* If the objects should not expire based on this timer, remove or adapt the @expires attributes.
* Note, however, unless these attributes are overwritten on the Activity-class implementation level, these settings
* will be inherited for all activities (since all Activity-implementations should extend or implement one of the
* abstract classes/interfaces listed below.
*/
declare DroolsBaseActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
@expires( 30m )
end
declare Activity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
@expires( 30m )
end
declare ReplaceableActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
@expires( 30m )
end
declare AbstractActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
@expires( 30m )
end
declare AbstractReplaceableActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
@expires( 30m )
end

View File

@ -0,0 +1,44 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* This global variable constitutes the default output writer that is used to write derived facts, i.e. Activity objects,
* to the final output stream.
*/
global at.jku.fim.rubanetra.output.OutputWriterStrategy outputWriter;
/**
* This rule will ensure that all encountered OutputActivityEvents will be written to the final output stream,
* as long as the enclosed Activity 'toOutput' is not null and the global 'outputWriter' exists.
* The encountered, valid OutputActivityEvent will be retracted afterwards.
* This behaviour is useful to free memory in case the default event expiration time is not defined or
* set to a high value.
*/
rule "Write to OutputStream (event-based)"
when
$outEvent : OutputActivityEvent(toOutput != null)
then
if (outputWriter != null) {
outputWriter.writeActivity($outEvent.getToOutput());
}
retract($outEvent);
end

View File

@ -0,0 +1,201 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.tcp.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import org.xbill.DNS.*;
import org.apache.http.HttpHeaders;
import org.jnetpcap.protocol.tcpip.Tcp;
import org.jnetpcap.packet.PcapPacket;
import org.apache.commons.codec.binary.Hex;
import java.net.InetSocketAddress;
import java.util.HashSet;
import java.util.Date
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress;
import java.util.List;
import java.util.Set;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
/**
* This declaration serves as an example to demonstrate the basic attribute overriding process.
* Usually this class extends the Activity-interface and is declared to be an event.
* However, currently no time-based reasoning will be performed for these objects, therefore it can be
* converted to a Fact.
* This declaration may be removed to use the default attributes again (see 00.Basic.Metadata.drl).
*/
declare HttpImageActivity
@role( fact )
@author( Stefan Swerk )
@dateOfCreation( 10.01.2014 )
end
/**
* The following Tcp declaration represents the jNetPcap-Tcp class, see org.jnetpcap.protocol.tcpip.Tcp.
* Due to 'Tcp' being a Java class of a different library it cannot extend or implement one of the Activity
* base classes and therefore is not treated as a Drools-event per se. Therefore, the metadata of this custom
* class must be defined individually, which can be interpreted as a forward declaration.
*/
declare Tcp
@role( event )
@author( Stefan Swerk )
@timestamp( getPacket().getCaptureHeader().timestampInMillis() )
@expires( 30m )
end
/**
* Currently it appears as if the Tcp-decoder of the Kraken library does not parse all valid Tcp-packets successfully.
* As a kind of workaround this rule has been defined to fallback to the jNetPcap library (hence the previous Tcp-forward
* declaration) for all IPv4 activities that indicate TCP as the encapsulated protocol,
* but that have not been decoded by the Kraken-Tcp-Decoder until now.
* This rule will ensure that an appropriate drop-in TcpActivity will be created and inserted in the event-stream,
* which may be used by other rules.
*/
rule "TCP (work around Kraken limitation)"
when
$ip : Ipv4Activity(ipv4.nextHeaderId == Tcp.ID)
not (exists TcpActivity(pcapActivity == $ip.pcapActivity))
then
Tcp tcp = new Tcp();
PcapPacket p = $ip.getPcapActivity().getPcapPacket();
p.hasHeader(tcp);
log.debug("A workaround Tcp-Activity will be created for frames {}", $ip.getCompoundFrameNumbers());
TcpActivity tcpActivity = new TcpActivity($ip.getPcapActivity(),tcp,$ip);
tcpActivity.replaceActivity($ip);
insert(tcpActivity);
end
/**
* This rules makes use of a custom entry-point called "fact-stream" and the previously declared fact-attribute of
* HttpImageActivity. If a HttpActivity is encountered containing an response that defined an "image/..." content_type
* header, it may be assumed that this reponse was used for delivering image data and the corresponding URL of the request
* contained the image path.
*/
rule "Http Image Activity"
no-loop
when
$httpActivity : HttpActivity($contentType : response.responseHeaderMap[HttpHeaders.CONTENT_TYPE] matches "image/.*",
imageActivities.isEmpty())
then
log.debug("An HttpImageActivity based on the content type was found for frames {}", $httpActivity.getCompoundFrameNumbers());
HttpImageActivity imgAct = new HttpImageActivity($httpActivity);
imgAct.setImagePath($httpActivity.getRequest().getUrl().getFile());
imgAct.setImageType($contentType);
imgAct.setStartInstant($httpActivity.getStartInstant());
imgAct.setEndInstant($httpActivity.getEndInstant());
drools.getEntryPoint("fact-stream").insert(imgAct);
modify($httpActivity){
addImageActivity(imgAct)
}
end
/**
* This rule fires iff there is a HttpImageActivity whose Requests REFERER Header field matches the Request-URI of
* another HttpActivity, i.e. it collects ImageActivities which may be related to a single HttpActivity.
* Consider the following example: A user queries a HTML-Resource that contains external image resources,
* and usually the browser creates subsequent HTTP requests for the image data retrieval.
* Whenever the Browser sets the Referer header field for those separate requests, we could correlate those separate
* image requests with a single HTML resource request.
*/
rule "Collect Http Image Activities (based on referer header)"
when
$http : HttpActivity($req : request, $reqResource : request.url.toString())
$imgAct : HttpImageActivity(this not memberOf $http.imageActivities,
source#HttpActivity.request.requestHeaderMap[HttpHeaders.REFERER] matches $reqResource)
from entry-point "fact-stream"
// add an additional time based constraint
// $htmlRequest : HttpRequestActivity( pcapActivity == $req.pcapActivity)
// $imgRequest : HttpRequestActivity( pcapActivity == $imgAct.source#HttpActivity.request.pcapActivity,
// this after[0s,10s] $htmlRequest)
//
// match a single image request for an image resource to a single request for an html resource only
// not (exists HttpRequestActivity(pcapActivity != $htmlRequest.pcapActivity,
// url.toString() matches $reqResource,
// this before $imgRequest))
then
modify($http) {
addImageActivity($imgAct)
}
end
/**
* Currently the event stream will only contain not yet matched HttpRequests and HttpResponses.
* Since the reasoning process will be enhanced by correlated each request to a response this rule tries to achieve
* a simple matching mechanism based on the TCP/IP source and destination port and address.
*/
rule "Http Request and Response Matching (based on TCP/IP source/destination and time)"
when
$tcpReq : TcpActivity( $reqId := pcapActivity, $src : sourceAddress, $dst : destinationAddress)
$request : HttpRequestActivity( $reqId := pcapActivity)
$tcpResp : TcpActivity( $respId : pcapActivity, $tcpReq.sourcePort == destinationPort,
$src == destinationAddress, $dst == sourceAddress)
$response : HttpResponseActivity(pcapActivity == $respId, this after[0s,1m] $request)
not (exists HttpActivity(request == $request || response == $response))
then
HttpActivity activity = new HttpActivity($request, $response);
log.debug("A HttpRequest was matched with a HttpResponse (frames {})", activity.getCompoundFrameNumbers());
insert(activity);
end
/**
* This rule tries to match a DNS response to a an already existing HttpActivity using the hostname header field and
* a maximum interval between the DNS response and the Http response of [0s;20s].
* An already existing DNS match of a HttpActivity will not be overwritten.
*/
rule "HttpActivity as a potential result of a preceding DNS activity"
when
$http : HttpActivity($hostHeader : request.requestHeaderMap[HttpHeaders.HOST], dnsMatch==null)
$dnsResponse : DnsActivity(isResponse(), this before[0s,20s] $http)
/**
* The first two checks are IP based, i.e: was the ip address from the DNS A/AAAA record called and does it match the HTTP server IP?
* The last check is domain based, i.e. the "Host:"-Header field from the HttpRequest is compared against the DNS name reply.
*/
exists( ARecord( $address : getAddress(), $address!.getHostAddress() == $http.request.serverAddress.getAddress().getHostAddress())
from $dnsResponse.getAnswerRecords()
or AAAARecord( $address : getAddress(), $address!.getHostAddress() == $http.request.serverAddress.getAddress().getHostAddress())
from $dnsResponse.getAnswerRecords()
or Record( $address : name, $address!.toString().startsWith($hostHeader))
from $dnsResponse.getAnswerRecords()
)
then
// At this point there was a preceding DNS response and a matching subsequent HTTP Request and Response
modify($http) {
setDnsMatch($dnsResponse);
};
end

View File

@ -0,0 +1,93 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.tcp.*;
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress
import java.util.List;
import java.util.Set
import java.util.HashSet;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
/**
* This experimental rule looks for sequences of three related TCP-activities, i.e.:
* First, it tries to find a "ClientHello" Packet (according to the TLS handshake) followed by a "ServerHello".
* Finally an additional "ChangeCipher" message is expected before classifying this sequence as a TLS/SSL stream, see
* RFC 5246 (https://tools.ietf.org/html/rfc5246).
* The remaining packets will be assembled by the "TLS traffic"-rules (see below)
*/
rule "TLS Handshake"
when
$clientHello : TcpActivity( $payload : payloadHexFormattedDump(), $payload!=null,
TlsActivityHelper.isClientHello(tcp))
$serverHello : TcpActivity( sourceSocketAddress==$clientHello.destinationSocketAddress,
destinationSocketAddress==$clientHello.sourceSocketAddress,
TlsActivityHelper.isServerHello(tcp),
this after[0s,10s] $clientHello)
$changeCipher : TcpActivity(sourceSocketAddress==$clientHello.destinationSocketAddress,
destinationSocketAddress==$clientHello.sourceSocketAddress,
TlsActivityHelper.isChangeCipherSpec(tcp),
this after[0s,10s] $serverHello)
exists TcpActivity( sourceSocketAddress==$clientHello.destinationSocketAddress,
destinationSocketAddress==$clientHello.sourceSocketAddress,
TlsActivityHelper.isChangeCipherSpec(tcp),
this after[0s,10s] $changeCipher)
not (exists TlsActivity(clientHello==$clientHello || serverHello==$serverHello || changeCipherSpec==$changeCipher))
then
TlsActivity tls = new TlsActivity($clientHello,$serverHello);
tls.setChangeCipherSpec($changeCipher);
insert(tls);
end
/**
* Collects TCP activities for a given TlsActivity (client to server only) based on source/destionation ip/port
*/
rule "TLS traffic (client -> server)"
when
$tls : TlsActivity($clientHello : clientHello)
$tcp : TcpActivity( sourceSocketAddress==$clientHello.sourceSocketAddress,
destinationSocketAddress==$clientHello.destinationSocketAddress)
then
$tls.addClientToServerTcpActivity($tcp);
end
/**
* Collects TCP activities for a given TlsActivity (server to client only) based on source/destionation ip/port
*/
rule "TLS traffic (server -> client)"
when
$tls : TlsActivity($serverHello : serverHello)
$tcp : TcpActivity( sourceSocketAddress==$serverHello.sourceSocketAddress,
destinationSocketAddress==$serverHello.destinationSocketAddress)
then
$tls.addServerToClientTcpActivity($tcp);
end

View File

@ -0,0 +1,77 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import org.xbill.DNS.*;
import org.apache.http.HttpHeaders;
import org.jnetpcap.protocol.tcpip.Tcp;
import org.jnetpcap.packet.PcapPacket;
import org.apache.commons.codec.binary.Hex;
import java.net.InetSocketAddress;
import java.util.HashSet;
import java.util.Date
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress
import java.util.List;
import java.util.Set;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
// this forward declaration is required to demonstrate the in-place definition of a custom event class,
// see HttpsActivity below
declare DroolsBaseActivity
end
/**
* This declaration demonstrates an in-place declaration of a custom event class.
* A HttpsActivity currently consists of a client/server socket address and TLS-Activity, however,
* it includes all relevant frame numbers for further analysis because it replaces the TLS-activity.
*/
declare HttpsActivity extends DroolsBaseActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
client : InetSocketAddress
server : InetSocketAddress
tlsActivity : TlsActivity
end
rule "HTTPS" when
$tls : TlsActivity( clientHello.destinationPort == 443, !replaced)
not (exists HttpsActivity($tls == tlsActivity))
then
HttpsActivity httpsActivity = new HttpsActivity();
httpsActivity.setClient($tls.getClientHello().getSourceSocketAddress());
httpsActivity.setServer($tls.getClientHello().getDestinationSocketAddress());
httpsActivity.setTlsActivity($tls);
httpsActivity.replaceActivity($tls);
insert(httpsActivity);
end

View File

@ -0,0 +1,46 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import org.xbill.DNS.*;
import org.jnetpcap.protocol.network.Icmp.IcmpCode;
import org.jnetpcap.protocol.network.Icmp.IcmpType;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
/**
* Groups ICMP echo requests and echo replies to a PingActivity
*/
rule "Ping (Icmpv4)"
when
$req : Icmpv4Activity( $id : identifier, $seq : sequence, icmpType == IcmpType.ECHO_REQUEST)
$rep : Icmpv4Activity( identifier == $id, sequence == $seq, icmpType == IcmpType.ECHO_REPLY)
not (exists PingActivity(request == $req || reply == $rep))
then
insert(new PingActivity($req, $rep));
end

View File

@ -0,0 +1,112 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import at.jku.fim.rubanetra.protocol.activity.tcp.*;
import java.util.HashSet;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
/**
* forward declaration, used for declaring the OpenSSHActivity
*/
declare DroolsBaseActivity
end
/**
* Represents OpenSSH traffic between a client and a server.
*/
declare OpenSSHActivity extends DroolsBaseActivity
@role( event )
@timestamp( getStartTimestamp() )
handshakeQuery : TcpActivity
handshakeReply : TcpActivity
clientToServerTraffic : HashSet
serverToClientTraffic : HashSet
end
/**
* Tries to identfiy an OpenSSH handshake by relying on the presence of the 'SSH-' substring of the
* payload to identify the handshake.
*/
rule "OpenSSH Handshake"
when
$handshakeQuery : TcpActivity( payloadString!.startsWith("SSH-"),
payloadString!.contains("OpenSSH"))
$handshakeReply : TcpActivity( pcapActivity != $handshakeQuery.getPcapActivity(),
payloadString!.startsWith("SSH-"),
payloadString!.contains("OpenSSH"),
sourcePort==$handshakeQuery.destinationPort,
destinationPort==$handshakeQuery.sourcePort,
this after[0s,10s] $handshakeQuery)
// there should not exist another reply before the matched reply
not(exists TcpActivity( pcapActivity != $handshakeQuery.getPcapActivity(),
payloadString!.startsWith("SSH-"),
sourcePort==$handshakeQuery.destinationPort, destinationPort==$handshakeQuery.sourcePort,
this before $handshakeReply, this after $handshakeQuery))
then
OpenSSHActivity sshAct = new OpenSSHActivity();
sshAct.setHandshakeQuery($handshakeQuery);
sshAct.setHandshakeReply($handshakeReply);
sshAct.setClientToServerTraffic(new HashSet());
sshAct.setServerToClientTraffic(new HashSet());
sshAct.replaceActivity($handshakeQuery);
sshAct.replaceActivity($handshakeReply);
insert(sshAct);
end
/**
* Collects client to server traffic (TCP activities)
*/
rule "OpenSSH traffic (client -> server)"
when
$sshAct : OpenSSHActivity()
$tcp : TcpActivity( pcapActivity.frameNumber not memberOf $sshAct.compoundFrameNumbers,
sourceSocketAddress==$sshAct.handshakeQuery.sourceSocketAddress,
destinationSocketAddress==$sshAct.handshakeQuery.destinationSocketAddress)
then
$sshAct.getClientToServerTraffic().addAll($tcp.getCompoundFrameNumbers());
$sshAct.replaceActivity($tcp);
end
/**
* Collects server to client traffic (TCP activities)
*/
rule "OpenSSH traffic (server -> client)"
when
$sshAct : OpenSSHActivity()
$tcp : TcpActivity( pcapActivity.frameNumber not memberOf $sshAct.compoundFrameNumbers,
sourceSocketAddress==$sshAct.handshakeReply.sourceSocketAddress,
destinationSocketAddress==$sshAct.handshakeReply.destinationSocketAddress)
then
$sshAct.getServerToClientTraffic().addAll($tcp.getCompoundFrameNumbers());
$sshAct.replaceActivity($tcp);
end

