| 16 | | = [wiki:ExperimentLog1 實驗一] = |
| 17 | | |
| 18 | | 格式: |
| | 16 | = [wiki:ExperimentLog3 實驗一] = |
| | 17 | * select * from flex; |
| | 18 | 98 row(s) in set. (0.30 sec) |
| | 19 | * 格式: |
| | 20 | |
| | 21 | $dst_IP |
| | 22 | || Column Family : Column Qulify || cell value || |
| | 23 | || direction:dstport || $dst_port || |
| | 24 | || direction:soure || $src_IP || |
| | 25 | || direction:srcport || $src_port || |
| | 26 | || id:gid || $generation_id || |
| | 27 | || id:priority || $priority || |
| | 28 | || id:sid || $sid || |
| | 29 | || id:version || $version || |
| | 30 | || name:class || $class || |
| | 31 | || name:name || $alert_name || |
| | 32 | || payload:type || $type || |
| | 33 | |
| | 34 | * 範例: |
| | 35 | {{{ |
| | 36 | #!html |
| | 37 | |
| | 38 | <table> |
| | 39 | |
| | 40 | <tbody><tr> |
| | 41 | <th> |
| | 42 | Row |
| | 43 | </th> |
| | 44 | <th> |
| | 45 | Column |
| | 46 | </th> |
| | 47 | <th> |
| | 48 | Cell |
| | 49 | </th> |
| | 50 | </tr> |
| | 51 | <tr> |
| | 52 | |
| | 53 | <td> |
| | 54 | 105.175.203.246 |
| | 55 | </td> |
| | 56 | <td> |
| | 57 | direction:dstport |
| | 58 | </td> |
| | 59 | <td> |
| | 60 | 0 |
| | 61 | </td> |
| | 62 | </tr> |
| | 63 | <tr> |
| | 64 | <td> |
| | 65 | |
| | 66 | 105.175.203.246 |
| | 67 | </td> |
| | 68 | <td> |
| | 69 | direction:soure |
| | 70 | </td> |
| | 71 | <td> |
| | 72 | 168.150.177.165 |
| | 73 | </td> |
| | 74 | </tr> |
| | 75 | <tr> |
| | 76 | <td> |
| | 77 | 105.175.203.246 |
| | 78 | </td> |
| | 79 | |
| | 80 | <td> |
| | 81 | direction:srcport |
| | 82 | </td> |
| | 83 | <td> |
| | 84 | 0 |
| | 85 | </td> |
| | 86 | </tr> |
| | 87 | <tr> |
| | 88 | <td> |
| | 89 | 105.175.203.246 |
| | 90 | </td> |
| | 91 | <td> |
| | 92 | |
| | 93 | id:gid |
| | 94 | </td> |
| | 95 | <td> |
| | 96 | 1 |
| | 97 | </td> |
| | 98 | </tr> |
| | 99 | <tr> |
| | 100 | <td> |
| | 101 | 105.175.203.246 |
| | 102 | </td> |
| | 103 | <td> |
| | 104 | id:priority |
| | 105 | </td> |
| | 106 | |
| | 107 | <td> |
| | 108 | 3 |
| | 109 | </td> |
| | 110 | </tr> |
| | 111 | <tr> |
| | 112 | <td> |
| | 113 | 105.175.203.246 |
| | 114 | </td> |
| | 115 | <td> |
| | 116 | id:sid |
| | 117 | </td> |
| | 118 | <td> |
| | 119 | |
| | 120 | 402 |
| | 121 | </td> |
| | 122 | </tr> |
| | 123 | <tr> |
| | 124 | <td> |
| | 125 | 105.175.203.246 |
| | 126 | </td> |
| | 127 | <td> |
| | 128 | id:version |
| | 129 | </td> |
| | 130 | <td> |
| | 131 | 7 |
| | 132 | </td> |
| | 133 | |
| | 134 | </tr> |
| | 135 | <tr> |
| | 136 | <td> |
| | 137 | 105.175.203.246 |
| | 138 | </td> |
| | 139 | <td> |
| | 140 | name:class |
| | 141 | </td> |
| | 142 | <td> |
| | 143 | Misc activity |
| | 144 | </td> |
| | 145 | </tr> |
| | 146 | |
| | 147 | <tr> |
| | 148 | <td> |
| | 149 | 105.175.203.246 |
| | 150 | </td> |
| | 151 | <td> |
| | 152 | name:name |
| | 153 | </td> |
| | 154 | <td> |
| | 155 | ICMP Destination Unreachable Port Unreachable |
| | 156 | </td> |
| | 157 | </tr> |
| | 158 | <tr> |
| | 159 | |
| | 160 | <td> |
