Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
aiengine — AIEngine 是下一代交互式/可编程的 Python/Ruby/Java/Lua 和 Go NIDS(网络入侵检测系统)。 | Kitploit
工具/BitbucketBitbucket/camp0/aiengine
防御工具网络取证网络安全威胁情报机器学习入侵检测DNS 分析异常检测
Bitbucketcamp0/aiengine

aiengine

AIEngine 是下一代交互式/可编程的 Python/Ruby/Java/Lua 和 Go NIDS(网络入侵检测系统)。

查看仓库
263年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Documentation Status codecov coverity CII Best Practices Python 2.7|3.5|3.6|3.7|3.8|3.9 Lua 5.1|5.2|5.4 Go 1.15 License LGTM Grade LGTM Grade

AIEngine(人工智能引擎)

AIEngine 是一种下一代交互式/可编程的 Python/Ruby/Java/Lua 和 Go 网络入侵检测系统引擎,具备无需人工干预的学习能力、DNS 域名分类、垃圾邮件检测、网络数据采集、网络取证等功能。

AIEngine 还能帮助网络/安全专业人员识别流量并为 NIDS、防火墙、流量分类器等设备开发签名。

AIEngine 的主要功能包括:

  • 支持引擎运行时与用户交互/编程。
  • 支持 PCRE JIT 进行正则匹配。
  • 支持正则图(复杂检测模式)。
  • 支持六种网络栈(lan、mobile、lan6、virtual、oflow 和 mobile6)。
  • 支持 IP 查找的集合(Sets)和布隆过滤器(Bloom filters)。
  • 支持 x86_64、ARM 和 MIPS 架构,操作系统包括 Linux、FreeBSD 和 MacOS。
  • 支持 HTTP、DNS 和 SSL 域名匹配。
  • 支持 HTTP、DNS、SMTP 和 SSL 的域名和主机禁用。
  • 未知流量的频率分析和自动正则生成。
  • 生成 Yara 签名。
  • 易于与数据库(MySQL、Redis、Cassandra、Hadoop 等)集成以进行数据关联。
  • 易于与其他数据包引擎(Netfilter)集成。
  • 支持内存清理缓存以刷新存储的内存信息。
  • 支持在网络/应用层检测 DDoS。
  • 支持拒绝 TCP/UDP 连接。
  • 支持实时网络取证。
  • 支持 SSL 上的 JA3 TLS 签名。
  • 支持以下协议:Bitcoin、CoAP、DHCPv4/DHCPv6、DNS、DTLS、GPRS、GRE、HTTP、 ICMPv4/ICMPv6、IMAP、IPv4/v6、Modbus、MPLS、MQTT、Netbios、NTP、OpenFlow、PPPoE、 POP、Quic、RTP、SIP、SMB、SMTP、SSDP、SSH、SSL、TCP、UDP、VLAN、VXLAN。
  • 集成 HTTP 服务器以实时检索和配置系统。

更多信息请查看 docs 文件夹

使用 AIEngine

要使用 AIEngine(简化版本),只需执行 aiengine 二进制文件或使用 Python/Ruby/Java/Lua 绑定。

luis@luis-xps:~/c++/aiengine/src$ ./aiengine -h
aiengine 2.1.0
Mandatory arguments:
  -I [ --input ] arg                Sets the network interface ,pcap file or 
                                    directory with pcap files.

Link Layer optional arguments:
  -q [ --tag ] arg      Selects the tag type of the ethernet layer (vlan,mpls).

TCP optional arguments:
  -t [ --tcp-flows ] arg (=32768) Sets the number of TCP flows on the pool.

UDP optional arguments:
  -u [ --udp-flows ] arg (=16384) Sets the number of UDP flows on the pool.

    Domain optional arguments:
      -D [ --domain-file ] arg             Reads domain names from file.
      -B [ --domain-protocol ] arg (=dns)  Protocol to plug the domain-file (dns, 
                                           ssl, http).
      -S [ --matched-domain ]              Shows only the domains that matches.