View File

@ -0,0 +1,93 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress;
import java.util.List;
import java.util.Set;
import java.util.HashSet;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
// forward declaration
declare DroolsBaseActivity
end
/**
* A DropboxTlsActivity contains a DNS query/reply, client/server address/port and the associated Tls-Activity
*/
declare DropboxTlsActivity extends DroolsBaseActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
dnsQuestion : DnsActivity
dnsAnswer : DnsActivity
clientAddress : InetSocketAddress
serverAddress : InetSocketAddress
associatedTlsActivity : TlsActivity
end
/**
* Due to the generally encrypted dropbox traffic a DnsActivity containing the rule looks for query to "*.dropbox.com"
* first and gathers the relevant Ip-Addresses for which possible TlsActivitiy-objects will be probed against.
*/
rule "Dropbox TLS traffic based on previous DnsActivity"
when
$dnsQuery : DnsActivity(!isResponse(), !questionRecords.isEmpty(),
$queryId : dnsMessageHeader.ID,$question : dnsMessage.question.name,
$question.toString() matches ".*\\.dropbox.com\\.$")
$dnsReply : DnsActivity(isResponse(),!answerRecords.isEmpty(),
dnsMessageHeader.ID == $queryId,
this after[0s,10s] $dnsQuery)
$tls : TlsActivity(this after[0s,10s] $dnsReply)
exists ( ARecord( $address : getAddress(),
$address!.getHostAddress() == $tls.getServerHello().getSourceAddress().getHostAddress())
from $dnsReply.getAnswerRecords()
or AAAARecord( $address : getAddress(),
$address!.getHostAddress() == $tls.getServerHello().getSourceAddress().getHostAddress())
from $dnsReply.getAnswerRecords()
)
not ( exists DropboxTlsActivity($tls == associatedTlsActivity))
then
DropboxTlsActivity act = new DropboxTlsActivity();
act.setClientAddress($tls.getClientHello().getSourceSocketAddress());
act.setServerAddress($tls.getServerHello().getSourceSocketAddress());
act.setDnsQuestion($dnsQuery);
act.setDnsAnswer($dnsReply);
act.setAssociatedTlsActivity($tls);
act.replaceActivity($dnsQuery); act.replaceActivity($dnsReply); act.replaceActivity($tls);
insert(act);
end

View File

@ -0,0 +1,92 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress;
import java.util.List;
import java.util.Set;
import java.util.HashSet;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
// forward declaration
declare DroolsBaseActivity
end
/**
* This declaration defines an SpiderOak related Activity, consisting of DNS query/reply, client/server address/port
* and the associated TlsActivity
*/
declare SpiderOakActivity extends DroolsBaseActivity
@role( event )
@author( Stefan Swerk )
@timestamp( getStartTimestamp() )
dnsAnswer : DnsActivity
clientAddress : InetSocketAddress
serverAddress : InetSocketAddress
associatedTlsActivity : TlsActivity
end
/**
* This rule is quite similar to the Dropbox tls traffic matching rule.
* It looks for a DNS query to "*.spideroak.com" and gathers the relevant IP addresses for probing existing, yet unmatched
* TlsActivities.
*/
rule "Spideroak TLS traffic based on DnsActivity"
when
$dnsReply : DnsActivity(isResponse(), !answerRecords.isEmpty(),
$question : dnsMessage.question.name,
$question.toString() matches ".*\\.spideroak.com\\.$")
$tls : TlsActivity(this after[0s,10s] $dnsReply)
exists( ARecord($address : getAddress(),
$address!.getHostAddress() == $tls.getServerHello().getSourceAddress().getHostAddress())
from $dnsReply.getAnswerRecords()
or
AAAARecord( $address : getAddress(),
$address!.getHostAddress() == $tls.getServerHello().getSourceAddress().getHostAddress())
from $dnsReply.getAnswerRecords()
)
then
SpiderOakActivity spiderOakActivity = new SpiderOakActivity();
spiderOakActivity.setDnsAnswer($dnsReply);
spiderOakActivity.setClientAddress($tls.getClientHello().getSourceSocketAddress());
spiderOakActivity.setServerAddress($tls.getServerHello().getSourceSocketAddress());
spiderOakActivity.setAssociatedTlsActivity($tls);
spiderOakActivity.replaceActivity($dnsReply);
spiderOakActivity.replaceActivity($tls);
insert(spiderOakActivity);
end

View File

@ -0,0 +1,114 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
import at.jku.fim.rubanetra.protocol.activity.*;
import at.jku.fim.rubanetra.protocol.activity.tls.*;
import at.jku.fim.rubanetra.protocol.activity.http.*;
import at.jku.fim.rubanetra.protocol.activity.ip.*;
import at.jku.fim.rubanetra.protocol.activity.icmp.*;
import at.jku.fim.rubanetra.protocol.activity.dns.*;
import at.jku.fim.rubanetra.protocol.activity.tcp.*;
import at.jku.fim.rubanetra.protocol.activity.udp.*;
import at.jku.fim.rubanetra.protocol.activity.skype.*;
import at.jku.fim.rubanetra.protocol.activity.DroolsBaseActivity;
import java.util.SortedSet;
import java.util.TreeSet;
import org.xbill.DNS.Record;
import java.net.InetSocketAddress
import java.util.List;
import java.util.Set
import java.util.HashSet
import org.jnetpcap.protocol.tcpip.Udp;
// using the MVEL expression language, see http://mvel.codehaus.org/
dialect "mvel"
/**
* A logger that may be used for logging custom messages
*/
global org.slf4j.Logger log;
// forward declaration
declare DroolsBaseActivity end
/**
* Represents a Skype payload of arbitrary type, consisting of an source/destination object id and hosts.
*/
declare SkypePayloadActivity extends DroolsBaseActivity
@role( event )
@timestamp( getStartTimestamp() )
sourceObjectId : int
destinationObjectId : int
sourceHost : InetSocketAddress
destinationHost : InetSocketAddress
end
/**
* This rule is based on a crude heuristic which is again partially based on: https://github.com/matthiasbock/OpenSkype.
* Skype traffic usually consists of Udp-packets containing a certain kind of object id, therefore those special packets
* have to be matched first.
* This rule should be disabled/removed/improved if it causes false-positives (to reduce the negative impact, this
* rule does not replace any Activities, but extends them instead).
* Possible enhancements include:
* - Use Dns-matches to obtain the skype hosts, if possible (see Dropbox/Spideroak examples)
* - Extend the SkypePayloadActivity according to the known metadata (see https://github.com/matthiasbock/OpenSkype)
*/
rule "Skype Payload (one way, two matches)"
no-loop
when
$udp : UdpActivity( $objectId : SkypeActivityHelper.objectId(udp), SkypeActivityHelper.hasSkypePayload(udp))
$udpResp : UdpActivity( $objectIdResp : SkypeActivityHelper.objectId(udp),
SkypeActivityHelper.hasSkypePayload(udp),
sourceSocketAddress==$udp.destinationSocketAddress,
destinationSocketAddress==$udp.sourceSocketAddress,
this after[0s,10s] $udp)
exists( UdpActivity($oid : SkypeActivityHelper.objectId(udp),
($objectId + 10) > $oid,
$oid > $objectId,
SkypeActivityHelper.hasSkypePayload(udp),
sourceSocketAddress==$udp.sourceSocketAddress,
destinationSocketAddress==$udp.destinationSocketAddress,
this after[0s,10s] $udp) )
exists( UdpActivity($oid : SkypeActivityHelper.objectId(udp),
($objectIdResp + 10) > $oid,
$oid > $objectIdResp,
SkypeActivityHelper.hasSkypePayload(udp),
sourceSocketAddress==$udpResp.sourceSocketAddress,
destinationSocketAddress==$udpResp.destinationSocketAddress,
this after[0s,10s] $udpResp) )
not ( exists UdpActivity( SkypeActivityHelper.objectId(udp)<$objectId,
SkypeActivityHelper.hasSkypePayload(udp),
sourceSocketAddress==$udp.sourceSocketAddress,
destinationSocketAddress==$udp.destinationSocketAddress,
this after[10s] $udp))
not ( exists UdpActivity( SkypeActivityHelper.objectId(udp)<$objectIdResp,
SkypeActivityHelper.hasSkypePayload(udp),
sourceSocketAddress==$udpResp.sourceSocketAddress,
destinationSocketAddress==$udpResp.destinationSocketAddress,
this after[10s] $udpResp))
not ( exists SkypePayloadActivity(sourceObjectId==$objectId || sourceObjectId==$objectIdResp
|| destinationObjectId==$objectId || destinationObjectId==$objectIdResp))
then
SkypePayloadActivity act = new SkypePayloadActivity();
act.setSourceObjectId($objectId); act.setDestinationObjectId($objectIdResp);
act.setSourceHost($udp.getSourceSocketAddress()); act.setDestinationHost($udp.getDestinationSocketAddress());
act.extendActivity($udp); act.extendActivity($udpResp);
insert(act);
end

View File

@ -0,0 +1,33 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<kmodule xmlns="http://jboss.org/kie/6.0.0/kmodule">
<!-- the knowledge base name should correspond to the name of the top level directory containing the rules-->
<kbase name="DefaultKnowledgeBase"
default="true"
eventProcessingMode="stream"
equalsBehavior="equality"
packages="at.jku.fim.rubanetra.drools.rules">
<ksession name="DefaultSession"
default="true"
type="stateful"
clockType="pseudo"/>
</kbase>
</kmodule>

View File

@ -0,0 +1,5 @@
#Generated by Maven
#Tue Jul 07 12:26:27 CEST 2015
version=0.0.6
groupId=at.jku.fim
artifactId=rubanetra

