From: Eduardo Ramos Testillano Date: Sun, 12 Apr 2015 12:32:51 +0000 (+0200) Subject: Now pcapDecoder only decodes diameter pcap and dump hex files (optional) X-Git-Tag: REFACTORING_TESTING_LIBRARY~166 X-Git-Url: https://git.teslayout.com/public/public/public/?p=anna.git;a=commitdiff_plain;h=db04ba506b776f4fd925df83a3d092687cf674c5 Now pcapDecoder only decodes diameter pcap and dump hex files (optional) --- diff --git a/example/diameter/pcapDecoder/SConscript b/example/diameter/pcapDecoder/SConscript index ab3bc06..c84a9c6 100644 --- a/example/diameter/pcapDecoder/SConscript +++ b/example/diameter/pcapDecoder/SConscript @@ -10,7 +10,7 @@ pPath = pName.replace("_", "/") + "/" pwd = str(Dir ('.').abspath); anna_libpaths = [] anna_libs = [] -modules = [ 'core', 'io', 'xml', 'time', 'diameter' ]; +modules = [ 'core' ]; for module in modules: anna_libs.append ("anna_" + module) #module = module.replace("_", ".") @@ -26,7 +26,7 @@ localEnv = env.Clone() anna_library = { 'LIBS' : anna_rlibs } localEnv.MergeFlags (anna_library) -system_library = { 'LIBS' : [ 'xml2', 'rt', 'pcap' ] } +system_library = { 'LIBS' : [ 'rt', 'pcap' ] } localEnv.MergeFlags (system_library) localEnv.Append(LIBPATH = anna_libpaths) diff --git a/example/diameter/pcapDecoder/dictionary.xml b/example/diameter/pcapDecoder/dictionary.xml deleted file mode 100644 index 99c4b3a..0000000 --- a/example/diameter/pcapDecoder/dictionary.xml +++ /dev/null @@ -1,2141 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/example/diameter/pcapDecoder/main.cpp b/example/diameter/pcapDecoder/main.cpp index d3f6f4e..c8bbea7 100644 --- a/example/diameter/pcapDecoder/main.cpp +++ b/example/diameter/pcapDecoder/main.cpp @@ -51,16 +51,9 @@ #include #include #include -#include -#include -#include -#include -//#include // typedef unsigned int ApplicationId; -#include // ApplicationId anna::diameter::codec::functions::getApplicationId(const anna::DataBlock &) throw(anna::RuntimeException); using namespace anna; -using namespace anna::diameter; // Payload and frame metadata ///////////////////////////////////////////////////////////////////////////// class Payload { @@ -149,8 +142,6 @@ public: typedef std::map < int /* frame */, Payload > payloads_t; typedef std::map < int /* frame */, Payload >::const_iterator payloads_it; payloads_t G_payloads; -anna::diameter::codec::Message G_codecMsg; -anna::diameter::codec::Engine *G_codecEngine; // Sniffing structures //////////////////////////////////////////////////////////////////////////////////// @@ -327,17 +318,6 @@ void _exit(const std::string &message, int resultCode = 1) { exit(resultCode); } -// Decodes a diameter message coming from a datablock -void decodeDataBlock(const anna::DataBlock &db, unsigned int & detectedApplicationId) throw() { - try { - detectedApplicationId = anna::diameter::codec::functions::getApplicationId(db); - G_codecEngine->setDictionary(detectedApplicationId); - G_codecMsg.decode(db); - } catch(RuntimeException &ex) { - _exit(ex.asString()); - } -} - //------------------------------------------------------------------- int main(int argc, char **argv) { @@ -347,111 +327,27 @@ int main(int argc, char **argv) { std::cout << std::endl; //check command line arguments - if(argc < 3) { + if(argc < 2) { std::string msg = "Usage: "; msg += exec; - msg += " [--no-validation] [--ignore-flags] [--debug]\n\n"; - msg += " stacks: \n"; - msg += " This is a list of #-separated stacks defined by a comma-separated pair \n"; - msg += " If only one stack is provided, application-id could be omitted and then, all the messages will be decoded with the\n"; - msg += " dictionary regardless the value of the application-id (the stack will be registered with id=0).