16 | | = [wiki:ExperimentLog1 實驗一] = |
17 | | |
18 | | 格式: |
| 16 | = [wiki:ExperimentLog3 實驗一] = |
| 17 | * select * from flex; |
| 18 | 98 row(s) in set. (0.30 sec) |
| 19 | * 格式: |
| 20 | |
| 21 | $dst_IP |
| 22 | || Column Family : Column Qulify || cell value || |
| 23 | || direction:dstport || $dst_port || |
| 24 | || direction:soure || $src_IP || |
| 25 | || direction:srcport || $src_port || |
| 26 | || id:gid || $generation_id || |
| 27 | || id:priority || $priority || |
| 28 | || id:sid || $sid || |
| 29 | || id:version || $version || |
| 30 | || name:class || $class || |
| 31 | || name:name || $alert_name || |
| 32 | || payload:type || $type || |
| 33 | |
| 34 | * 範例: |
| 35 | {{{ |
| 36 | #!html |
| 37 | |
| 38 | <table> |
| 39 | |
| 40 | <tbody><tr> |
| 41 | <th> |
| 42 | Row |
| 43 | </th> |
| 44 | <th> |
| 45 | Column |
| 46 | </th> |
| 47 | <th> |
| 48 | Cell |
| 49 | </th> |
| 50 | </tr> |
| 51 | <tr> |
| 52 | |
| 53 | <td> |
| 54 | 105.175.203.246 |
| 55 | </td> |
| 56 | <td> |
| 57 | direction:dstport |
| 58 | </td> |
| 59 | <td> |
| 60 | 0 |
| 61 | </td> |
| 62 | </tr> |
| 63 | <tr> |
| 64 | <td> |
| 65 | |
| 66 | 105.175.203.246 |
| 67 | </td> |
| 68 | <td> |
| 69 | direction:soure |
| 70 | </td> |
| 71 | <td> |
| 72 | 168.150.177.165 |
| 73 | </td> |
| 74 | </tr> |
| 75 | <tr> |
| 76 | <td> |
| 77 | 105.175.203.246 |
| 78 | </td> |
| 79 | |
| 80 | <td> |
| 81 | direction:srcport |
| 82 | </td> |
| 83 | <td> |
| 84 | 0 |
| 85 | </td> |
| 86 | </tr> |
| 87 | <tr> |
| 88 | <td> |
| 89 | 105.175.203.246 |
| 90 | </td> |
| 91 | <td> |
| 92 | |
| 93 | id:gid |
| 94 | </td> |
| 95 | <td> |
| 96 | 1 |
| 97 | </td> |
| 98 | </tr> |
| 99 | <tr> |
| 100 | <td> |
| 101 | 105.175.203.246 |
| 102 | </td> |
| 103 | <td> |
| 104 | id:priority |
| 105 | </td> |
| 106 | |
| 107 | <td> |
| 108 | 3 |
| 109 | </td> |
| 110 | </tr> |
| 111 | <tr> |
| 112 | <td> |
| 113 | 105.175.203.246 |
| 114 | </td> |
| 115 | <td> |
| 116 | id:sid |
| 117 | </td> |
| 118 | <td> |
| 119 | |
| 120 | 402 |
| 121 | </td> |
| 122 | </tr> |
| 123 | <tr> |
| 124 | <td> |
| 125 | 105.175.203.246 |
| 126 | </td> |
| 127 | <td> |
| 128 | id:version |
| 129 | </td> |
| 130 | <td> |
| 131 | 7 |
| 132 | </td> |
| 133 | |
| 134 | </tr> |
| 135 | <tr> |
| 136 | <td> |
| 137 | 105.175.203.246 |
| 138 | </td> |
| 139 | <td> |
| 140 | name:class |
| 141 | </td> |
| 142 | <td> |
| 143 | Misc activity |
| 144 | </td> |
| 145 | </tr> |
| 146 | |
| 147 | <tr> |
| 148 | <td> |
| 149 | 105.175.203.246 |
| 150 | </td> |
| 151 | <td> |
| 152 | name:name |
| 153 | </td> |
| 154 | <td> |
| 155 | ICMP Destination Unreachable Port Unreachable |
| 156 | </td> |
| 157 | </tr> |
| 158 | <tr> |
| 159 | |
| 160 | <td> |
| 161 | 105.175.203.246 |
| 162 | </td> |
| 163 | <td> |
| 164 | payload:type |
| 165 | </td> |
| 166 | <td> |
| 167 | ICMP |
| 168 | </td></tr></tbody></table> |
| 169 | }}} |
| 170 | |
| 171 | |
| 172 | = [wiki:ExperimentLog1 實驗二] = |
| 173 | |
| 174 | * 目的 : |