View File

@ -0,0 +1,748 @@
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns="http://maven.apache.org/POM/4.0.0"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>at.jku.fim</groupId>
<artifactId>rubanetra</artifactId>
<version>0.0.6</version>
<name>Rubanetra</name>
<inceptionYear>2013</inceptionYear>
<licenses>
<license>
<name>GNU General Public License, Version 3</name>
<url>https://gnu.org/licenses/gpl-3.0.txt</url>
<distribution>repo</distribution>
</license>
</licenses>
<organization>
<name>Institute of networks and security</name>
<url>https://ins.jku.at</url>
</organization>
<developers>
<developer>
<id>stefan</id>
<name>Stefan Swerk</name>
<email>stefan_rubanetra@swerk.priv.at</email>
<roles>
<role>developer</role>
</roles>
<timezone>+1</timezone>
</developer>
</developers>
<scm>
<connection>scm:git:http://gitlab.swerk.priv.at/stefan/rubanetra.git</connection>
<url>http://gitlab.swerk.priv.at/stefan/rubanetra</url>
</scm>
<issueManagement>
<system>Gitlab</system>
<url>http://gitlab.swerk.priv.at/stefan/rubanetra/issues</url>
</issueManagement>
<properties>
<!-- the default settings to use in the final configuration files -->
<droolsKnowledgeBase>DefaultKnowledgeBase</droolsKnowledgeBase>
<droolsSessionName>DefaultSession</droolsSessionName>
<fnaInputFormat>pcap</fnaInputFormat>
<fnaOutputFile>stdout</fnaOutputFile>
<fnaOutputFormat>plaso</fnaOutputFormat>
<logLevel>info</logLevel>
<logDirectory>./logs</logDirectory>
<library.directory>./lib</library.directory>
<config.directory>./conf</config.directory>
<native.lib.classpath>/usr/lib</native.lib.classpath>
<!-- general settings -->
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
<antlr4.visitor>false</antlr4.visitor>
<antlr4.listener>true</antlr4.listener>
<archive.output.directory>/home/stefan/IdeaProjects/rubanetra/target/archive</archive.output.directory>
<recentYears>2014</recentYears>
<!-- main library versions to use -->
<jnetpcap.version>1.4.r1425-1d</jnetpcap.version>
<jnetpcap.native.lib.dirname>libjnetpcap</jnetpcap.native.lib.dirname>
<krakenpcap.version>1.7.1</krakenpcap.version>
<antlr.version>4.5</antlr.version>
<drools.version>6.1.0.Final</drools.version>
<apachehttpclient.version>4.3.3</apachehttpclient.version>
<dnsjava.version>2.1.7</dnsjava.version>
<junit.version>4.11</junit.version>
<jackson.version>2.5.3</jackson.version>
<slf4j.version>1.7.6</slf4j.version>
</properties>
<repositories>
<!--This repository contains the required Kraken Pcap modules, it may be disabled as soon as the
actual krakenapps.org repository (see below) is up again.-->
<repository>
<id>OpenSOC-Kraken-Repo</id>
<name>OpenSOC Kraken Repository</name>
<url>https://raw.github.com/opensoc/kraken/mvn-repo</url>
</repository>
<!--The following repository is currently down (03.2015), it should be enabled if possible.-->
<!--<repository>-->
<!--<id>krakenapps.org</id>-->
<!--<name>Kraken Repository</name>-->
<!--<url>http://download.krakenapps.org/</url>-->
<!--</repository>-->
<!--The following repository serves as workaround for the missing kraken-pcap-pom dependency problem,
See also https://github.com/nchovy/kraken/issues/4 .
In case the repository location as specified below does not exist, delete the following repository entry,
acquire the kraken-pcap-pom file and execute
$ mvn install:install-file -DlocalRepositoryPath=kraken-workaround-repository \
-DcreateChecksum=true -Dpackaging=pom -Dfile=<PATH-TO_KRAKEN-PCAP-POM.pom> \
-DgroupId=org.krakenapps -DartifactId=kraken-pcap-pom -Dversion=1.0.0
As soon as the underlying issue is resolved upstream, this repository entry may be deleted.-->
<repository>
<id>krakenapps.org - workaround</id>
<releases>
<enabled>true</enabled>
<checksumPolicy>ignore</checksumPolicy>
</releases>
<snapshots>
<enabled>false</enabled>
</snapshots>
<url>file:///home/stefan/IdeaProjects/rubanetra/src/main/resources/kraken-workaround-repository</url>
</repository>
<repository>
<id>jboss-public-repository-group</id>
<name>JBoss Public Maven Repository Group</name>
<url>http://repository.jboss.org/nexus/content/groups/public/</url>
<layout>default</layout>
<releases>
<enabled>true</enabled>
<updatePolicy>always</updatePolicy>
</releases>
<snapshots>
<enabled>true</enabled>
<updatePolicy>always</updatePolicy>
</snapshots>
</repository>
<repository>
<id>central</id>
<name>Central Maven Repository</name>
<layout>default</layout>
<url>http://repo1.maven.org/maven2</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</repository>
<repository>
<id>clojars.org</id>
<name>Clojars Community Maven Repository</name>
<url>http://clojars.org/repo</url>
</repository>
</repositories>
<pluginRepositories>
<pluginRepository>
<id>jboss-public-repository-group</id>
<name>JBoss Public Maven Repository Group</name>
<url>http://repository.jboss.org/nexus/content/groups/public/</url>
<layout>default</layout>
</pluginRepository>
<pluginRepository>
<id>central</id>
<name>Central Maven Repository</name>
<layout>default</layout>
<url>http://repo1.maven.org/maven2</url>
<snapshots>
<enabled>true</enabled>
</snapshots>
</pluginRepository>
</pluginRepositories>
<dependencies>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>4.11</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>slf4j-api</artifactId>
<version>1.7.6</version>
</dependency>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>jcl-over-slf4j</artifactId>
<version>1.7.6</version>
</dependency>
<dependency>
<groupId>ch.qos.logback</groupId>
<artifactId>logback-classic</artifactId>
<version>1.1.1</version>
</dependency>
<dependency>
<groupId>commons-logging</groupId>
<artifactId>commons-logging</artifactId>
<version>1.1.3</version>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.5.3</version>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.dataformat</groupId>
<artifactId>jackson-dataformat-xml</artifactId>
<version>2.5.3</version>
</dependency>
<dependency>
<groupId>org.codehaus.woodstox</groupId>
<artifactId>woodstox-core-asl</artifactId>
<version>4.3.0</version>
</dependency>
<dependency>
<groupId>javax.mail</groupId>
<artifactId>mail</artifactId>
<version>1.4.7</version>
<exclusions>
<exclusion>
<artifactId>activation</artifactId>
<groupId>javax.activation</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-pcap</artifactId>
<version>1.7.1</version>
<exclusions>
<exclusion>
<artifactId>slf4j-simple</artifactId>
<groupId>org.slf4j</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-http-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-smtp-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>activation</artifactId>
<groupId>javax.activation</groupId>
</exclusion>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-ftp-decoder</artifactId>
<version>1.2.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-msn-decoder</artifactId>
<version>1.2.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-netbios-decoder</artifactId>
<version>1.0.0</version>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-pop3-decoder</artifactId>
<version>1.0.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-dhcp-decoder</artifactId>
<version>1.0.1</version>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-snmp-decoder</artifactId>
<version>1.1.0</version>
<exclusions>
<exclusion>
<artifactId>mail</artifactId>
<groupId>javax.mail</groupId>
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.krakenapps</groupId>
<artifactId>kraken-telnet-decoder</artifactId>
<version>1.0.0</version>
</dependency>
<dependency>
<groupId>jnetpcap</groupId>
<artifactId>jnetpcap</artifactId>
<version>1.4.r1425-1d</version>
</dependency>
<dependency>
<groupId>org.antlr</groupId>
<artifactId>antlr4-runtime</artifactId>
<version>4.5</version>
</dependency>
<dependency>
<groupId>org.drools</groupId>
<artifactId>drools-core</artifactId>
<version>6.1.0.Final</version>
</dependency>
<dependency>
<groupId>org.drools</groupId>
<artifactId>drools-compiler</artifactId>
<version>6.1.0.Final</version>
</dependency>
<dependency>
<groupId>org.kie</groupId>
<artifactId>kie-api</artifactId>
<version>6.1.0.Final</version>
</dependency>
<dependency>
<groupId>org.apache.httpcomponents</groupId>
<artifactId>httpclient</artifactId>
<version>4.3.3</version>
</dependency>
<dependency>
<groupId>commons-cli</groupId>
<artifactId>commons-cli</artifactId>
<version>1.2</version>
</dependency>
<dependency>
<groupId>org.apache.commons</groupId>
<artifactId>commons-csv</artifactId>
<version>1.0</version>
</dependency>
<dependency>
<groupId>dnsjava</groupId>
<artifactId>dnsjava</artifactId>
<version>2.1.7</version>
</dependency>
</dependencies>
<build>
<resources>
<resource>
<directory>src/main/resources</directory>
<filtering>true</filtering>
</resource>
</resources>
<plugins>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-compiler-plugin</artifactId>
<version>3.1</version>
<configuration>
<source>1.8</source>
<target>1.8</target>
<showWarnings>true</showWarnings>
<showDeprecation>true</showDeprecation>
<compilerArgument>-proc:none</compilerArgument>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-javadoc-plugin</artifactId>
<version>2.9.1</version>
<configuration>
<quiet>false</quiet>
<jarOutputDirectory>/home/stefan/IdeaProjects/rubanetra/target/archive</jarOutputDirectory>
<additionalparam>-Xdoclint:none</additionalparam>
</configuration>
<executions>
<execution>
<id>attach-javadocs</id>
<phase>prepare-package</phase>
<goals>
<goal>jar</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-surefire-plugin</artifactId>
<version>2.16</version>
<configuration>
<skip>true</skip>
<systemPropertyVariables>
<logDirectory>/home/stefan/IdeaProjects/rubanetra/target/logs</logDirectory>
<logLevel>DEBUG</logLevel>
</systemPropertyVariables>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-assembly-plugin</artifactId>
<version>2.4</version>
<executions>
<execution>
<phase>package</phase>
<goals>
<goal>single</goal>
</goals>
</execution>
</executions>
<configuration>
<descriptors>
<descriptor>src/main/assembly/distribution-zip.xml</descriptor>
<descriptor>src/main/assembly/package-zip.xml</descriptor>
</descriptors>
<tarLongFileMode>gnu</tarLongFileMode>
</configuration>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-jar-plugin</artifactId>
<version>2.4</version>
<configuration>
<outputDirectory>/home/stefan/IdeaProjects/rubanetra/target/archive</outputDirectory>
<archive>
<manifest>
<addClasspath>true</addClasspath>
<!-- Workaround for Maven bug #MJAR-156 (https://jira.codehaus.org/browse/MJAR-156) -->
<useUniqueVersions>false</useUniqueVersions>
<classpathPrefix>./lib/</classpathPrefix>
<addExtensions>false</addExtensions>
<mainClass>at.jku.fim.rubanetra.config.ConfigurationController</mainClass>
<addDefaultImplementationEntries>true</addDefaultImplementationEntries>
</manifest>
<manifestEntries>
<Class-Path>./conf/ /usr/lib/</Class-Path>
<Build-Java>1.8.0_45</Build-Java>
<Build-OS>Linux</Build-OS>
<Build-Arch>amd64</Build-Arch>
<License-Short-Name>GPLv3</License-Short-Name>
<License-Long-Name>GNU General Public License, Version 3</License-Long-Name>
<License-Url>https://gnu.org/licenses/gpl-3.0.txt</License-Url>
<License-Short-Header>This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
</License-Short-Header>
<License-Inception-Year>2013</License-Inception-Year>
<License-Recent-Years>2014</License-Recent-Years>
<Copyright-Owner>Stefan Swerk (stefan_rubanetra@swerk.priv.at)</Copyright-Owner>
<Issue-Management>http://gitlab.swerk.priv.at/stefan/rubanetra/issues</Issue-Management>
<Project-Home>http://gitlab.swerk.priv.at/stefan/rubanetra</Project-Home>
</manifestEntries>
</archive>
<excludes>
<exclude>**/*.properties</exclude>
<exclude>**/*.drl</exclude>
<exclude>**/*.xml</exclude>
<exclude>**/*.conf</exclude>
<exclude>kraken-workaround-repository/**</exclude>
<exclude>DefaultKnowledgeBase/**</exclude>
</excludes>
</configuration>
<executions>
<execution>
<phase>prepare-package</phase>
<goals>
<goal>jar</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-source-plugin</artifactId>
<version>2.2.1</version>
<configuration>
<includePom>true</includePom>
<outputDirectory>/home/stefan/IdeaProjects/rubanetra/target/archive</outputDirectory>
</configuration>
<executions>
<execution>
<id>attach-sources</id>
<phase>prepare-package</phase>
<goals>
<goal>jar-no-fork</goal>
</goals>
</execution>
<execution>
<id>attach-test-sources</id>
<phase>prepare-package</phase>
<goals>
<goal>test-jar-no-fork</goal>
</goals>
<configuration>
<excludes>
<exclude>**/captures/**</exclude>
</excludes>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>build-helper-maven-plugin</artifactId>
<version>1.8</version>
<executions>
<execution>
<phase>generate-sources</phase>
<goals>
<goal>add-source</goal>
</goals>
<configuration>
<sources>
<source>/home/stefan/IdeaProjects/rubanetra/target/generated-sources/antlr4</source>
</sources>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.antlr</groupId>
<artifactId>antlr4-maven-plugin</artifactId>
<version>4.5</version>
<executions>
<execution>
<id>antlr</id>
<phase>generate-sources</phase>
<goals>
<goal>antlr4</goal>
</goals>
<configuration>
<!-- This options is currently not required, since this plugin looks for ANTLR grammars
in the directory 'main/antlr4' anyway-->
<!--<sourceDirectory>/home/stefan/IdeaProjects/rubanetra/src/main/java</sourceDirectory> -->
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.kie</groupId>
<artifactId>kie-maven-plugin</artifactId>
<version>6.1.0.Final</version>
<extensions>true</extensions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-dependency-plugin</artifactId>
<version>2.8</version>
<executions>
<execution>
<id>copy-dependencies</id>
<phase>prepare-package</phase>
<goals>
<goal>copy-dependencies</goal>
</goals>
<configuration>
<outputDirectory>/home/stefan/IdeaProjects/rubanetra/target/lib</outputDirectory>
<overWriteReleases>false</overWriteReleases>
<overWriteSnapshots>false</overWriteSnapshots>
<overWriteIfNewer>true</overWriteIfNewer>
<useBaseVersion>true</useBaseVersion>
</configuration>
</execution>
<execution>
<id>unpack</id>
<phase>compile</phase>
<goals>
<goal>unpack</goal>
</goals>
<configuration>
<artifactItems>
<artifactItem>
<groupId>jnetpcap</groupId>
<artifactId>jnetpcap</artifactId>
<version>1.4.r1425-1d</version>
<type>jar</type>
<overWrite>false</overWrite>
<outputDirectory>/home/stefan/IdeaProjects/rubanetra/target/lib/libjnetpcap
</outputDirectory>
</artifactItem>
</artifactItems>
<includes>native/**</includes>
</configuration>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>license-maven-plugin</artifactId>
<version>1.6</version>
<configuration>
<licenseName>gpl_v3</licenseName>
<copyrightOwners>Stefan Swerk (stefan_rubanetra@swerk.priv.at)</copyrightOwners>
<useMissingFile>true</useMissingFile>
<useRepositoryMissingFiles>true</useRepositoryMissingFiles>
<licenseMerges>
<licenseMerge>The Apache Software License, Version 2.0|Apache 2</licenseMerge>
<licenseMerge>The Apache Software License, Version 2.0|Apache
License
</licenseMerge>
<licenseMerge>The Apache Software License, Version 2.0|Apache
License, Version 2.0
</licenseMerge>
</licenseMerges>
</configuration>
<executions>
<execution>
<id>add-third-party</id>
<goals>
<goal>add-third-party</goal>
</goals>
<phase>process-sources</phase>
</execution>
<!--<execution>-->
<!--<id>download-licenses</id>-->
<!--<goals>-->
<!--<goal>download-licenses</goal>-->
<!--</goals>-->
<!--<phase>process-sources</phase>-->
<!--</execution>-->
<execution>
<id>update-project-license</id>
<goals>
<goal>update-project-license</goal>
</goals>
<phase>process-sources</phase>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-install-plugin</artifactId>
<version>2.5.1</version>
<configuration>
<createChecksum>true</createChecksum>
</configuration>
</plugin>
<plugin>
<groupId>net.ju-n.maven.plugins</groupId>
<artifactId>checksum-maven-plugin</artifactId>
<version>1.2</version>
<executions>
<execution>
<goals>
<goal>artifacts</goal>
</goals>
</execution>
</executions>
<configuration>
<algorithms>
<algorithm>MD5</algorithm>
<algorithm>SHA-1</algorithm>
<algorithm>SHA-256</algorithm>
</algorithms>
</configuration>
</plugin>
<plugin>
<groupId>com.mycila</groupId>
<artifactId>license-maven-plugin</artifactId>
<version>2.6</version>
<configuration>
<header>src/license/gpl_v3/header.txt</header>
<properties>
<owner>Stefan Swerk</owner>
<year>2013</year>
<recentYears>2014</recentYears>
<currentYear>${maven.build.timestamp}</currentYear>
<email>stefan_rubanetra@swerk.priv.at</email>
</properties>
<useDefaultExcludes>true</useDefaultExcludes>
<mapping>
<drl>JAVADOC_STYLE</drl>
<g4>JAVADOC_STYLE</g4>
<conf>JAVADOC_STYLE</conf>
</mapping>
</configuration>
<executions>
<execution>
<id>license-basedir</id>
<phase>process-sources</phase>
<goals>
<goal>format</goal>
</goals>
<configuration>
<basedir>/home/stefan/IdeaProjects/rubanetra</basedir>
<excludes>
<exclude>**/README*</exclude>
<exclude>**/LICENSE*</exclude>
<exclude>src/license/gpl_v3/**</exclude>
<exclude>src/main/resources/kraken-workaround-repository/**</exclude>
<exclude>src/test/resources/captures/**</exclude>
</excludes>
<includes>
<include>pom.xml</include>
<include>src/**</include>
</includes>
</configuration>
</execution>
<execution>
<id>license-gen-src</id>
<phase>process-sources</phase>
<goals>
<goal>format</goal>
</goals>
<configuration>
<basedir>/home/stefan/IdeaProjects/rubanetra/target/generated-sources/antlr4</basedir>
<excludes>
<exclude>**/README*</exclude>
<exclude>**/LICENSE*</exclude>
<exclude>**/*.tokens</exclude>
</excludes>
</configuration>
</execution>
</executions>
</plugin>
</plugins>
</build>
</project>

View File

@ -0,0 +1,54 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<configuration>
<appender name="CONSOLE" class="ch.qos.logback.core.ConsoleAppender">
<Target>System.err</Target>
<encoder>
<pattern>%d{yyyy-MM-dd HH:mm:ss.SSS} %-5p - %m%n</pattern>
</encoder>
<filter class="ch.qos.logback.classic.filter.ThresholdFilter">
<level>info</level>
</filter>
</appender>
<appender name="FILE" class="ch.qos.logback.core.rolling.RollingFileAppender">
<!--See also http://logback.qos.ch/manual/appenders.html#RollingFileAppender-->
<Append>true</Append>
<File>./logs/rubanetra.log</File>
<encoder>
<pattern>%date %level [%thread] [%file:%line] - %msg%n</pattern>
</encoder>
<filter class="ch.qos.logback.classic.filter.ThresholdFilter">
<level>info</level>
</filter>
<rollingPolicy class="ch.qos.logback.core.rolling.FixedWindowRollingPolicy">
<maxIndex>5</maxIndex>
<FileNamePattern>./logs/rubanetra.log.%i</FileNamePattern>
</rollingPolicy>
<triggeringPolicy class="ch.qos.logback.core.rolling.SizeBasedTriggeringPolicy">
<MaxFileSize>10MB</MaxFileSize>
</triggeringPolicy>
</appender>
<root level="info">
<appender-ref ref="CONSOLE"/>
<!-- uncomment the following line to enable file based logging -->
<!--<appender-ref ref="FILE"/>-->
</root>
</configuration>