\n"; - msg += " Input file: normally a pcap file, but hexadecimal content (colons allowed) can also be decoded (use '.hex' extension).\n"; - msg += " --no-validation: no validation is performed.\n"; - msg += " --ignore-flags: wrong flags regarding dictionary are ignored in xml representation.\n"; - msg += " --debug: activates debug level traces (warning by default)."; + msg += " [--write-hex: to write hex files] [--debug: activates debug level traces (warning by default)]\n\n"; _exit(msg); } // Command-line parameters: - std::string stacks = argv[1]; - std::string inputFile = argv[2]; + std::string inputFile = argv[1]; bool isHex = (inputFile.substr(inputFile.find_last_of(".") + 1) == "hex"); std::string outputFile = inputFile; // extension will be added later std::string optionals; - int indx = 3; - + int indx = 2; while(indx < argc) { optionals += " "; optionals += argv[indx]; indx++; } - bool no_validation = (optionals.find("--no-validation") != std::string::npos); - bool ignore_flags = (optionals.find("--ignore-flags") != std::string::npos); bool debug = (optionals.find("--debug") != std::string::npos); + bool writeHex = (optionals.find("--write-hex") != std::string::npos); Logger::setLevel(debug ? Logger::Debug:Logger::Warning); Logger::initialize(execBN.c_str(), new TraceWriter(filetrace.c_str(), 2048000)); - G_codecEngine = new anna::diameter::codec::Engine(); - anna::diameter::stack::Engine &stackEngine = - anna::diameter::stack::Engine::instantiate(); - - // Register stacks: - try { - anna::Tokenizer stacksTok; - stacksTok.apply(stacks, "#"); - anna::Tokenizer::const_iterator stacks_it, stack_it; - - for(stacks_it = stacksTok.begin(); stacks_it != stacksTok.end(); stacks_it++) { - std::string stack = anna::Tokenizer::data(stacks_it); - anna::Tokenizer stackTok; - stackTok.apply(stack, ","); - - if(stackTok.size() == 1) { - if(stacksTok.size() != 1) - throw anna::RuntimeException("Application Id value is mandatory when more than one stack is going to be configured", ANNA_FILE_LOCATION); - - anna::diameter::stack::Dictionary * d = stackEngine.createDictionary(0 /* no matter */, stack); // the stack is the dictionary - G_codecEngine->setDictionary(d); - break; - } - - if(stackTok.size() != 2) - throw anna::RuntimeException("Each stack must be in the form '#'", ANNA_FILE_LOCATION); - - stack_it = stackTok.begin(); - unsigned int stackId = atoll(anna::Tokenizer::data(stack_it)); - stack_it++; - std::string file = anna::Tokenizer::data(stack_it); - anna::diameter::stack::Dictionary * d = stackEngine.createDictionary(stackId, file); - } - - std::cout << "Stacks provided: " << std::endl; - std::cout << anna::functions::tab(stackEngine.asString(false /* light */)); - std::cout << std::endl; - std::cout << "Input file provided: " << inputFile << std::endl; - std::cout << "Validation: " << (!no_validation ? "yes" : "no") << std::endl; - std::cout << "Ignore Flags: " << (ignore_flags ? "yes" : "no") << std::endl; - std::cout << std::endl; - } catch(anna::RuntimeException &ex) { - _exit(ex.asString()); - } - // Validation kindness - G_codecEngine->setValidationDepth(anna::diameter::codec::EngineImpl::ValidationDepth::Complete); // complete validation for better reports - if(no_validation) G_codecEngine->setValidationMode(anna::diameter::codec::EngineImpl::ValidationMode::Never); - - if(ignore_flags) G_codecEngine->ignoreFlagsOnValidation(true); - - // Tracing: - //if (cl.exists("trace")) - // anna::Logger::setLevel(anna::Logger::asLevel(cl.getValue("trace"))); - // Check hex content input file (look extension): anna::DataBlock db_aux(true); - unsigned int detectedApplicationId; - - if(isHex) { - if(!getDataBlockFromHexFile(inputFile, db_aux)) - _exit("Error reading hex file provided"); - - // Decode datablock: - decodeDataBlock(db_aux, detectedApplicationId); - // Open output file: - outputFile += ".as.xml"; - std::ofstream out(outputFile.c_str(), std::ifstream::out); - out << G_codecMsg.asXMLString(); - // Close output file: - out.close(); - std::string msg = "Open '"; msg += filetrace; msg += "' in order to see process traces.