
네트워크 검사 도구
네트워크 트래픽 검사 도구
이 도구는 libnids (Jon Oberheide의 파이썬 바인딩: pynids)를 통해 IP 단편화를 해제하고 TCP 패킷을 재조립하여 (UDP는 패킷 단위로 검사됨) 네트워크 플로우를 생성합니다. 그런 다음 이러한 플로우는 네 가지 검사 모드 중 하나를 사용하여 검사됩니다:
정규식 매칭은 re2 라이브러리와 그 파이썬 바인딩인 pyre2를 사용하여 수행되며, PCRE, 대소문자 구분 없음, 반전 및 여러 줄 매칭 등을 지원합니다. 이는 파이썬 내장 re 모듈(만약 re2가 설치되지 않은 경우 대체로 사용됨)에 비해 엄청난 성능 향상을 제공합니다.
퍼지 문자열 매칭 기능은 fuzzywuzzy 모듈을 통해 수행됩니다. 정확한 문자열 매칭과 상대적 문자열 매칭을 모두 수행하는 데 도움이 됩니다. 기본 매치 임계값 75가 기본값으로 사용되며 CLI를 통해 재정의할 수 있습니다.
Libemu와 그 파이썬 바인딩인 pylibemu는 쉘코드 탐지에 사용됩니다. libemu에서 사용하는 GetPC 휴리스틱은 적절한 탐지율을 제공합니다. libemu가 실패하는 몇 가지 경우가 있지만 대부분의 사용 사례에서는 충분히 좋습니다.
Yara는 시그니처 기반의 악성코드 식별 및 분류 도구입니다. yara-python 바인딩은 네트워크 스트림인 입력 버퍼에 기존/사용자 정의 시그니처 파일을 사용할 수 있는 API를 제공합니다.
검사는 CTS/STC/ANY 방향 또는 그 조합 중 하나로 요청될 수 있습니다. 검사 버퍼는 네트워크 트래픽이 도착함에 따라 채워지므로 CTS 일치(CTS 또는 ANY)가 먼저 발생합니다. 둘 이상의 검사 모드가 요청되면 플로우는 다음 순서로 검사됩니다: 정규식, 퍼지, libemu, 마지막으로 yara. TCP의 경우, 어떤 검사 모드든 성공하면 일치된 플로우는 더 이상 검사되지 않습니다. 이는 낙관적 접근 방식이며 기본적으로 활성화되어 있습니다. 그러나 특정 사용 사례에서 TCP 스트림을 여러 번 검사해야 하는 경우 CLI를 통해 명시적으로 요청할 수 있습니다.
필요한 경우 CLI의 linemode 옵션을 통해 검사를 완전히 비활성화할 수 있습니다. 이 모드는 매우 유용하며 적절한 outmode와 결합하면 통신이 유선 상에서 발생하는 그대로를 확인하는 데 도움이 됩니다. CLI를 통해 검사 모드가 제공되지 않으면 linemode가 자동으로 대체로 활성화됩니다.
UDP의 경우 일치는 패킷 단위로 발생하므로 UDP 플로우에서 이미 일치가 발견된 후에도 후속 패킷이 테스트됩니다. 후속 패킷과 그 내용만 검사되므로 이전 검사 주기에서 이미 일치된 데이터는 다시 검사되지 않습니다.
일치 범위는 BPF 표현식, Snort 유사 offset-depth 콘텐츠 수정자 또는 패킷/스트림 검사 제한 CLI 옵션을 통해 제한될 수 있습니다. TCP의 경우 필요하면 일치된 플로우를 종료할 수도 있습니다. 플로우는 stdout에 덤프되는 것 외에도 파일에 기록될 수 있습니다. 몇 가지 유용한 출력 모드(quite, meta, hex, print, raw)가 추가 분석에 도움이 됩니다. 특히 meta outmode는 일치된 콘텐츠의 총 크기, 네트워크 스트림에서 일치 시작 오프셋, 일치가 걸쳐 있는 패킷 ID, 일치가 발생한 패킷의 방향 등과 같은 매우 중요한 일치 관련 세부 정보를 보여주므로 특히 유용합니다.
일치하는 플로우에 대한 pcap 생성도 지원됩니다. 활성화되면 시작부터 플로우 끝까지 모든 패킷을 덤프합니다. 일치된 TCP 플로우는 close/reset이 보이면 덤프되며, close/reset이 보이지 않는 플로우는 도구가 종료되기 전에 덤프됩니다. UDP의 경우 close/reset과 같은 상태 정보가 없으므로 도구가 종료될 때만 덤프됩니다. 이렇게 하면 일치 후에 도착하는 패킷까지 포함하여 모든 패킷이 플로우 pcap에 캡처됩니다. 사용자 정의 pcap 글로벌 헤더, 패킷별 pcap 헤더 및 Ethernet II L2 헤더(flowinspect에서 볼 수 없음)를 제외하고, 그 위의 모든 것은 덤프된 패킷 캡처에서 그대로 유지됩니다.