View File

@ -0,0 +1,471 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
/**
* This file serves as the Rubanetra configuration entry point and will be looked up by the main executable jar.
* Therefore this file must be either directly available via classpath entry, or the file-path has to be passed via
* command line argument (for further details refer to the README file).
*
* While this file must contain all configuration sections, i.e. 'general', 'protocols', 'input' and 'output'
* at once, one may prefer to split certain dynamically changing configuration sections into separate and therefore
* replaceable files. However, please note that the general section must reside in a statically known location to the
* Rubanetra executable and the paths to the dynamically changed files must be defined in the appropriate sections.
*
* Since all configuration files will be parsed by ANTLRv4, the corresponding grammar defining the exact syntax
* is available in the source archive, see 'src/main/antlr4/.../RubanetraSystemConfiguration.g4'.
*/
/**
* #########################
* # General Configuration #
* #########################
*/
general {
/**
* Defines the base directory containing the Drools knowledge-base configuration.
* Currently this directory must contain:
* - 'META-INF' as subdirectory, containing:
* ~ 'kmodule.xml', the Drools configuration file, i.e. 'META-INF/kmodule.xml'
* ~ the subsequent Apache Maven configuration structure, i.e.:
* + 'maven/at.jku.fim/rubanetra/' sub-directories
* + 'maven/at.jku.fim/rubanetra/pom.xml' the project's Maven configuration file
* + 'maven/at.jku.fim/rubanetra/pom.properties' Maven-generated properties
*
* If this setting is changed, the default 'META-INF' directory should be removed either from the classpath
* or directly from the configuration directory (since this directory is by default in the classpath).
*
* Default value "./conf", this setting is mandatory.
*/
drools_configuration_directory = "./conf";
/**
* Defines the name of the Drools knowledge base to use for the reasoning process.
* This knowledge base name must be listed in the Drools knowledge base descriptor file 'kmodule.xml'.
* If this setting is not specified the default knowledge base as specified in the Drools descriptor file will
* be compiled and used.
*
* Default value "DefaultKnowledgeBase", this setting is optional.
*/
drools_base_model_name = "DefaultKnowledgeBase";
/**
* Defines the name of the Drools session to use for the reasoning process.
* This session name must be listed in the Drools knowledge base descriptor file 'kmodule.xml' as session entry
* under the specified (or the default) 'drools_base_model_name'.
* If this setting is not specified the default session name as specified in the Drools descriptor file will be
* used instead.
*
* Default value "DefaultSession", this setting is optional.
*/
drools_session_model_name = "DefaultSession";
};
/**
* ##########################
* # Protocol Configuration #
* # (Application Layer) #
* ##########################
*
* This section should be filled with application layer specific protocol settings, i.e. underlying lower layer
* protocol parser bindings and potential port filters, if applicable. The listed application layer parser settings
* also serve as a vital tool of directing the output generation engine. By default, any parser output below the
* application layer will be suppressed due to verboseness, however, this behaviour may be overturned by appropriate
* rule definitions inside the used Knowledge Base. For further information on how to achieve this, please refer to
* the documentation of Activity#setExcludedFromOutput(boolean).
* Additional Notes: An application layer parser will only produce output if all of the following conditions are met:
* - A protocol decoder pipeline has been setup, including all lower layer protocols,
* e.g.: L2 -> L3 -> L4 -> <application_layer_parser>
* - The destination port restriction may not be 'None' and has to include the relevant port(s).
* - The PCAP file actually contains relevant packets applicable to <application_layer_parser> and defined port(s).
*
* Furthermore, it is recommended to specify one protocol identifier per application layer protocol parser, however,
* remember that there must be a 1:1 mapping between a transport layer parser and an application layer parser, therefore
* the following example will not work:
* [HTTPandDNSoverTCP]:
* port = ALL;
* protocol_binding = Ethernet -> Ipv4;
* protocol_binding = Ipv4 -> Tcp;
* protocol_binding = Tcp -> Http;
* protocol_binding = Tcp -> Dns;
*
* In general, the following implementation constraints may be observed:
* - 1:n mapping between Layer1 (Pcap) and Layer2 (link) parsers
* - n:m mapping between Layer2 (link) and Layer3 (IP), Layer3 and Layer4 (transport) parsers
* - 1:1 mapping between Layer4 (transport) and application layer parsers
*
* On the other hand, if extremely fine grained control over the actual PCAP data is required, see the BPF setting
* in the 'input' configuration section.
*
* If the Drools knowledge base contains rules that require certain protocol parsers, those parsers must be referenced
* at least one time in this configuration section. However, rule based parsers must be configured entirely in the
* Drools rule files.
*/
protocols {
/**
* If a 'protocol_configuration_file' setting is specified all remaining protocol specific settings will be looked
* up in the referenced file. This file must exist and be readable for the invoking process.
* Note, however, that there will be no explicit checks against configuration file dereferencing chains, i.e.
* it should be ensured that there is no 'protocol_configuration_file' setting in the referenced file again.
* The referenced file must contain a "protocols {};" section containing the entire protocol specific configuration.
*
* This setting is optional, but if it is specified all remaining protocol specific settings in the
* main configuration file will be ignored.
*/
//protocol_configuration_file = "/path/to/protocol.conf";
/**
* An unique protocol id should be defined for each application layer protocol parser that should be used, i.e.
* by default the name of an application layer protocol should suffice.
* Syntax: '[ Protocol_ID ]:', where Protocol_ID represents an unique protocol identifier conforming
* to ([a-zA-Z]+ DIGIT*)+.
* A number of protocol specific settings may be specified subsequently.
* This setting may be repeated multiple times for configuring different protocol parsers.
*
* Constraints: It is currently not defined what will happen in the case of multiple different protocol ids that
* contain exactly the same protocol bindings. Consider for instance:
* [HTTP]: ... as below ...
* [HTTP1]: ... as [HTTP] ...
*
* The rule engine will probably receive double notifications for all HTTP related events in this case and this
* could lead to severe issues during the reasoning process and the corresponding output (two identical frame numbers
* for two different parser instances).
*/
[HTTP]:
/**
* The strategy to use for mapping Kraken's transport layer parsers to the application layer parsers.
* Currently only the destination port strategy has been implemented, i.e. an application layer parser receives
* packets that match the specified destination port number(s) defined by the "port" setting.
*
* Default value "destination_port", this setting is required.
*/
transport_layer_mapping_strategy = destination_port;
/**
* Restricts the transport layer parser (UDP/TCP) to the specified destination ports and/or port-ranges.
* A similar result could be achieved globally (and more efficiently) via the input BPF filter setting.
*
* Default value "80", this setting is required if the mapping strategy used is "destination_port".
* Exemplary values:
* - ALL or ANY, i.e. do not apply any port based restriction to the parser (matches all ports)
* - NONE, i.e. disable this protocol since no ports will be allowed (matches no ports)
* - 80, i.e. match only packets with destination port 80, any valid port numbers are allowed
* - 80,8080,8081 matches packets with destination port 80 or 8080 or 8081
* - 80,8080-8088 matches packets with destination port 80 or the destination port range 8080-8088
* Warning: A setting of ALL should be used with care, as it may cause a library decoder to crash and
* prevent the continued parsing process of valid HTTP data.
*/
port = 80;
/**
* The "protocol_binding" setting binds an available protocol parser to another protocol parser that is capable
* of decoding the previously "unwrapped/decoded" content. Usually this setting should be used to define
* the network layer decoding pipeline. The lowest network layer parser available is currently a
* layer 2 parser, e.g. ethernet. Layer 1 (basically PCAP-entries) may be implicitly assumed to be always
* provided in decoded form.
* A network layer protocol parser is always identified by the unique protocol identifier that this parser is
* advertising as capable of decoding. Unless custom protocol parsers have been registered, the following parsers
* should be available:
* Ethernet, Arp,
* Ipv4, Ipv6, Icmpv4, Icmpv6,
* Tcp, Udp,
* Telnet, Snmp, Netbios, Dhcp, Pop3, Msn, Ftp, Dns, Smtp, Http
*
* This setting is not required, however, if no bindings are specified no parsers will be setup.
* This setting must be specified multiple times in case of different bindings for the same higher layer protocol
* parser, i.e. the entire network layer stack below the highest defined protocol parser layer must be bound.
* For instance, if the highest network layer protocol specified is TCP (layer 4), a layer 2 parser
* must be bound to layer 3 and a layer 3 parser must be bound to tcp. If the parsers are incompatible or the
* pipeline is not complete, the parser of the highest layer will not receive any decoded data.
* Multiple lower layer parsers leading to a common higher layer parser are nevertheless allowed, e.g.
* ethernet -> ipv4, ethernet -> ipv6,
* ipv4 -> tcp, ipv6 -> tcp,
* tcp -> http
*
* In general, the following implementation constraints may be observed:
* - 1:n mapping between Layer1 (Pcap) and Layer2 (link) parsers
* - n:m mapping between Layer2 (link) and Layer3 (IP), Layer3 and Layer4 (transport) parsers
* - 1:1 mapping between Layer4 (transport) and application layer parsers
*
* Note: Not all theoretically possible bindings are implemented, e.g. a binding from ethernet -> http will
* cause a runtime exception because the Http-parser handles decoded TCP/IP-data only.
* It is also discouraged to bind a higher layer parser to a lower layer, e.g. http -> tcp, since this will
* depend solely on the individual parser implementation on how this case is handled and should therefore
* be avoided.
*/
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Http;
/**
* Example of a possible DNS protocol parser pipeline setup. Note that larger DNS messages are sent via
* the TCP transport layer instead of UDP. This pipeline is capable of handling Ethernet, IPv4/IPv6, UDP/TCP and
* the DNS parsers. however, the TCP -> DNS parser is currently considered experimental.
*/
[DNS]:
transport_layer_mapping_strategy = destination_port;
port = Any;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv4 -> Udp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Ipv6 -> Udp;
protocol_binding = Tcp -> Dns;
protocol_binding = Udp -> Dns;
/**
* Exemplary SNMP v1/v2 Pipeline configuration.
* (default: disabled)
*/
[SNMPv1v2]:
transport_layer_mapping_strategy = destination_port;
port = None;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Udp;
protocol_binding = Ipv6 -> Udp;
protocol_binding = Udp -> Snmp;
/**
* Exemplary DHCP Pipeline configuration.
* (default: enabled for port 67,68)
*/
[DHCP]:
transport_layer_mapping_strategy = destination_port;
port = 67,68;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Udp;
protocol_binding = Ipv6 -> Udp;
protocol_binding = Udp -> Dhcp;
/**
* Exemplary Netbios Pipeline configuration.
* (default: disabled)
*/
[Netbios]:
transport_layer_mapping_strategy = destination_port;
port = None;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Udp;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Udp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Udp -> Netbios;
protocol_binding = Tcp -> Netbios;
/**
* Exemplary Msn Pipeline configuration.
* (default: disabled)
*/
[MSN]:
transport_layer_mapping_strategy = destination_port;
port = None;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Msn;
/**
* Exemplary Ftp Pipeline configuration.
* (default: disabled)
*/
[FTP]:
transport_layer_mapping_strategy = destination_port;
port = None;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Ftp;
/**
* Exemplary Pop3 Pipeline configuration.
* (default: enabled for ports 110, 995)
*/
[Pop3]:
transport_layer_mapping_strategy = destination_port;
port = 110, 995;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Pop3;
/**
* Exemplary Telnet Pipeline configuration.
* (default: enabled for port 23)
*/
[Telnet]:
transport_layer_mapping_strategy = destination_port;
port = 23;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Telnet;
/**
* Exemplary Smtp Pipeline configuration.
* (default: enabled for ports 25, 587, 465)
*/
[SMTP]:
transport_layer_mapping_strategy = destination_port;
port = 25, 587, 465;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Tcp;
protocol_binding = Ipv6 -> Tcp;
protocol_binding = Tcp -> Smtp;
/**
* Exemplary ICMPv4/v6 Pipeline configuration.
* (default: enabled, a port based restriction is not possible)
*/
[ICMP]:
transport_layer_mapping_strategy = destination_port;
port = None;
protocol_binding = Ethernet -> Ipv4;
protocol_binding = Ethernet -> Ipv6;
protocol_binding = Ipv4 -> Icmpv4;
protocol_binding = Ipv6 -> Icmpv6;
};
/**
* #######################
* # Input Configuration #
* #######################
*/
input {
/**
* If a 'input_configuration_file' setting is specified, all remaining input specific settings will be looked
* up in the referenced file. This file must exist and be readable for the invoking process.
* Note, however, that there will be no explicit checks against configuration file dereferencing chains, i.e.
* it should be ensured that there is no 'input_configuration_file' setting in the referenced file again.
* The referenced file must contain a "input {};" section containing the entire input specific configuration.
*
* This setting is optional, but if it is specified all remaining input specific settings in the
* main configuration file will be ignored.
*/
//input_configuration_file = "path/to/input.conf";
/**
* The path to the input files to parse. All specified files must adhere to the format specified by
* the "input_format" setting.
*
* This setting is required, syntax (curly braces indicate arbitrary repetitions and must not be included):
* input_file = "/path/to/file1" {, "/path/to/another/file"};
* This setting may be specified multiple times, all occurrences will be processed.
*
* Notes: Input files that were specified by using the command line interface will not replace the input_file
* specifications of this section, i.e. all sources will be combined and processed.
*/
//input_file = "path/to/input/file";
/**
* The format of the specified input files.
* Currently only a pcap parser has been implemented.
*
* This setting is required.
*/
input_format = pcap;
/**
* A Berkeley Packet Filter string to facilitate an efficient way to filter the entire PCAP-Stream before it is
* passed to the parsers. This string will be compiled and applied by the native PCAP-decoding library by the means
* of JNetPcap.
*
* This setting is optional.
* Syntax definition: <https://www.wireshark.org/docs/man-pages/pcap-filter.html>.
*/
bpf_filter = "";
/**
* The Berkeley Packet Filter optimization flag.
* This boolean value will be passed along the bpf_netmask and the bpf_filter string to the native PCAP decoding
* library and indicates whether or not the bpf_filter string should be optimized by the compiler.
*
* This setting is optional, default value = false.
*/
bpf_optimize = false;
/**
* If this setting is set to true, all specified input files will be opened and the first content entry will be
* parsed respectively, i.e. the timestamp of the first entry in each file will be analyzed and compared.
* The File-Handler will then try to sort all files chronologically according to this timestamp, so that
* the "real" parsing process provides all packet capture entries in the original order (the oldest entry will
* be parsed first).
* Because this process relies only on the first timestamp of each file, it cannot handle overlapping
* time-intervals.
*
* This setting is optional, default value: false
* Possible values:
* - false, i.e. parse in the order the files were specified in the configuration itself.
* - true, try to sort all files chronologically according to the timestamp of their first network capture entry.
*/
sort_by_first_timestamp = false;
};
/**
* ########################
* # Output Configuration #
* ########################
*/
output {
/**
* If a 'output_configuration_file' setting is specified, all remaining output specific settings will be looked
* up in the referenced file. This file must exist and be readable for the invoking process.
* Note, however, that there will be no explicit checks against configuration file dereferencing chains, i.e.
* it should be ensured that there is no 'output_configuration_file' setting in the referenced file again.
* The referenced file must contain a "output {};" section containing the entire output specific configuration.
*
* This setting is optional, but if it is specified all remaining output specific settings in the
* main configuration file will be ignored.
*/
//output_configuration_file = "path/to/output.conf";
/**
* The file descriptor to use for writing the derived information to. The information will be transformed
* according to the specified output_format before it is written to the output-stream.
*
* This setting is required, default value: stdout.
* The file or stream must be writable by the invoking process.
* Possible values:
* - STDOUT, the standard output stream
* - "path/to/a/file", a file-path
*/
output_file = stdout;
/**
* The output format that is used to transform the derived information to before writing it to "output_file".
*
* This setting is required, default value: plaso
* Possible values:
* - plaso, a format that can be parsed by the provided Plaso specific parser (currently XML)
* - xml, however, without a schema definition
* - json
* - csv, generic/limited comma separated value content will be produced
* If extended output for certain activities is desired, a custom CSV schema has to be provided first.
* - nop, does not write anything to "output_file".
* - callback, as 'nop', mainly interesting for developers/testing.
*/
output_format = plaso;
};

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

View File

@ -0,0 +1,15 @@
This file is part of ${project.name}.
Copyright (C) ${project.inceptionYear},${recentYears} ${owner} (${email})
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.

