"""Generate three clearly-synthetic example captures for the demo UI. These are NOT real traffic — they are constructed so each example exercises one verdict band of the trained model (benign browsing, port scan, exploit-like payload). The README and UI label them as synthetic. """ import os from scapy.all import (Ether, IP, TCP, UDP, DNS, DNSQR, DNSRR, Raw, wrpcap) os.makedirs("examples", exist_ok=True) def tcp_pkt(sip, dip, sp, dp, flags, payload=b"", seq=1000, ack=0): return (Ether(src="02:00:00:00:00:01", dst="02:00:00:00:00:02") / IP(src=sip, dst=dip) / TCP(sport=sp, dport=dp, flags=flags, seq=seq, ack=ack) / Raw(payload)) def handshake(sip, dip, sp, dp): return [tcp_pkt(sip, dip, sp, dp, "S"), tcp_pkt(dip, sip, dp, sp, "SA", seq=5000, ack=101), tcp_pkt(sip, dip, sp, dp, "A", seq=101, ack=501)] # --- benign: a couple of plain HTTP-ish flows + a UDP DNS query flow pkts = [] for i, (sp, host) in enumerate([(51000, "example.com"), (51002, "example.org")]): sip, dip = "10.0.0.5", "93.184.216.%d" % (34 + i) req = ("GET / HTTP/1.1\r\nHost: %s\r\nUser-Agent: demo/1.0\r\nAccept: */*\r\n\r\n" % host).encode() resp = ("HTTP/1.1 200 OK\r\nContent-Type: text/html\r\nContent-Length: 21\r\n\r\nhello").encode() pkts += handshake(sip, dip, sp, 80) pkts += [tcp_pkt(sip, dip, sp, 80, "PA", req, seq=101), tcp_pkt(dip, sip, 80, sp, "PA", resp, seq=501, ack=101 + len(req))] # DNS pkts += [Ether() / IP(src="10.0.0.5", dst="10.0.0.1") / UDP(sport=53000, dport=53) / DNS(rd=1, qd=DNSQR(qname="example.com")), Ether() / IP(src="10.0.0.1", dst="10.0.0.5") / UDP(sport=53, dport=53000) / DNS(aa=1, qd=DNSQR(qname="example.com"), an=DNSRR(rrname="example.com", rdata="93.184.216.34"))] wrpcap("examples/benign.pcap", pkts) # --- scan: one source probing many TCP ports (SYN only, no payload) pkts = [] for dp in [21, 22, 23, 25, 53, 80, 110, 135, 139, 143, 443, 445, 993, 995, 1433, 3306, 3389, 5432, 5900, 6379, 8080, 8443, 9200, 27017, 11211]: pkts.append(tcp_pkt("10.0.0.99", "10.0.0.9", 40125, dp, "S")) wrpcap("examples/scan.pcap", pkts) # --- exploit-like: payload traffic with a NOP sled + shellcode-shaped bytes sled = b"\x90" * 48 shell = bytes([0x31, 0xc0, 0x50, 0x68, 0x2f, 0x2f, 0x73, 0x68, 0x68, 0x2f, 0x62, 0x69, 0x6e, 0x89, 0xe3, 0x50, 0x89, 0xe2, 0x53, 0x89, 0xe1, 0xb0, 0x0b, 0xcd, 0x80]) pkts = [] sip, dip = "10.0.0.66", "10.0.0.9" pkts += handshake(sip, dip, 49152, 4444) pkts += [tcp_pkt(sip, dip, 49152, 4444, "PA", sled + shell, seq=101), tcp_pkt(sip, dip, 49152, 4444, "PA", sled + shell, seq=101 + 73)] wrpcap("examples/exploit.pcap", pkts) print("examples written:", os.listdir("examples"))