\n"; - msg += "Open '"; msg += outputFile; msg += "' to see decoding results."; - _exit(msg, 0); - } - // Normal input: pcap file: // SNIFFING //////////////////////////////////////////////////////////////////////////////////////////////7 //temporary packet buffers struct pcap_pkthdr header; // The header that pcap gives us @@ -464,6 +360,25 @@ int main(int argc, char **argv) { if(handle == NULL) _exit(errbuf, 2); + // TODO: add filtering. At the moment, pcap must be previously filtered for diameter protocol ('tcp port 3868' or any other filter allowed) + /* + // Filtering: + std::string filter = ?????; + struct bpf_program _fp; + struct bpf_program *fp = &_fp; + bpf_u_int32 netmask = 4294967295; // FFFFFFFF + + if (pcap_compile(handle, fp, (char*)(filter.c_str()), 1, netmask) == -1) { + std::cerr << "Couldn't compile the filter " << filter << std::endl; + return(2); + } + + if (pcap_setfilter(handle, fp) == -1) { + std::cerr << "Couldn't set the filter " << filter << std::endl; + return(2); + } + */ + //begin processing the packets in this particular file int packets = -1; @@ -475,6 +390,7 @@ int main(int argc, char **argv) { } pcap_close(handle); //close the pcap file + // Print payloads ////////////////////////////////////////////////////////////////////////////////////////////// // Open output file: outputFile += ".report"; @@ -487,30 +403,31 @@ int main(int argc, char **argv) { int tsu = (it->second).getTimestampU(); std::string ts_str = ctime(&ts); ts_str.erase(ts_str.find("\n")); - out << std::endl; - out - << "===================================================================================================" - << std::endl; + out << "Frame: " << anna::functions::asString(it->first) << std::endl; out << "Date: " << ts_str << std::endl; out << "Timestamp: " << anna::functions::asString((int)ts) << "." << anna::functions::asString((int)tsu) << std::endl; out << "Origin IP: " << (it->second).getSourceIP() << std::endl; out << "Destination IP: " << (it->second).getDestinationIP() << std::endl; - // decode hex string: - anna::functions::fromHexString((it->second).getDataAsHex(), db_aux); - // Decode datablock: - decodeDataBlock(db_aux, detectedApplicationId); - // Stack identification: - //out << "Application Id: " << detectedApplicationId << std::endl; - out << "Dictionary used: " << G_codecEngine->getDictionary()->getName() << std::endl; + out << "Destination IP: " << (it->second).getDestinationIP() << std::endl; + out << "Hex String: " << (it->second).getDataAsHex() << std::endl; + + // Create hex file: + if (writeHex) { + std::string hexFile = anna::functions::asString(it->first) + ".hex"; + std::ofstream hex(hexFile.c_str(), std::ifstream::out); + hex << (it->second).getDataAsHex(); + hex.close(); + } + out << std::endl; - out << G_codecMsg.asXMLString(); } // Close output file: out.close(); std::string msg = "Open '"; msg += filetrace; msg += "' in order to see process traces.\n"; - msg += "Open '"; msg += outputFile; msg += "' to see decoding results."; + msg += "Open '"; msg += outputFile; msg += "' to see decoding results.\n"; + if (writeHex) msg += "Open '.hex' to see specific frame data."; _exit(msg, 0); }