84
src/license/licenses.xml Normal file
View File

@ -0,0 +1,84 @@
<?xml version="1.0"?>
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<licenseSummary xmlns="http://mojo.codehaus.org/">
<dependencies>
<dependency>
<groupId>org.slf4j</groupId>
<artifactId>slf4j-simple</artifactId>
<licenses>
<license>
<name>The MIT License</name>
<url>http://www.slf4j.org/license.html</url>
</license>
</licenses>
</dependency>
<dependency>
<groupId>commons-codec</groupId>
<artifactId>commons-codec</artifactId>
<licenses>
<license>
<name>The Apache Software License, Version 2.0</name>
<url>https://www.apache.org/licenses/LICENSE-2.0.txt</url>
</license>
</licenses>
</dependency>
<dependency>
<groupId>dnsjava</groupId>
<artifactId>dnsjava</artifactId>
<licenses>
<license>
<name>The BSD License</name>
<url>http://www.dnsjava.org/dnsjava-current/README</url>
</license>
</licenses>
</dependency>
<dependency>
<groupId>xpp3</groupId>
<artifactId>xpp3_min</artifactId>
<licenses>
<license>
<name>Indiana University Extreme! Lab Software License, version 1.1.1</name>
<url>http://www.bearcave.com/software/java/xml/xmlpull_license.html</url>
</license>
</licenses>
</dependency>
<dependency>
<groupId>org.apache.httpcomponents</groupId>
<artifactId>httpclient</artifactId>
<licenses>
<license>
<name>The Apache Software License, Version 2.0</name>
<url>https://www.apache.org/licenses/LICENSE-2.0.txt</url>
</license>
</licenses>
</dependency>
<dependency>
<groupId>org.apache.httpcomponents</groupId>
<artifactId>httpcore</artifactId>
<licenses>
<license>
<name>The Apache Software License, Version 2.0</name>
<url>https://www.apache.org/licenses/LICENSE-2.0.txt</url>
</license>
</licenses>
</dependency>
</dependencies>
</licenseSummary>

View File

@ -0,0 +1,183 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
grammar RubanetraSystemConfiguration;
/**
* This file defines the EBNF grammar of the default system configuration
* using the ANTLR v4 syntax (see http://www.antlr.org/wiki/display/ANTLR4/ANTLR+4+Documentation).
* The general settings '*_configuration_file' may be used
* to indicate the location of the corresponding configuration files, however
* the main configuration file path containing the 'general' section
* must be known by the system a priori at a fixed location (usually the classpath) or it has to be passed as
* command line parameter during runtime.
* The recommended setup is to use two configuration files, i.e.
* one file containing all static configuration blocks ('general', 'protocols')
* and another file containing the dynamic runtime configuration ('input', 'output').
* The system configuration itself may be split into four different files according
* to the main settings categories 'general', 'protocols', 'input/output' (a coarser split into a single, two or three
* file(s) is possible as well).
*
* The 'system' node serves as grammar entry point and consists of a mandatory 'general'
* configuration section, followed by the remaining configurations optionally within the
* same file. However, this does not implicate that the protocol/library/runtime configurations
* are optional in general.
**/
system : (generalConfig|inputConfig|outputConfig|protocolConfig)* ;
/**
* Although the general configuration contains a predefined number of settings,
* future extensions may lead to a different set of settings, therefore no semantic
* restrictions will be laid upon the parser at the top level nodes.
**/
generalConfig : 'general' '{' (generalSetting)* '}' ';' ;
protocolConfig : 'protocols' '{' (protocolConfigurationFileSetting | (protocolSetting)*) '}' ';' ;
inputConfig : 'input' '{' (inputConfigurationFileSetting | (inputSetting)*) '}' ';' ;
outputConfig : 'output' '{' (outputConfigurationFileSetting | (outputSetting)*) '}' ';' ;
/**
* ##################################
* # General Setting Specification #
* ##################################
**/
generalSetting : ( 'drools_base_model_name' '=' droolsBaseModelName // optional, the name of the knowledge base to use (defined in 'kmodule.xml')
| 'drools_session_model_name' '=' droolsSessionModelName // optional, the name of the session to use (defined in 'kmodule.xml')
| 'drools_configuration_directory' '=' droolsConfigurationFile // required, path of a separate file containing the Drools knowledge base configuration ('kmodule.xml')
) ';' ;
droolsBaseModelName : STRING ;
droolsSessionModelName : STRING ;
droolsConfigurationFile : filePath ;
// End of General Setting Specification
/**
* ###################################
* # Protocol Setting Specification #
* ###################################
**/
protocolConfigurationFileSetting : 'protocol_configuration_file' '=' filePath ;
protocolSetting : (protocolHeader (portSpecification|protocolBinding|transportLayerMappingSetting)*) ;
protocolHeader : '[' protocolId ']' ':' ; // every protocol parser configuration section has an unique identifier
portSpecification : 'port' '=' ( ALL // matches all network ports [0;2^16-1]
| NONE // matches no ports (i.e. another way to disable a protocol)
| multiplePorts // matches either one or several single ports or port ranges
) ';' ;
multiplePorts : portRange (',' portRange)* ;
portRange : singlePort ('-' singlePort)? ;
protocolBinding : 'protocol_binding' '=' protocolId BIND_OP protocolId ';';
transportLayerMappingSetting : 'transport_layer_mapping_strategy' '=' transportLayerMappingStrategy ';' ;
transportLayerMappingStrategy : (DESTINATION_PORT) ;
// End of Protocol Setting Specification
/**
* ###########################################
* # Dynamic Runtime Setting Specification #
* ###########################################
* The following settings will be used to adjust the concrete runtime behaviour of the system,
* i.e. a set of one or multiple PCAP input files, a set of predefined protocols (see Protocol Setting Specification),
* a set of rules to enable.
**/
inputConfigurationFileSetting : 'input_configuration_file' '=' filePath ';' ; // optional, path of a separate file containing the I/O configuration
inputSetting : ( 'input_file' '=' inputSpecification // required, list of network capture input files
| 'input_format' '=' inputFormat // required, currently only PCAP (all format versions supported by the utilized libpcap library)
| 'bpf_filter' '=' bpfFilterString // optional, String representing a Berkeley Packet Filter (BPF) expression - a syntax check will not be performed
| 'bpf_netmask' '=' bpfNetmask // optional, integer representing a Berkeley Packet Filter (BPF) netmask
| 'bpf_optimize' '=' bpfOptimize // optional, boolean representing a Berkeley Packet Filter (BPF) optimization flag
| 'sort_by_first_timestamp' '=' sortByFirstTimestamp // optional, boolean flag indicating whether or not to sort according to the first timestamp of the PCAP entry
) ';' ;
outputConfigurationFileSetting : 'output_configuration_file' '=' filePath ';'; // optional, path of a separate file containing the I/O configuration
outputSetting : ( 'output_file' '=' outputSpecification // required, content output stream
| 'output_format' '=' outputFormat // plaso parser or general csv format
) ';' ;
inputSpecification : filePath (',' filePath)* ;
inputFormat : (PCAP) ;
bpfFilterString : STRING ;
bpfNetmask : INT ;
bpfOptimize : (TRUE|FALSE) ;
sortByFirstTimestamp : (TRUE|FALSE) ;
outputSpecification : (STDOUT|filePath) ;
outputFormat : (PLASO|CSV|NOP) ;
// End of Runtime Setting Specification
regexFlag : // see docs.oracle.com/javase/7/docs/api/java/util/regex/Pattern.html#UNIX_LINES
CASE_INSENSITIVE | MULTILINE | DOTALL | UNICODE_CASE | CANON_EQ
| UNIX_LINES | LITERAL | UNICODE_CHARACTER_CLASS | COMMENTS | NONE ;
ipv6 : // loosely based on RFC 5954, see http://tools.ietf.org/html/rfc5954, semantic check (int range) will be performed after parsing
( INT ':' INT ':' INT ':' INT ':' INT ':' INT ':' optIPv6Trailer
| '::' INT ':' INT ':' INT ':' INT ':' INT ':' optIPv6Trailer
| INT? '::' INT ':' INT ':' INT ':' INT ':' optIPv6Trailer
| ((INT ':' )? INT)? '::' INT ':' INT ':' INT ':' optIPv6Trailer
| ((INT ':' )? (INT ':' )? INT)? '::' INT ':' INT ':' optIPv6Trailer
| ((INT ':' )? (INT ':' )? (INT ':' )? INT)? '::' INT ':' optIPv6Trailer
| ((INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? INT)? '::' optIPv6Trailer
| ((INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? INT)? '::' INT
| ((INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? (INT ':' )? INT)? '::'
)
;
optIPv6Trailer : ( INT ':' INT) | ipv4 ;
ipv4 : INT '.' INT '.' INT '.' INT ; // Match an IPv4 address, e.g. 127.0.0.1
protocolId : ID ;
singlePort : INT ;
filePath : STRING ;
DEBUG : [Dd][Ee][Bb][Uu][Gg] ;
WARNING : [Ww][Aa][Rr][Nn][Ii][Nn][Gg] ;
INFO : [Ii][Nn][Ff][Oo] ;
DISABLED : [Dd][Ii][Ss][Aa][Bb][Ll][Ee][Dd] ;
PLASO : [Pp][Ll][Aa][Ss][Oo] ;
PCAP : [Pp][Cc][Aa][Pp] ;
DEFAULT : [Dd][Ee][Ff][Aa][Uu][Ll][Tt] ;
DESTINATION_PORT: [Dd][Ee][Ss][Tt][Ii][Nn][Aa][Tt][Ii][Oo][Nn]'_'[Pp][Oo][Rr][Tt] ;
CSV : [Cc][Ss][Vv] ;
CUSTOM : [Cc][Uu][Ss][Tt][Oo][Mm] ;
TRUE : ([Tt][Rr][Uu][Ee]) ;
FALSE : ([Ff][Aa][Ll][Ss][Ee]) ;
BIND_OP : ([Tt][Oo]) | '->' ;
ALL : ([Aa][Ll][Ll]) | ([Aa][Nn][Yy]) ;
NONE : [Nn][Oo][Nn][Ee] ;
NOP : [Nn][Oo][Pp] ;
STDOUT : ([Ss][Tt][Dd][Oo][Uu][Tt]) ;
/**
* Possible Java regular expression flags
* See docs.oracle.com/javase/7/docs/api/java/util/regex/Pattern.html#UNIX_LINES
**/
CASE_INSENSITIVE : [Cc][Aa][Ss][Ee][_][Ii][Nn][Ss][Ee][Nn][Ss][Ii][Tt][Ii][Vv][Ee] ;
MULTILINE : [Mm][Uu][Ll][Tt][Ii][Ll][Ii][Nn][Ee];
DOTALL : [Dd][Oo][Tt][Aa][Ll][Ll] ;
UNICODE_CASE : [Uu][Nn][Ii][Cc][Oo][Dd][Ee][_][Cc][Aa][Ss][Ee] ;
CANON_EQ : [Cc][Aa][Nn][Oo][Nn][_][Ee][Qq] ;
UNIX_LINES : [Uu][Nn][Ii][Xx][_][Ll][Ii][Nn][Ee][Ss] ;
LITERAL : [Ll][Ii][Tt][Ee][Rr][Aa][Ll] ;
UNICODE_CHARACTER_CLASS : [Uu][Nn][Ii][Cc][Oo][Dd][Ee][_][Cc][Hh][Aa][Rr][Aa][Cc][Tt][Ee][Rr][_][Cc][Ll][Aa][Ss][Ss] ;
COMMENTS : [Cc][Oo][Mm][Mm][Ee][Nn][Tt][Ss] ;
fragment DIGIT : [0-9] ;
ID : ([a-zA-Z]+ DIGIT*)+ ; // match lower-case and upper-case identifiers
INT : DIGIT+ ; // match natural, positive numbers including 0
STRING : '"' ('\\"'|.)*? '"' ; // match any characters between double quotes, including escaped '"'
LINE_COMMENT : ('//'|'#') .*? '\r'? '\n' -> skip ; // match line comments
COMMENT : '/*' .*? '*/' -> skip ; // match "/*" multiline comment "*/"
WS : [ \t\r\n]+ -> skip ; // skip spaces, tabs, newlines

View File

@ -0,0 +1,96 @@
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<assembly xmlns="http://maven.apache.org/plugins/maven-assembly-plugin/assembly/1.1.2"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/plugins/maven-assembly-plugin/assembly/1.1.2 http://maven.apache.org/xsd/assembly-1.1.2.xsd">
<id>distribution</id>
<baseDirectory>${project.build.finalName}-distribution</baseDirectory>
<formats>
<format>zip</format>
</formats>
<fileSets>
<fileSet>
<directory>${project.basedir}</directory>
<outputDirectory>/</outputDirectory>
<includes>
<include>README*</include>
<include>LICENSE*</include>
<include>NOTICE*</include>
</includes>
<filtered>true</filtered>
</fileSet>
<fileSet>
<directory>${archive.output.directory}</directory>
<outputDirectory>/</outputDirectory>
<includes>
<include>*.jar</include>
</includes>
</fileSet>
<fileSet>
<directory>${project.build.directory}/lib</directory>
<outputDirectory>lib</outputDirectory>
</fileSet>
<fileSet>
<directory>${project.build.directory}/${jnetpcap.native.lib.directory}/native</directory>
<outputDirectory>lib/${jnetpcap.native.lib.directory}</outputDirectory>
</fileSet>
<fileSet>
<directory>${project.build.directory}/generated-sources/license</directory>
<outputDirectory>/</outputDirectory>
</fileSet>
<fileSet>
<directory>${project.build.directory}/generated-resources/licenses</directory>
<outputDirectory>lib/licenses</outputDirectory>
</fileSet>
<fileSet>
<directory>${project.build.directory}/generated-resources</directory>
<outputDirectory>lib</outputDirectory>
<includes>
<include>licenses.xml</include>
</includes>
</fileSet>
<fileSet>
<directory>src/main/resources</directory>
<outputDirectory>conf</outputDirectory>
<includes>
<include>DefaultKnowledgeBase/**</include>
<include>META-INF/kmodule.xml</include>
<include>*.conf</include>
<include>*.properties</include>
<include>*.xml</include>
</includes>
<filtered>true</filtered>
</fileSet>
</fileSets>
<files>
<file>
<source>pom.xml</source>
<outputDirectory>conf/META-INF/maven/${project.groupId}/${project.artifactId}</outputDirectory>
<filtered>true</filtered>
</file>
<file>
<source>${project.build.directory}/maven-archiver/pom.properties</source>
<outputDirectory>conf/META-INF/maven/${project.groupId}/${project.artifactId}</outputDirectory>
<filtered>true</filtered>
</file>
</files>
</assembly>

View File

@ -0,0 +1,68 @@
<!--
This file is part of Rubanetra.
Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
-->
<assembly xmlns="http://maven.apache.org/plugins/maven-assembly-plugin/assembly/1.1.2"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/plugins/maven-assembly-plugin/assembly/1.1.2 http://maven.apache.org/xsd/assembly-1.1.2.xsd">
<id>package</id>
<baseDirectory>${project.build.finalName}-package</baseDirectory>
<formats>
<!--<format>tar.gz</format>-->
<!--<format>tar.bz2</format>-->
<format>zip</format>
</formats>
<fileSets>
<fileSet>
<directory>${project.basedir}</directory>
<includes>
<include>README*</include>
<include>NOTICE*</include>
</includes>
<useDefaultExcludes>true</useDefaultExcludes>
<filtered>true</filtered>
</fileSet>
<fileSet>
<directory>${project.basedir}</directory>
<includes>
<include>pom.xml</include>
</includes>
<filtered>false</filtered>
</fileSet>
<fileSet>
<directory>${project.basedir}/src/main</directory>
</fileSet>
<fileSet>
<directory>${project.basedir}/src/license</directory>
</fileSet>
<fileSet>
<directory>${project.build.directory}/generated-sources/license</directory>
<outputDirectory>/</outputDirectory>
</fileSet>
<fileSet>
<directory>${project.basedir}/src</directory>
<outputDirectory>/src</outputDirectory>
<useDefaultExcludes>true</useDefaultExcludes>
<excludes>
<exclude>**/*.log</exclude>
<exclude>**/${project.build.directory}/**</exclude>
<exclude>**/test/**</exclude>
</excludes>
</fileSet>
</fileSets>
</assembly>