Regex optional arguments:
  -R [ --enable-signatures ]     Enables the Signature engine.
  -r [ --regex ] arg (=.*)       Sets the regex for evaluate agains the flows.
  -c [ --flow-class ] arg (=all) Uses tcp, udp or all for matches the signature
				 on the flows.
  -m [ --matched-flows ]         Shows the flows that matchs with the regex.
  -M [ --matched-packet ]        Shows the packet payload that matchs with 
    	                         the regex.
  -C [ --continue ]              Continue evaluating the regex with the 
                                 next packets of the Flow.
  -j [ --reject-flows ]          Rejects the flows that matchs with the 
                                     regex.
  -w [ --evidence ]              Generates a pcap file with the matching 
                                     regex for forensic analysis.

Frequencies optional arguments:
  -F [ --enable-frequencies ]       Enables the Frequency engine.
  -g [ --group-by ] arg (=dst-port) Groups frequencies by src-ip,dst-ip,src-por
				    t and dst-port.
  -f [ --flow-type ] arg (=tcp)     Uses tcp or udp flows.
  -L [ --enable-learner ]           Enables the Learner engine.
  -k [ --key-learner ] arg (=80)    Sets the key for the Learner engine.
  -b [ --buffer-size ] arg (=64)    Sets the size of the internal buffer for 
    	                            generate the regex.
      -Q [ --byte-quality ] arg (=80)   Sets the minimum quality for the bytes of 
                                        the generated regex.
  -y [ --enable-yara ]              Generates a yara signature.

Optional arguments:
  -n [ --stack ] arg (=lan)    Sets the network stack (lan,mobile,lan6,virtual,
			       oflow).
  -d [ --dumpflows ]           Dump the flows to stdout.
  -s [ --statistics ] arg (=0) Show statistics of the network stack (5 levels).
  -T [ --timeout ] arg (=180)  Sets the flows timeout.
  -P [ --protocol ] arg        Show statistics of a specific protocol of the 
                                   network stack.
  -a [ --port ] arg (=0)       Sets the HTTP listenting port.
  -e [ --release ]             Release the caches.
  -l [ --release-cache ] arg   Release a specific cache.
  -p [ --pstatistics ]         Show statistics of the process.
      -o [ --summary ]             Show protocol summmary statistics 
                                   (bytes,packets,% bytes,cache miss,memory).
  -h [ --help ]                Show help.
  -v [ --version ]             Show version string.

网络栈类型

AIEngine 支持六种网络栈,具体取决于网络拓扑。

  • StackLan (lan) 基于 IPv4 的局域网。

  • StackLanIPv6 (lan6) 支持 IPv6 的局域网。

  • StackMobile (mobile) 用于 IPv4 的移动网络(Gn 接口)。

  • StackVirtual (virtual) 用于虚拟/云环境的栈,支持 VxLan 和 GRE 透明传输。

  • StackOpenFlow (oflow) 用于 OpenFlow 环境的栈。

  • StackMobileIPv6 (mobile6) 用于 IPv6 的移动网络(Gn 接口)。

将 AIEngine 集成/编程到其他系统

AIEngine 也是一个 Python/Ruby/Java/Lua 模块,允许更灵活地集成到其他系统和功能中。Python 模块提供的主要导出对象如下:

    BitcoinInfo
    Cache
    CoAPInfo
    DCERCPInfo
    DHCPInfo
    DHCPv6Info
    DNSInfo
    DTLSInfo
    DatabaseAdaptor
    DomainName
    DomainNameManager
    Flow
    FlowManager
    Frequencies
    FrequencyGroup
    HTTPInfo
    HTTPUriSet
    IMAPInfo
    IPAbstractSet
        IPRadixTree
        IPSet
    IPSetManager
    LearnerEngine
    MQTTInfo
    NetbiosInfo
    NetworkStack
        StackLan
        StackLanIPv6
        StackMobile
        StackMobileIPv6
        StackOpenFlow
        StackVirtual
    POPInfo
    PacketDispatcher
    PacketFrequencies
    QuicInfo
    Regex
    RegexManager
    SIPInfo
    SMBInfo
    SMTPInfo
    SSDPInfo
    SSHInfo
    SSLInfo
    TCPInfo

关于 Python 中类方法的完整描述

import pyaiengine
help(pyaiengine)

请查看 examples 目录以获取有用的用例,并查看 /docs 目录获取文档

编译 AIEngine 二进制文件

您的系统至少需要安装 pcre-devel、libpcap-devel 和 boost-devel。

$ git clone https://bitbucket.com/camp0/aiengine
$ ./autogen.sh
$ ./configure
$ make

可选功能

系统根据您的需求提供以下启用/禁用功能。

下载工具