도움말: -----```c ______ _ __ / / /_ _ () _________ ___ / / / // / __ \ | /| / / / __ / / __ / _ / / __/ / __/ / // / |/ |/ / / / / ( ) // / / // / // //_/|/|/// /// ._/_/___/_/ //
flowinspect v0.2 - A network inspection tool Ankur Tyagi (7h3rAm [at] gmail [dot] com)
usage: flowinspect.py [-h] (-p --pcap | -d --device) [-c --cregex] [-s --sregex] [-a --aregex] [-i] [-m] [-G --cfuzz] [-H --sfuzz] [-I --afuzz] [-r fuzzminthreshold] [-C --cdfa] [-S --sdfa] [-A --adfa] [-l] [-X --dfaexpr] [-g [graphdir]] [-P --cyararules] [-Q --syararules] [-R --ayararules] [-M] [-y] [-Y --emuprofileoutsize] [-O --offset] [-D --depth] [-T --maxinspstreams] [-U --maxinsppackets] [-t --maxdispstreams] [-u --maxdisppackets] [-b --maxdispbytes] [-w [logdir]] [-o {quite,meta,hex,print,raw}] [-f --bpf] [-v] [-V] [-e] [-k] [-j] [-Z] [-n] [-L]
optional arguments: -h, --help show this help message and exit -p --pcap input pcap file -d --device listening device
RegEx per Direction: -c --cregex regex to match against CTS data -s --sregex regex to match against STC data -a --aregex regex to match against ANY data
RegEx Options: -i ignore case -m disable multiline match
Fuzzy Patterns per Direction: -G --cfuzz string to fuzzy match against CTS data -H --sfuzz string to fuzzy match against STC data -I --afuzz string to fuzzy match against ANY data
Fuzzy Options: -r fuzzminthreshold threshold for fuzzy match (1-100) - default 75
DFAs per Direction ('m[0-9][1-9]='): -C --cdfa DFA expression to match against CTS data -S --sdfa DFA expression to match against STC data -A --adfa DFA expression to match against ANY data
DFA Options: -l switch default boolean operator to 'or' -X --dfaexpr expression to test chain members -g [graphdir] generate DFA transitions graph
Yara Rules per Direction: -P --cyararules Yara rules to match on CTS data -Q --syararules Yara rules to match on STC data -R --ayararules Yara rules to match on ANY data
Shellcode Detection: -M enable shellcode detection -y generate emulator profile for detected shellcode -Y --emuprofileoutsize emulator profile memory size (default 1024K | max: 10240K)
Content Modifiers: -O --offset bytes to skip before matching -D --depth bytes to look at while matching (starting from offset)
Inspection Limits: -T --maxinspstreams max streams to inspect -U --maxinsppackets max packets to inspect
Display Limits: -t --maxdispstreams max streams to display -u --maxdisppackets max packets to display -b --maxdispbytes max bytes to display
Output Options: -w [logdir] write matching packets/streams -o {quite,meta,hex,print,raw} match output modes
Misc. Options: -f --bpf BPF expression -v invert match -V verbose output -e highlight CTS/STC matches -k kill matching TCP stream -j enable TCP multi match mode -Z write matching flows to pcap -n confirm before initializing NIDS -L enable linemode (disables inspection)
예시:
---------
__실시간 HTTP 세션 보기__:```c
./flowinspect.py -d eth0 -c "^(GET|POST|HEAD|PUT).*" -f "tcp and port 80" -o print
GET / HTTP/1.1
User-Agent: curl/7.22.0 (i686-pc-linux-gnu) libcurl/7.22.0 OpenSSL/1.0.1 zlib/1.2.3.4 libidn/1.23 librtmp/2.3
Host: www.google.com
Accept: */*
[U] Processed: 0 | Matches: 0 | Shortest: 0B (#0) | Longest: 0B (#0)
[T] Processed: 1 | Matches: 1 | Shortest: 164B (#1) | Longest: 164B (#1)
Metasploit ie_cgenericelement_uaf 익스플로잇(CVE-2013-1347)에 대한 HTTP 스트림 검사:```c ./flowinspect.py -p cgenericelement.pcap -s 'CollectGarbage().*mstime_malloc({shellcode:' -b32