View File

@ -0,0 +1,638 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config;
import at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration;
import at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBaseListenerImpl;
import at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBuilder;
import at.jku.fim.rubanetra.drools.DroolsKrakenProtocolHandler;
import org.antlr.v4.runtime.tree.ParseTreeWalker;
import org.apache.commons.cli.*;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import java.io.File;
import java.io.IOException;
import java.io.OutputStream;
import java.net.URISyntaxException;
import java.net.URL;
import java.nio.file.Paths;
import java.util.Enumeration;
import java.util.LinkedList;
import java.util.jar.Attributes;
import java.util.jar.Manifest;
/**
* This class serves as the projects main entry point, i.e. it contains a main-method and provides
* a basic command line interface. However, it may also serve as basic configuration initializer for use by other
* classes.
* <p>
* The main method of this class relies on the fact that it has been executed and loaded from within a runnable
* jar archive containing a manifest file consisting of basic project information.
* By default, i.e. without providing any command line arguments, the main configuration will be looked up at the
* following locations:
* <ul>
* <li>File named "rubanetra.conf" in the classpath and as a relative path</li>
* <li>"./conf/rubanetra.conf" in the classpath and as relative path</li>
* <li>Value of environment variable "RUBANETRA_SYSTEM_CONF_FILE" interpreted as file path.</li>
* </ul>
* <p>
* If the file could not be located successfully an exception will be thrown.
* Alternatively, the main configuration file path may be provided as command line argument using
* the switch '-c' or '--configuration-file'.
* <p>
* During the initialization procedure the ANTLR configuration parser will be invoked. Any encountered syntax errors
* will be printed to the standard error stream, however, unless any critical errors during the setup process
* occurred the application will continue running.
* <p>
* After completing the initialization procedure the control over the program flow will be returned
* to the caller in the main method, who in turn is able to retrieve the parsed and validated @{RubanetraSystemConfiguration}.
* By default, invoking the start-method
* of this class will initialize a default @{DroolsKrakenProtocolHandler} which effectively passes all PCAP-entries
* to the Kraken protocol decoding pipeline and ultimately to the Drools rule engine.
*
* @see at.jku.fim.rubanetra.drools.DroolsKrakenProtocolHandler
* @see at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBuilder
* @see at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration
*/
public class ConfigurationController {
public static final String defaultMainConfigName = "rubanetra.conf";
public static final String defaultMainConfigPath = "./conf/" + defaultMainConfigName;
public static final String defaultMainConfigEnvVar = "RUBANETRA_SYSTEM_CONF_FILE";
private static final Logger log = LoggerFactory.getLogger(ConfigurationController.class);
private static final Option helpOption = new Option("h", "help", false, "print the option overview message");
private static final Option versionOption = new Option("v", "version", false, "print the version information");
private static final Option mainConfigFileOption = new Option("c", "configuration-file", true, "path to the main configuration file");
private static final Option inputFiles = new Option("i", "input-files", true, String.format("pcap input files, delimited by '%s' (complements config file)", File.pathSeparatorChar));
private static final Option outputFile = new Option("o", "output-file", true, "path to the output file (contents will be overridden)");
private static final Option outputType = new Option("t", "output-type", true, "output type/format of the generated content (PLASO, CSV, JSON, XML or NOP)");
private final RubanetraSystemConfigurationBuilder systemConfigBuilder;
private RubanetraSystemConfiguration systemConfiguration;
private final LinkedList<String> inputFilePaths = new LinkedList<>();
private String outputFilePath;
private String outputFormat;
/**
* Creates a new instance of itself and a {@link at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBuilder}
*/
public ConfigurationController() {
systemConfigBuilder = RubanetraSystemConfigurationBuilder.create();
}
/**
* @return the default command line options, i.e. help (h), version (v), configuration-file (c), input-files (i),
* output-file (o), output-type (t)
*/
public static Options createDefaultOptions() {
inputFiles.setArgs(Option.UNLIMITED_VALUES);
inputFiles.setValueSeparator(File.pathSeparatorChar);
Options options = new Options();
options.addOption(helpOption);
options.addOption(versionOption);
options.addOption(mainConfigFileOption);
options.addOption(inputFiles);
options.addOption(outputFile);
options.addOption(outputType);
return options;
}
/**
* Creates a {@link at.jku.fim.rubanetra.config.ConfigurationController} using default options
* {@link #createDefaultOptions()} and a {@link org.apache.commons.cli.GnuParser} to parse the command line
* arguments.
* After a successful parsing process, {@link ConfigurationController#start()}
* will be invoked.
*
* @param args command line arguments as defined by {@link #createDefaultOptions()}
*/
public static void main(String[] args) {
ConfigurationController controller = new ConfigurationController();
Options defaultOptions = ConfigurationController.createDefaultOptions();
CommandLineParser cliParser = new GnuParser();
CommandLine cli;
try {
cli = cliParser.parse(defaultOptions, args);
} catch (ParseException e) {
log.error("Unable to process parsed arguments: ", e);
printHelp(defaultOptions);
return;
}
if (cli.hasOption(ConfigurationController.helpOption.getOpt())) {
printHelp(defaultOptions);
return;
} else if (cli.hasOption(ConfigurationController.versionOption.getOpt())) {
printVersion();
return;
}
if (cli.hasOption(ConfigurationController.inputFiles.getOpt())) {
String[] inputFileValues = cli.getOptionValues(ConfigurationController.inputFiles.getOpt());
controller.addInputFiles(inputFileValues);
}
if (cli.hasOption(ConfigurationController.outputFile.getOpt())) {
String outputFileValue = cli.getOptionValue(ConfigurationController.outputFile.getOpt());
controller.setOutputFile(outputFileValue);
}
if (cli.hasOption(ConfigurationController.outputType.getOpt())) {
String outputType = cli.getOptionValue(ConfigurationController.outputType.getOpt());
controller.setOutputFormat(outputType);
}
boolean initialized;
String mainConfigurationPath = cli.getOptionValue(ConfigurationController.mainConfigFileOption.getOpt());
if (mainConfigurationPath == null) {
// config was not provided via command line arg
initialized = controller.initialize();
} else {
initialized = controller.initialize(mainConfigurationPath);
}
if (!initialized || controller.getRubanetraSystemConfiguration() == null) {
log.error("Unable to initialize the system: configuration file does either not exist or it is not readable or it is not valid.");
return;
}
log.info("System configuration has been initialized successfully, starting the rule engine and input file parsing process.");
controller.start();
}
private static void printVersion() {
Package classPackage = ConfigurationController.class.getPackage();
StringBuilder strBuilder = new StringBuilder();
Attributes manifestAttributes = getMainAttributes();
if (manifestAttributes != null) {
strBuilder.append(String.format("%s %s%n", classPackage.getImplementationTitle(), classPackage.getImplementationVersion()));
String licShort = manifestAttributes.getValue("License-Short-Name");
String licLong = manifestAttributes.getValue("License-Long-Name");
String licHeaderLine = manifestAttributes.getValue("License-Short-Header");
String licUrl = manifestAttributes.getValue("License-Url");
String licInceptionYear = manifestAttributes.getValue("License-Inception-Year");
String licRecentYears = manifestAttributes.getValue("License-Recent-Years");
String copyrightOwner = manifestAttributes.getValue("Copyright-Owner");
strBuilder.append(String.format("Copyright (C) %s,%s %s%n", licInceptionYear, licRecentYears, copyrightOwner));
strBuilder.append(String.format("License %s: %s <%s>%n", licShort, licLong, licUrl));
String[] headerSplit = licHeaderLine.split("\\.\\s", 2);
String headerML = headerSplit.length == 2 ?
String.format("%s.%n%s%n", headerSplit[0], headerSplit[1]) : String.format("%s%n", licHeaderLine);
strBuilder.append(headerML);
} else {
strBuilder.append("Unknown version.%n");
}
System.out.println(strBuilder.toString());
}
private static void printHelp(Options defaultOptions) {
Package classPackage = ConfigurationController.class.getPackage();
HelpFormatter formatter = new HelpFormatter();
Attributes manifestAttributes = getMainAttributes();
String cmdLineSyntax;
try {
cmdLineSyntax = Paths.get(ConfigurationController.class.getProtectionDomain().getCodeSource().getLocation().toURI()).getFileName().toString();
} catch (URISyntaxException e) {
cmdLineSyntax = String.format("./rubanetra-%s.jar", classPackage.getImplementationVersion());
}
formatter.printHelp(String.format("java -jar %s <args>", cmdLineSyntax), defaultOptions);
if (manifestAttributes != null) {
StringBuilder strBuilder = new StringBuilder();
strBuilder.append(String.format("%nReport bugs to: <%s> or <stefan_rubanetra@swerk.priv.at>%n",
manifestAttributes.getValue("Issue-Management")));
strBuilder.append(String.format("Project home page: <%s>%n", manifestAttributes.getValue("Project-Home")));
System.out.println(strBuilder.toString());
}
}
/**
* @return the main attributes of the invoked JAR's manifest, containing at least "Implementation-Title",
* "Implementation-Version" and "Implementation-Vendor" attributes or null, if the manifest was not found
*/
public static Attributes getMainAttributes() {
Package classPackage = ConfigurationController.class.getPackage();
try {
Enumeration<URL> resourceEnum = ClassLoader.getSystemResources("META-INF/MANIFEST.MF");
while (resourceEnum.hasMoreElements()) {
try {
URL nextManifestUrl = resourceEnum.nextElement();
Manifest manifest = new Manifest(nextManifestUrl.openStream());
Attributes manifestAttributes = manifest.getMainAttributes();
String mainClassVal = manifestAttributes.getValue("Main-Class");
String implementationTitleVal = manifestAttributes.getValue("Implementation-Title");
String implementationVersionVal = manifestAttributes.getValue("Implementation-Version");
String implementationVendorVal = manifestAttributes.getValue("Implementation-Vendor");
if (mainClassVal != null && mainClassVal.equals(ConfigurationController.class.getCanonicalName())
&& classPackage.getImplementationTitle().equals(implementationTitleVal)
&& classPackage.getImplementationVendor().equals(implementationVendorVal)
&& classPackage.getImplementationVersion().equals(implementationVersionVal)) {
return manifestAttributes;
}
} catch (IOException e) {
log.warn("Unable to open manifest, skipping...", e);
}
}
} catch (IOException e) {
log.warn("Unable to find any manifest", e);
}
return null;
}
/**
* This method initializes the system invoking a parser for the main configuration file
* denoted by mainConfigFile. It tries to canonicalize all encountered file paths and will fail if it is unable
* to create a canonical representation.
* It relies on {@link at.jku.fim.rubanetra.config.RubanetraSystemConfigurationParser} and
* {@link at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBaseListenerImpl} for parsing
* functionality and builds the final {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration}
* object which can be obtained iff this method returned true via {@link #getRubanetraSystemConfiguration()}.
*
* @param mainConfigFile the main configuration file, which may not be null
* @return true, iff a main configuration instance was created (one may obtain this reference by calling
* {@link #getRubanetraSystemConfiguration()}.
* @throws java.lang.NullPointerException if the main config file is a null pointer
* @throws java.lang.IllegalArgumentException if the main config file is not valid
*/
public boolean initialize(File mainConfigFile) {
if (mainConfigFile == null) {
throw new NullPointerException("The main configuration file must not be a null pointer");
}
try {
mainConfigFile = mainConfigFile.getCanonicalFile();
} catch (IOException e) {
log.error("Unable to canonicalize file {}", mainConfigFile);
return false;
}
if (!checkMainConfigFile(mainConfigFile)) {
return false;
}
log.info("Trying to load main configuration from file {}", mainConfigFile);
RubanetraSystemConfigurationParser systemConfigParser = RubanetraSystemConfigurationBaseListenerImpl.createConfigurationFileParser(mainConfigFile);
RubanetraSystemConfigurationBaseListenerImpl systemConfigBaseListener = new RubanetraSystemConfigurationBaseListenerImpl(systemConfigBuilder);
RubanetraSystemConfigurationParser.SystemContext systemContext = systemConfigParser.system();
if (systemContext == null) {
throw new IllegalArgumentException("Invalid configuration file.");
}
String errorMsg = "Exactly one %s configuration section required, %d have been found";
int generalConfigurations = systemContext.generalConfig().size();
int inputConfigurations = systemContext.inputConfig().size();
int outputConfigurations = systemContext.outputConfig().size();
int protocolConfigurations = systemContext.protocolConfig().size();
if (generalConfigurations != 1)
throw new IllegalArgumentException(String.format(errorMsg, "general", generalConfigurations));
if (inputConfigurations != 1)
throw new IllegalArgumentException(String.format(errorMsg, "input", inputConfigurations));
if (outputConfigurations != 1)
throw new IllegalArgumentException(String.format(errorMsg, "output", outputConfigurations));
if (protocolConfigurations != 1)
throw new IllegalArgumentException(String.format(errorMsg, "protocol", protocolConfigurations));
/*
The general section should be parsed first, as it could contain vital information,
followed by the I/O configuration. Due to potentially existing file path entries in those sections and the
possibility of a redundant path specification via command line arguments, these settings must be adjusted
accordingly, i.e. either complemented or replaced altogether before the Pcap handler can be built, since the
protocol configuration depends on an already existing Pcap handler in order to setup listeners.
*/
ParseTreeWalker.DEFAULT.walk(systemConfigBaseListener, systemContext.generalConfig(0));
ParseTreeWalker.DEFAULT.walk(systemConfigBaseListener, systemContext.inputConfig(0));
ParseTreeWalker.DEFAULT.walk(systemConfigBaseListener, systemContext.outputConfig(0));
complementOrReplaceExistingConfig();
systemConfigBuilder.createPcapHandler();
ParseTreeWalker.DEFAULT.walk(systemConfigBaseListener, systemContext.protocolConfig(0));
systemConfiguration = systemConfigBuilder.build();
return true;
}
/**
* Tries to either complement (input files) or replace (output file/type) the existing configuration parsed from
* the main config files by the provided command line arguments.
*/
private void complementOrReplaceExistingConfig() {
if (this.inputFilePaths.size() > 0) {
if (!systemConfigBuilder.getInputFiles().isEmpty()) {
log.warn("The configuration file contains at least one reference to an input file, complementing with" +
" specified command line input file(s)");
}
for (String inputFilePath : this.inputFilePaths) {
systemConfigBuilder.addInputPath(inputFilePath);
}
}
if (this.outputFilePath != null) {
final OutputStream oldOutputStream = systemConfigBuilder.getOutputStream();
if (oldOutputStream != null) {
log.warn("The configuration file contains at least one reference to an output stream ... replacing it");
if (oldOutputStream != System.out && oldOutputStream != System.err) {
try {
oldOutputStream.close();
} catch (IOException e) {
log.warn("IOException while trying to close the replaced output stream", e);
}
}
}
if (outputFilePath.equalsIgnoreCase("stdout") || outputFilePath.equals("-")) {
systemConfigBuilder.setOutputStream(System.out);
} else {
systemConfigBuilder.setOutputFile(outputFilePath);
}
}
if (this.outputFormat != null) {
if (systemConfigBuilder.getOutputFormat() != null) {
log.warn("The configuration file contains at least one reference to an output format ... replacing it");
}
systemConfigBuilder.setOutputFormat(outputFormat);
}
}
/**
* Convenience method for {@link #initialize(java.io.File)}.
* It creates a file based on the given path.
*
* @param mainConfigurationPath the path of the main configuration file
* @return true, iff the configuration could be parsed (one may obtain a reference to the configuration object by
* calling {@link #getRubanetraSystemConfiguration()}.
*/
public boolean initialize(String mainConfigurationPath) {
File systemConfigurationFile = createFileFromResourceString(mainConfigurationPath);
if (systemConfigurationFile == null) {
systemConfigurationFile = getCanonicalFile(mainConfigurationPath);
}
return initialize(systemConfigurationFile);
}
/**
* This method initializes the system invoking a parser for the main configuration file
* denoted by (in processing order):
* <ul>
* <li>"rubanetra.conf" in the classpath and working directory</li>
* <li>"./conf/rubanetra.conf" in the classpath and working directory</li>
* <li>path denoted by environment variable FNA_SYSTEM_CONF_FILE in the class path and working directory</li>
* </ul>
* It tries to canonicalize all encountered file paths and will fail if it is unable
* to create a canonical representation.
* It relies on {@link at.jku.fim.rubanetra.config.RubanetraSystemConfigurationParser} and
* {@link at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBaseListenerImpl} for parsing
* functionality and builds the final {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration}
* object which can be obtained iff this method returned true via {@link #getRubanetraSystemConfiguration()}.
*
* @return true, iff a main configuration instance was created (one may obtain this reference by calling
* {@link #getRubanetraSystemConfiguration()}.
* @throws java.lang.NullPointerException if the main config file is a null pointer
* @throws java.lang.IllegalArgumentException if the main config file is not valid
*/
public boolean initialize() {
boolean initialized;
log.info("Trying to look up {} in the classpath and the working directory", defaultMainConfigName);
// try the default name
initialized = initialize(defaultMainConfigName);
if (!initialized) {
log.info("Trying to look up {} in the classpath and the working directory", defaultMainConfigPath);
// try the default full path
initialized = initialize(defaultMainConfigPath);
}
if (!initialized) {
log.info("Trying to look up path denoted by environment variable {} in the classpath and the working directory",
defaultMainConfigEnvVar);
// try the default env variable
initialized = initializeFromEnvVar(defaultMainConfigEnvVar);
}
return initialized;
}
/**
* Tries to look up the value of the environment variable denoted by envVariableName, and interprets it as
* main configuration path ({@link #initialize(java.io.File)} will be called)
*
* @param envVariableName the name of the environment variable to look up (the value should represent the main
* configuration file path)
* @return true, iff a main configuration instance was created (one may obtain this reference by calling
* {@link #getRubanetraSystemConfiguration()} afterwards.
*/
public boolean initializeFromEnvVar(String envVariableName) {
// try environment variable
log.info("Trying to load main configuration path from environment variable {}", envVariableName);
File systemConfigurationFile = createFileFromEnvVariable(envVariableName);
return initialize(systemConfigurationFile);
}
/**
* Tries to represent the path denoted by mainConfigurationPath canonically.
*
* @param mainConfigurationPath the file to canonicalize.
* @return the file denoted by mainConfigurationPath using a canonical representation or null, if not possible
*/
public File getCanonicalFile(String mainConfigurationPath) {
File systemConfigurationFile;
try {
systemConfigurationFile = new File(mainConfigurationPath).getCanonicalFile();
} catch (IOException e) {
log.warn("Unable to canonicalize the configuration file path");
return null;
}
return systemConfigurationFile;
}
private File createFileFromEnvVariable(String optionalMainConfigEnvVar) {
String mainConfigPath;
try {
mainConfigPath = System.getenv(optionalMainConfigEnvVar);
} catch (SecurityException e) {
log.warn("Unable to access environment variable", e);
return null;
}
if (mainConfigPath == null) {
log.warn("Unable to load configuration file via environment variable.");
} else {
File fileFromResourceString = createFileFromResourceString(mainConfigPath);
return fileFromResourceString == null ? getCanonicalFile(mainConfigPath) : fileFromResourceString;
}
return null;
}
/**
* Tries to create a file object by looking up filePath in the current classloader's classpath.
*
* @param filePath the path of the file in the current classpath
* @return a file object for filePath, or null if not found
*/
public File createFileFromResourceString(String filePath) {
log.info("Trying to load main configuration as classpath resource: {}", filePath);
URL fileUrl = ClassLoader.getSystemResource(filePath);
if (fileUrl == null) {
log.warn("Unable to find configuration file via class path resource loader: {}", filePath);
return null;
}
File file;
try {
file = new File(fileUrl.toURI());
} catch (URISyntaxException e) {
file = new File(filePath);
}
return file;
}
/**
* Performs a simple file metadata validation (is it readable, is it a file),
* however, it does not verify the contents of the file itself.
*
* @param file the file to check
* @return true, iff the file is not a directory and is readable and is not null
*/
public boolean checkMainConfigFile(File file) {
if (file != null && !file.isDirectory() && file.canRead()) {
return true;
}
log.warn("Cannot read configuration file {}", file);
return false;
}
/**
* Adds files containing network captures to the configuration builder
* {@link at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBuilder}.
* <p>
* This method may not be invoked after the initialization step has been completed, i.e. this method must be
* invoked before {@link #initialize(java.io.File)}.
*
* @param filePaths a number of file paths containing network captures in the specified
* {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration.InputFormat}
*/
public void addInputFiles(String... filePaths) {
checkUninitialized();
if (filePaths == null) {
log.error("Invalid command line input file specification.");
throw new IllegalArgumentException();
}
for (String filePath : filePaths) {
if (filePath == null || filePath.isEmpty()) {
log.warn("Input file path passed from command line appears to be null/empty - ignoring");
} else {
inputFilePaths.addLast(filePath);
}
}
}
/**
* Sets the default output file for the derived and parsed data using
* {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration.OutputFormat}
* <p>
* This method may not be invoked after the initialization step has been completed, i.e. this method must be
* invoked before {@link #initialize(java.io.File)}.
*
* @param outputFilePath the path of the default output file
*/
public void setOutputFile(String outputFilePath) {
checkUninitialized();
if (outputFilePath == null || outputFilePath.isEmpty()) {
log.error("Output file path passed from command line appears to be null/empty");
throw new IllegalArgumentException();
}
this.outputFilePath = outputFilePath;
}
/**
* Sets the {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration.OutputFormat} to apply
* as serialization variant.
* <p>
* This method may not be invoked after the initialization step has been completed, i.e. this method must be
* invoked before {@link #initialize(java.io.File)}.
*
* @param outputFormat the String representation of a {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration.OutputFormat}
*/
public void setOutputFormat(String outputFormat) {
checkUninitialized();
if (outputFormat == null || outputFormat.isEmpty()) {
log.error("Output format path passed from command line appears to be null/empty");
throw new IllegalArgumentException();
}
this.outputFormat = outputFormat;
}
private void checkUninitialized() {
if (this.systemConfiguration != null) {
log.error("This system configuration has already been initialized, unable to add additional input files");
throw new IllegalStateException();
}
}
/**
* @return this method will always return null, unless one of the {@link #initialize(java.io.File)} methods was invoked
* successfully, then it will return the constructed {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration}.
*/
public RubanetraSystemConfiguration getRubanetraSystemConfiguration() {
return systemConfiguration;
}
/**
* This method will do nothing, unless one of the {@link #initialize(java.io.File)} methods has been invoked
* successfully.
* <p>
* If a valid {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration} is encountered,
* a {@link at.jku.fim.rubanetra.drools.DroolsKrakenProtocolHandler} will be constructed and
* {@link at.jku.fim.rubanetra.pcap.PcapHandler#readNextPcapEntry(at.jku.fim.rubanetra.pcap.PcapActivityListener)}
* will be called as long as it returns true (using an infinite loop), i.e. until all network packets have been read
* from the input files. Afterwards, it will try to close all opened input and output streams, that is it will call
* {@link at.jku.fim.rubanetra.drools.DroolsKrakenProtocolHandler#close()}
* and {@link at.jku.fim.rubanetra.pcap.PcapHandler#close()}.
* Ultimately the existing reference to the {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration}
* will be erased, therefore allowing for a subsequent initialization call while reusing the same object.
*/
public void start() {
if (this.systemConfiguration == null || systemConfiguration.getPcapHandler() == null) {
log.error("System configuration has not been initialized completely.");
return;
}
DroolsKrakenProtocolHandler droolsKrakenProtocolHandler = new DroolsKrakenProtocolHandler(systemConfiguration);
while (true) {
try {
final boolean processingSuccessful = (systemConfiguration.getPcapHandler().readNextPcapEntry(droolsKrakenProtocolHandler));
if (!processingSuccessful) break;
} catch (Exception e) {
log.debug("Catch all exception block was entered", e);
}
}
try {
droolsKrakenProtocolHandler.close();
} catch (IOException e) {
log.warn("Exception occurred while trying to close the Drools/Kraken Protocol Handler:", e);
} finally {
this.systemConfiguration.getPcapHandler().close();
this.systemConfiguration = null;
}
}
}

