Spaces:
Paused
Paused
File size: 2,799 Bytes
353fcd4 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 | """Generate three clearly-synthetic example captures for the demo UI.
These are NOT real traffic — they are constructed so each example exercises one verdict
band of the trained model (benign browsing, port scan, exploit-like payload). The README
and UI label them as synthetic.
"""
import os
from scapy.all import (Ether, IP, TCP, UDP, DNS, DNSQR, DNSRR, Raw, wrpcap)
os.makedirs("examples", exist_ok=True)
def tcp_pkt(sip, dip, sp, dp, flags, payload=b"", seq=1000, ack=0):
return (Ether(src="02:00:00:00:00:01", dst="02:00:00:00:00:02")
/ IP(src=sip, dst=dip) / TCP(sport=sp, dport=dp, flags=flags, seq=seq, ack=ack)
/ Raw(payload))
def handshake(sip, dip, sp, dp):
return [tcp_pkt(sip, dip, sp, dp, "S"),
tcp_pkt(dip, sip, dp, sp, "SA", seq=5000, ack=101),
tcp_pkt(sip, dip, sp, dp, "A", seq=101, ack=501)]
# --- benign: a couple of plain HTTP-ish flows + a UDP DNS query flow
pkts = []
for i, (sp, host) in enumerate([(51000, "example.com"), (51002, "example.org")]):
sip, dip = "10.0.0.5", "93.184.216.%d" % (34 + i)
req = ("GET / HTTP/1.1\r\nHost: %s\r\nUser-Agent: demo/1.0\r\nAccept: */*\r\n\r\n" % host).encode()
resp = ("HTTP/1.1 200 OK\r\nContent-Type: text/html\r\nContent-Length: 21\r\n\r\n<html>hello</html>").encode()
pkts += handshake(sip, dip, sp, 80)
pkts += [tcp_pkt(sip, dip, sp, 80, "PA", req, seq=101),
tcp_pkt(dip, sip, 80, sp, "PA", resp, seq=501, ack=101 + len(req))]
# DNS
pkts += [Ether() / IP(src="10.0.0.5", dst="10.0.0.1") / UDP(sport=53000, dport=53)
/ DNS(rd=1, qd=DNSQR(qname="example.com")),
Ether() / IP(src="10.0.0.1", dst="10.0.0.5") / UDP(sport=53, dport=53000)
/ DNS(aa=1, qd=DNSQR(qname="example.com"), an=DNSRR(rrname="example.com", rdata="93.184.216.34"))]
wrpcap("examples/benign.pcap", pkts)
# --- scan: one source probing many TCP ports (SYN only, no payload)
pkts = []
for dp in [21, 22, 23, 25, 53, 80, 110, 135, 139, 143, 443, 445, 993, 995, 1433,
3306, 3389, 5432, 5900, 6379, 8080, 8443, 9200, 27017, 11211]:
pkts.append(tcp_pkt("10.0.0.99", "10.0.0.9", 40125, dp, "S"))
wrpcap("examples/scan.pcap", pkts)
# --- exploit-like: payload traffic with a NOP sled + shellcode-shaped bytes
sled = b"\x90" * 48
shell = bytes([0x31, 0xc0, 0x50, 0x68, 0x2f, 0x2f, 0x73, 0x68, 0x68, 0x2f, 0x62, 0x69,
0x6e, 0x89, 0xe3, 0x50, 0x89, 0xe2, 0x53, 0x89, 0xe1, 0xb0, 0x0b, 0xcd, 0x80])
pkts = []
sip, dip = "10.0.0.66", "10.0.0.9"
pkts += handshake(sip, dip, 49152, 4444)
pkts += [tcp_pkt(sip, dip, 49152, 4444, "PA", sled + shell, seq=101),
tcp_pkt(sip, dip, 49152, 4444, "PA", sled + shell, seq=101 + 73)]
wrpcap("examples/exploit.pcap", pkts)
print("examples written:", os.listdir("examples")) |