| 175 | 矯正不同攻擊在同一個目標ip只能紀錄最後一筆的問題 |
| 176 | |
| 177 | * 格式: |
103 | | = [wiki:ExperimentLog3 實驗三] = |
104 | | * select * from flex; |
105 | | 98 row(s) in set. (0.30 sec) |
106 | | * 格式: |
107 | | |
108 | | $dst_IP |
109 | | || Column Family : Column Qulify || cell value || |
110 | | || direction:dstport || 0 || |
111 | | || direction:soure || 168.150.177.165 || |
112 | | || direction:srcport || 0 || |
113 | | || id:gid || 1 || |
114 | | || id:priority || 3 || |
115 | | || id:sid || 402 || |
116 | | || id:version || 7 || |
117 | | || name:class || Misc activity || |
118 | | || name:name || ICMP Destination Unreachable Port Unreachable || |
119 | | || payload:type || ICMP || |
120 | | |
121 | | * 範例: |
122 | | {{{ |
123 | | #!html |
124 | | |
125 | | <table> |
126 | | |
127 | | <tbody><tr> |
128 | | <th> |
129 | | Row |
130 | | </th> |
131 | | <th> |
132 | | Column |
133 | | </th> |
134 | | <th> |
135 | | Cell |
136 | | </th> |
137 | | </tr> |
138 | | <tr> |
139 | | |
140 | | <td> |
141 | | 105.175.203.246 |
142 | | </td> |
143 | | <td> |
144 | | direction:dstport |
145 | | </td> |
146 | | <td> |
147 | | 0 |
148 | | </td> |
149 | | </tr> |
150 | | <tr> |
151 | | <td> |
152 | | |
153 | | 105.175.203.246 |
154 | | </td> |
155 | | <td> |
156 | | direction:soure |
157 | | </td> |
158 | | <td> |
159 | | 168.150.177.165 |
160 | | </td> |
161 | | </tr> |
162 | | <tr> |
163 | | <td> |
164 | | 105.175.203.246 |
165 | | </td> |
166 | | |
167 | | <td> |
168 | | direction:srcport |
169 | | </td> |
170 | | <td> |
171 | | 0 |
172 | | </td> |
173 | | </tr> |
174 | | <tr> |
175 | | <td> |
176 | | 105.175.203.246 |
177 | | </td> |
178 | | <td> |
179 | | |
180 | | id:gid |
181 | | </td> |
182 | | <td> |
183 | | 1 |
184 | | </td> |
185 | | </tr> |
186 | | <tr> |
187 | | <td> |
188 | | 105.175.203.246 |
189 | | </td> |
190 | | <td> |
191 | | id:priority |
192 | | </td> |
193 | | |
194 | | <td> |
195 | | 3 |
196 | | </td> |
197 | | </tr> |
198 | | <tr> |
199 | | <td> |
200 | | 105.175.203.246 |
201 | | </td> |
202 | | <td> |
203 | | id:sid |
204 | | </td> |
205 | | <td> |
206 | | |
207 | | 402 |
208 | | </td> |
209 | | </tr> |
210 | | <tr> |
211 | | <td> |
212 | | 105.175.203.246 |
213 | | </td> |
214 | | <td> |
215 | | id:version |
216 | | </td> |
217 | | <td> |
218 | | 7 |
219 | | </td> |
220 | | |
221 | | </tr> |
222 | | <tr> |
223 | | <td> |
224 | | 105.175.203.246 |
225 | | </td> |
226 | | <td> |
227 | | name:class |
228 | | </td> |
229 | | <td> |
230 | | Misc activity |
231 | | </td> |
232 | | </tr> |
233 | | |
234 | | <tr> |
235 | | <td> |
236 | | 105.175.203.246 |
237 | | </td> |
238 | | <td> |
239 | | name:name |
240 | | </td> |
241 | | <td> |
242 | | ICMP Destination Unreachable Port Unreachable |
243 | | </td> |
244 | | </tr> |
245 | | <tr> |
246 | | |
247 | | <td> |
248 | | 105.175.203.246 |
249 | | </td> |
250 | | <td> |
251 | | payload:type |
252 | | </td> |
253 | | <td> |
254 | | ICMP |
255 | | </td></tr></tbody></table> |
256 | | }}} |