View File

@ -0,0 +1,34 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import org.jnetpcap.protocol.JProtocol;
/**
* This interface serves as an identifier for a potential {@link org.jnetpcap.protocol.JProtocol}.
* Since the current system utilizes the Kraken-library as main reference point, this interface is currently a
* placeholder for future refinements.
*/
public interface JNetPcapProtocolId extends ProtocolId {
/**
* @return the represented {@link org.jnetpcap.protocol.JProtocol}
*/
JProtocol getJNetPcapProtocol();
}

View File

@ -0,0 +1,33 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import org.krakenapps.pcap.Protocol;
/**
* Implementations of this interface serve as identifiers for potential {@link org.krakenapps.pcap.Protocol}s, i.e.
* the application layer specific Kraken-library protocol identifier.
*/
public interface KrakenApplicationProtocolId extends ProtocolId {
/**
* @return the represented Kraken-library specific {@link org.krakenapps.pcap.Protocol}
*/
public abstract Protocol getKrakenApplicationProtocol();
}

View File

@ -0,0 +1,111 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import at.jku.fim.rubanetra.pcap.PcapActivityListener;
import at.jku.fim.rubanetra.pcap.PcapHandler;
import at.jku.fim.rubanetra.protocol.KrakenBaseProtocol;
import at.jku.fim.rubanetra.protocol.mapper.KrakenTransportLayerMappingFactory;
import java.util.Map;
/**
* This interface specifies methods that may be used to represent the configuration of a single application layer
* protocol of the Kraken-library. A {@link at.jku.fim.rubanetra.config.model.impl.KrakenProtocolConfigurationBuilderImpl}
* should be used to obtain an implementation of this interface.
* <p>
* Due to the current design of the Kraken-PCAP-library all application layer protocols
* rely on either a UDP ({@link org.krakenapps.pcap.decoder.udp.UdpProtocolMapper}) or a TCP
* ({@link org.krakenapps.pcap.decoder.tcp.TcpProtocolMapper}) protocol mapper.
* One of the design goals of this framework is the abstraction of this mechanism to enable customizations that do
* not require modifications of existing application layer parsers (e.g. HTTP over a custom transport layer protocol
* or multiple ports).
* A first step to achieve this goal is the introduction of a generic
* {@link at.jku.fim.rubanetra.protocol.mapper.TransportLayerMappingStrategy}.
* However, currently only a port/service based approach has been implemented. Since Kraken apparently does not allow
* the use of multiple ports per application layer parser (since the TCP/UDP-Mapper would override the bindings with
* the default parser), a custom {@link at.jku.fim.rubanetra.config.model.PortSpecification} approach
* was implemented on an application layer basis, i.e. a single application layer protocol may be bound to a
* Kraken-application layer parser for a single, multiple, all or no port(s).
* However, as soon as JNetPcap provides suitable application layer parsers for the currently supported protocols,
* this mechanism should be replaced by JNetPcap-bindings which is more elegant and convenient.
* This interface is implemented by
* {@link at.jku.fim.rubanetra.config.model.impl.KrakenProtocolConfigurationBuilderImpl.KrakenProtocolConfigurationImpl}.
*/
public interface KrakenProtocolConfiguration {
/**
* The underlying source of all PCAP-packets for this application layer protocol. A listener will be attached
* by default to listen for new {@link at.jku.fim.rubanetra.pcap.PcapActivity}-objects.
* All parsed PCAP-packets will be either parsed by a Kraken-Application layer parser for this protocol or
* discarded by the transport layer mapping strategy and/or port-specification.
*
* @return the {@link at.jku.fim.rubanetra.pcap.PcapHandler} to use as input stream for
* {@link at.jku.fim.rubanetra.pcap.PcapActivity}-objects.
* @see #getTransportLayerMappingStrategy()
* @see #getPortSpecification()
*/
public abstract PcapHandler<PcapActivityListener> getPcapHandler();
/**
* Represents a primitive protocol to Kraken-protocol decoder mapping mechanism.
* A network protocol within this framework is always identified by a
* {@link at.jku.fim.rubanetra.config.model.ProtocolId}. Therefore a mapping of a protocol to
* an appropriate Kraken-protocol decoder/parser is needed. All
* {@link at.jku.fim.rubanetra.protocol.KrakenBaseProtocol} implementations provide a method to
* retrieve a suitable identifier
* {@link at.jku.fim.rubanetra.protocol.KrakenBaseProtocol#getProtocolId()}.
* These bindings may be configured by using a
* {@link at.jku.fim.rubanetra.config.model.impl.KrakenProtocolConfigurationBuilderImpl}.
*
* @return the immutable copy of all application layer protocol bindings
*/
public abstract Map<ProtocolId, KrakenBaseProtocol> getBoundProtocols();
/**
* The transport layer mapping strategy to use for this Kraken-application layer protocol decoder.
*
* @return the transport layer protocol mapping strategy identifier which may be used to obtain an instance of
* a {@link at.jku.fim.rubanetra.protocol.mapper.TransportLayerMappingStrategy} by using
* {@link at.jku.fim.rubanetra.protocol.mapper.KrakenTransportLayerMappingFactory}.
*/
public abstract String getTransportLayerMappingStrategy();
/**
* The specification of a number of {@link at.jku.fim.rubanetra.config.model.PortRange}s or
* {@link at.jku.fim.rubanetra.config.model.Port}s which filters packets at the transport layer
* for this application layer protocol. A simpler alternative to this method is the use of
* {@link at.jku.fim.rubanetra.config.model.PortSpecification.UniversalPortSpecification} and
* by restricting all transport layer packets globally via a BP-Filter,
* see {@link at.jku.fim.rubanetra.pcap.PcapHandler}.
*
* @return the {@link at.jku.fim.rubanetra.config.model.PortSpecification} as a transport layer
* filter for this application layer protocol only
* @see at.jku.fim.rubanetra.config.model.PortSpecification.UniversalPortSpecification
*/
public abstract PortSpecification getPortSpecification();
/**
* This {@link at.jku.fim.rubanetra.protocol.mapper.KrakenTransportLayerMappingFactory} may be used
* by the {@link at.jku.fim.rubanetra.protocol.KrakenBaseProtocol} parsers
* to obtain instances of the configured {@link #getTransportLayerMappingStrategy()}.
*
* @return a factory to obtain instances of the transport layer mapping strategy
*/
public abstract KrakenTransportLayerMappingFactory getTransportLayerMappingFactory();
}

View File

@ -0,0 +1,88 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import at.jku.fim.rubanetra.pcap.PcapActivityListener;
import at.jku.fim.rubanetra.pcap.PcapHandler;
import at.jku.fim.rubanetra.protocol.mapper.KrakenTransportLayerMappingFactory;
/**
* Generic specification of a Kraken application protocol configuration builder.
*/
public interface KrakenProtocolConfigurationBuilder {
/**
* Builds the protocol configuration that has been set up until now
* @return the immutable protocol configuration that has been set up until now
*/
public abstract KrakenProtocolConfiguration buildProtocolConfiguration();
/**
* Set a transport layer filter for the parser of this protocol
* @param transportProtocolPortSpec the port specification for this application layer protocol parser
* @return the builder instance
* @see at.jku.fim.rubanetra.config.model.KrakenProtocolConfiguration
*/
public abstract KrakenProtocolConfigurationBuilder setPortSpecification(PortSpecification transportProtocolPortSpec);
/**
* Set the transport layer mapping strategy to use for this protocol
* @param strategy the {@link at.jku.fim.rubanetra.protocol.mapper.TransportLayerMappingStrategy} to use
* @return the builder instance
* @see at.jku.fim.rubanetra.protocol.mapper.KrakenTransportLayerMappingFactory
*/
public abstract KrakenProtocolConfigurationBuilder setTransportProtocolMappingStrategy(String strategy);
/**
* Set the transport layer mapping factory to use for building transport layer mapping strategies
* @param mappingFactory the transport layer mapping factory to use
* @return the builder instance
*/
public abstract KrakenProtocolConfigurationBuilder setTransportProtocolMappingFactory(KrakenTransportLayerMappingFactory mappingFactory);
/**
* Set the pcap packet input stream for this application layer protocol parser
* @param pcapHandler the Pcap packet input stream
* @return the builder instance
*/
public abstract KrakenProtocolConfigurationBuilder setPcapHandler(PcapHandler<PcapActivityListener> pcapHandler);
/**
* Resets all settings of the current protocol configuration
*/
public abstract void resetCurrentProtocolConfiguration();
/**
* Bind a protocol handler to another protocol handler, i.e. define the stream of decoded data
* (in general one way only, unless bound vice-versa as well)
* @param bindFrom the wild protocol identifier which can be mapped by the protocol registry to
* an existing protocol handler, and that will be bound to the handler of the bindTo protocol
* @param bindTo the wild protocol identifier which can be mapped by the protocol registry to
* an existing protocol handler, and that will receive decoded data from the bindFrom handler
*
* @return the builder instance
*/
public abstract KrakenProtocolConfigurationBuilder bindProtocol(String bindFrom, String bindTo);
/**
* Set the protocol identifier to use for this protocol configuration.
* @param currentProtocolIdentifier a protocol identifier (should be unique within this framework)
* @return the builder instance
*/
public abstract KrakenProtocolConfigurationBuilder setCurrentProtocolIdentifier(String currentProtocolIdentifier);
}

View File

@ -0,0 +1,102 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import java.util.HashMap;
import java.util.Map;
/**
* A transport layer TCP/UDP port number.
*/
public class Port implements Comparable<Port> {
/**
* the lower bound of the available port number pool
*/
public static final int LOWER_BOUND = 0;
/**
* the upper bound of the available port number pool
*/
public static final int UPPER_BOUND = 65535;
private static final Map<Integer, Port> numberPortMap = new HashMap<>();
private int portNumber;
/**
* Private constructor, use {@link #create(int)} instead
*
* @throws java.lang.IllegalArgumentException if the port-number is not within the allowed range
*/
private Port(int portNumber) {
checkPortNumber(portNumber);
this.portNumber = portNumber;
}
/**
* Create a new {@link at.jku.fim.rubanetra.config.model.Port}
*
* @param portNumber the port number to use
* @return a new {@link at.jku.fim.rubanetra.config.model.Port} or
* an instance of an already instantiated port.
* @throws java.lang.IllegalArgumentException if the port-number is not within the allowed range
*/
public static Port create(int portNumber) {
if (!numberPortMap.containsKey(portNumber)) {
numberPortMap.put(portNumber, new Port(portNumber));
}
return numberPortMap.get(portNumber);
}
/**
* This method is equivalent to calling {@link #create(int)}.
* Create a new {@link at.jku.fim.rubanetra.config.model.Port}
*
* @param portNumber the port number to use
* @return a new {@link at.jku.fim.rubanetra.config.model.Port} or
* an instance of an already instantiated port.
* @throws java.lang.IllegalArgumentException if the port-number is not within the allowed range
*/
public static Port getPort(int portNumber) {
return create(portNumber);
}
private void checkPortNumber(int portNumber) {
if (portNumber < LOWER_BOUND || portNumber > UPPER_BOUND) {
throw new IllegalArgumentException(String.format("Port %d is out of range", portNumber));
}
}
/**
* @return the represented port number
*/
public int getPortNumber() {
return portNumber;
}
@Override
public int compareTo(Port otherPort) {
return Integer.compare(getPortNumber(), otherPort.getPortNumber());
}
@Override
public String toString() {
return String.valueOf(portNumber);
}
}

View File

@ -0,0 +1,95 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
/**
* A port range is defined by an interval that is bound by two ports, i.e.
* [lowerPort;upperPort], both bounds are inclusive.
*/
public class PortRange {
private Port lowerPort;
private Port higherPort;
/**
* Create a new port range, which represents all possible ports within the interval [lowerPort;upperPort], inclusive
*
* @param lowerPort the lower bound of the range, must be less than higherPort.
* @param higherPort the upper bound of the range, must be greater than lowerPort.
* @throws java.lang.IllegalArgumentException if invalid arguments are passed
*/
public PortRange(Port lowerPort, Port higherPort) {
this.lowerPort = lowerPort;
this.higherPort = higherPort;
checkPortRange(lowerPort, higherPort);
}
private void checkPortRange(Port lowerPort, Port higherPort) {
if (lowerPort == null || higherPort == null) {
throw new IllegalArgumentException();
}
if (lowerPort.compareTo(higherPort) >= 0) {
throw new IllegalArgumentException();
}
}
/**
* Checks whether the given port is within this range, i.e. port in [lowerPort;higherPort]
* @param port to check
* @return true, iff if port is in this range
* @throws java.lang.IllegalArgumentException if the port is null
*/
public boolean isWithinRange(Port port) {
if (port == null) {
throw new IllegalArgumentException();
}
return port.compareTo(getLowerPort()) >= 0 && port.compareTo(getHigherPort()) <= 0;
}
/**
* @return the upper bound of this range
*/
public Port getHigherPort() {
return higherPort;
}
/**
* Sets the upper bound of this range
* @param higherPort the upper bound of the range, must be greater than lowerPort.
*/
public void setHigherPort(Port higherPort) {
checkPortRange(lowerPort, higherPort);
this.higherPort = higherPort;
}
/**
* @return the lower bound of this range
*/
public Port getLowerPort() {
return lowerPort;
}
/**
* Sets the lower bound of the range
* @param lowerPort the lower bound of the range, must be less than higherPort.
*/
public void setLowerPort(Port lowerPort) {
checkPortRange(lowerPort, higherPort);
this.lowerPort = lowerPort;
}
}

View File

@ -0,0 +1,141 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import java.util.HashMap;
import java.util.HashSet;
import java.util.Map;
import java.util.Set;
/**
* This class constitutes a higher level specification of the mapping between an application layer protocol and
* the associated transport layer (TCP/UDP) port numbers and/or port ranges.
* It is utilized for a number of Kraken application layer protocol parser to transport layer mapping abstractions, e.g.
* {@link at.jku.fim.rubanetra.protocol.mapper.TransportLayerMappingStrategy}, and configured by
* an instance of {@link at.jku.fim.rubanetra.config.model.KrakenProtocolConfigurationBuilder} resulting
* in a {@link at.jku.fim.rubanetra.config.model.KrakenProtocolConfiguration} object.
* Note, that this implementation currently utilizes the Java 8 - Stream API for performing {@link at.jku.fim.rubanetra.config.model.PortRange}
* bound checking via predicates, see {@link #contains(Port)}.
* Additionally, the subclass {@link at.jku.fim.rubanetra.config.model.PortSpecification.UniversalPortSpecification}
* was defined for convenience reasons.
* This class is not thread-safe.
*/
public class PortSpecification {
private final Map<Integer, Port> portMap;
private final Set<PortRange> portRangeSet;
public PortSpecification() {
this.portMap = new HashMap<>();
this.portRangeSet = new HashSet<>();
}
/**
* Adds a single port to this specification.
* A previously defined port with the same port number will be overwritten silently.
*
* @param singlePort the port to add to this specification
* @throws java.lang.IllegalArgumentException if singlePort == null
*/
public void add(Port singlePort) {
if (singlePort == null) {
throw new IllegalArgumentException();
}
this.portMap.put(singlePort.getPortNumber(), singlePort);
}
/**
* Adds a new port-range to this specification.
* A {@link java.util.HashSet} is used internally to store the port ranges.
*
* @param portRange the port range to add to this specification
* @throws java.lang.IllegalArgumentException if the portRange is null
*/
public void add(PortRange portRange) {
if (portRange == null) {
throw new IllegalArgumentException();
}
this.portRangeSet.add(portRange);
}
/**
* This is a convenience method for {@link #contains(Port)}.
* A new {@link at.jku.fim.rubanetra.config.model.Port} is constructed for the passed
* integer argument.
*
* @param destinationPort the port number to check against this specification
* @return false, if the given port was null or if it does not conform to the bounds of this specification,
* true, iff the given port is backed by either a port-range or a single port number.
* @throws java.lang.IllegalArgumentException if the port number is invalid
* @see #contains(Port)
*/
public boolean contains(int destinationPort) {
Port p = Port.getPort(destinationPort);
return contains(p);
}
/**
* Performs a bound check according to the underlying specification.
* A port adheres to the specification iff it was specified as a single {@link at.jku.fim.rubanetra.config.model.Port}
* or any specified {@link at.jku.fim.rubanetra.config.model.PortRange} returns true by calling
* {@link at.jku.fim.rubanetra.config.model.PortRange#isWithinRange(Port)}.
* A Java 8 predicate check via the new stream-API is currently used for this check.
*
* @param destinationPort the port to check against this specification
* @return false, if the given port was null or if it does not conform to the bounds of this specification,
* true, iff the given port is backed by either a port-range or a single port number.
*/
public boolean contains(Port destinationPort) {
if (destinationPort == null) {
return false;
}
return this.portMap.containsKey(destinationPort.getPortNumber())
|| portRangeSet.stream().anyMatch(portRange -> portRange.isWithinRange(destinationPort));
}
/**
* A port specification that returns either always true or always false for any given port number.
*/
public static class UniversalPortSpecification extends PortSpecification {
public static final PortSpecification ACCEPT_ALL = new UniversalPortSpecification(true);
public static final PortSpecification REJECT_ALL = new UniversalPortSpecification(false);
private final boolean acceptPort;
/**
* Only two meaningful implementations available - either return true or false,
* therefore a public constructor was deemed to be unnecessary.
*/
private UniversalPortSpecification(boolean accept) {
super();
this.acceptPort = accept;
}
@Override
public boolean contains(int destinationPort) {
Port p = Port.getPort(destinationPort);
return contains(p);
}
@Override
public boolean contains(Port destinationPort) {
return destinationPort != null && acceptPort;
}
}
}

View File

@ -0,0 +1,42 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
/**
* This interface represents a meta-identifier for network protocols of arbitrary layers and frameworks.
* Since the currently included network stack parser/decoder (Kraken/JNetPcap) use their own, partly incompatible
* protocol identifier mechanism, this interface tries to provide a common denominator which allows the identification
* of a single network protocol within the system's framework.
* The provided information of implementations is intended for internal usage only, i.e. the used identifiers are
* neither globally unique nor adhere to a specific standard/RFC.
* See {@link at.jku.fim.rubanetra.config.model.KrakenApplicationProtocolId} and
* {@link at.jku.fim.rubanetra.config.model.JNetPcapProtocolId}.
*/
public interface ProtocolId {
/**
* @return a unique identifier (within the framework) for the network protocol to represent
*/
public abstract String getProtocolId();
/**
* @return a human-readable name for the network protocol to represent
*/
public abstract String getName();
}

View File

@ -0,0 +1,137 @@
/**
* This file is part of Rubanetra.
* Copyright (C) 2013,2014 Stefan Swerk (stefan_rubanetra@swerk.priv.at)
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package at.jku.fim.rubanetra.config.model;
import at.jku.fim.rubanetra.output.OutputWriterStrategy;
import at.jku.fim.rubanetra.pcap.PcapFileHandler;
import org.kie.api.runtime.KieSession;
import java.io.File;
import java.io.OutputStream;
import java.util.Set;
/**
* The generic specification of the system configuration itself.
* This may be considered to constitute many of the essential settings, i.e. how and where to write the derived data, the Pcap
* packet input stream, the input files, the Drools knowledge session.
* Use a {@link at.jku.fim.rubanetra.config.model.impl.RubanetraSystemConfigurationBuilder} to obtain an implementation
* instance programmatically.
*/
public interface RubanetraSystemConfiguration {
/**
* The main output stream that is used to write all derived information to.
* The format of this data is defined by the {@link at.jku.fim.rubanetra.config.model.RubanetraSystemConfiguration.OutputFormat},
* see{@link #getOutputFormat()}.
* The point of time that defines when the data is actually written to this stream, is controlled by the
* {@link at.jku.fim.rubanetra.output.OutputWriterStrategy}, see {@link #getOutputWriterStrategy()},
* and the Drools knowledge session (i.e. the Rule engine and custom rules).
*
* @return the main output stream of the derived information
*/
public OutputStream getOutputStream();
/**
* The format that is used to transform the derived data before it is written to the output-stream.
*
* @return the format to use for data transformation
* @see #getOutputStream()
*/
public OutputFormat getOutputFormat();
/**
* The writer strategy that is used to transform (using {@link #getOutputFormat()}) and finally write (using
* {@link #getOutputStream()}) the derived data (delivered from {@link #getKieSession()}).
*
* @return the defined writer strategy
* @see #getOutputStream()
* @see #getOutputFormat()
*/
public OutputWriterStrategy getOutputWriterStrategy();
/**
* The set of all defined protocol configurations, each representing the complete configuration of a Kraken protocol
* parser/decoder, containing protocol mappings (ETHERNET->IPv4->...->...).
*
* @return the immutable set of defined Kraken protocol parser configurations
*/
public Set<KrakenProtocolConfiguration> getProtocolSettings();
/**
* The Pcap packet input stream handler that is used to parse and react to Pcap-information
* from the set of defined input files.
*
* @return the pcap input stream handler
*/
public PcapFileHandler<?> getPcapHandler();
/**
* The set of input files possibly adhering to a PCAP-specification.
*
* @return the set of pcap input files used for parsing pcap-packets
*/
public Set<File> getInputFiles();
/**
* The format of all input files (currently always PCAP)
*
* @return the common input format of all files
*/
public InputFormat getInputFormat();
/**
* The Drools knowledge session reference, used to pass new facts to the rule engine
* decoded by the protocol parsers.
*
* @return the Drools knowledge session reference
*/
public KieSession getKieSession();
/**
* The enumeration of possible output formats, used for transforming derived data before it is written to the output
* stream.
*
* @see #getOutputFormat()
*/
public enum OutputFormat {
/**
* PLASO may be considered synonymous to XML,
*/
PLASO,
CSV,
JSON,
XML,
/**
* no-op, i.e. data will not be written at all
*/
NOP, CALLBACK
}
/**
* The enumeration of possible input formats, used for defining the appropriate input file handler without
* guessing
*
* @see #getInputFormat()
*/
public enum InputFormat {
PCAP
}
}

Some files were not shown because too many files have changed in this diff Show More