| | 161 | 105.175.203.246 |
| | 162 | </td> |
| | 163 | <td> |
| | 164 | payload:type |
| | 165 | </td> |
| | 166 | <td> |
| | 167 | ICMP |
| | 168 | </td></tr></tbody></table> |
| | 169 | }}} |
| | 170 | |
| | 171 | |
| | 172 | = [wiki:ExperimentLog1 實驗二] = |
| | 173 | |
| | 174 | * 目的 : |
| | 175 | 矯正不同攻擊在同一個目標ip只能紀錄最後一筆的問題 |
| | 176 | |
| | 177 | * 格式: |
| 103 | | = [wiki:ExperimentLog3 實驗三] = |
| 104 | | * select * from flex; |
| 105 | | 98 row(s) in set. (0.30 sec) |
| 106 | | * 格式: |
| 107 | | |
| 108 | | $dst_IP |
| 109 | | || Column Family : Column Qulify || cell value || |
| 110 | | || direction:dstport || 0 || |
| 111 | | || direction:soure || 168.150.177.165 || |
| 112 | | || direction:srcport || 0 || |
| 113 | | || id:gid || 1 || |
| 114 | | || id:priority || 3 || |
| 115 | | || id:sid || 402 || |
| 116 | | || id:version || 7 || |
| 117 | | || name:class || Misc activity || |
| 118 | | || name:name || ICMP Destination Unreachable Port Unreachable || |
| 119 | | || payload:type || ICMP || |
| 120 | | |
| 121 | | * 範例: |
| 122 | | {{{ |
| 123 | | #!html |
| 124 | | |
| 125 | | <table> |
| 126 | | |
| 127 | | <tbody><tr> |
| 128 | | <th> |
| 129 | | Row |
| 130 | | </th> |
| 131 | | <th> |
| 132 | | Column |
| 133 | | </th> |
| 134 | | <th> |
| 135 | | Cell |
| 136 | | </th> |
| 137 | | </tr> |
| 138 | | <tr> |
| 139 | | |
| 140 | | <td> |
| 141 | | 105.175.203.246 |
| 142 | | </td> |
| 143 | | <td> |
| 144 | | direction:dstport |
| 145 | | </td> |
| 146 | | <td> |
| 147 | | 0 |
| 148 | | </td> |
| 149 | | </tr> |
| 150 | | <tr> |
| 151 | | <td> |
| 152 | | |
| 153 | | 105.175.203.246 |
| 154 | | </td> |
| 155 | | <td> |
| 156 | | direction:soure |
| 157 | | </td> |
| 158 | | <td> |
| 159 | | 168.150.177.165 |
| 160 | | </td> |
| 161 | | </tr> |
| 162 | | <tr> |
| 163 | | <td> |
| 164 | | 105.175.203.246 |
| 165 | | </td> |
| 166 | | |
| 167 | | <td> |
| 168 | | direction:srcport |
| 169 | | </td> |
| 170 | | <td> |
| 171 | | 0 |
| 172 | | </td> |
| 173 | | </tr> |
| 174 | | <tr> |
| 175 | | <td> |
| 176 | | 105.175.203.246 |
| 177 | | </td> |
| 178 | | <td> |
| 179 | | |
| 180 | | id:gid |
| 181 | | </td> |
| 182 | | <td> |
| 183 | | 1 |
| 184 | | </td> |
| 185 | | </tr> |
| 186 | | <tr> |
| 187 | | <td> |
| 188 | | 105.175.203.246 |
| 189 | | </td> |
| 190 | | <td> |
| 191 | | id:priority |
| 192 | | </td> |
| 193 | | |
| 194 | | <td> |
| 195 | | 3 |
| 196 | | </td> |
| 197 | | </tr> |
| 198 | | <tr> |
| 199 | | <td> |
| 200 | | 105.175.203.246 |
| 201 | | </td> |
| 202 | | <td> |
| 203 | | id:sid |
| 204 | | </td> |
| 205 | | <td> |
| 206 | | |
| 207 | | 402 |
| 208 | | </td> |
| 209 | | </tr> |
| 210 | | <tr> |
| 211 | | <td> |
| 212 | | 105.175.203.246 |
| 213 | | </td> |
| 214 | | <td> |
| 215 | | id:version |
| 216 | | </td> |
| 217 | | <td> |
| 218 | | 7 |
| 219 | | </td> |
| 220 | | |
| 221 | | </tr> |
| 222 | | <tr> |
| 223 | | <td> |
| 224 | | 105.175.203.246 |
| 225 | | </td> |
| 226 | | <td> |
| 227 | | name:class |
| 228 | | </td> |
| 229 | | <td> |
| 230 | | Misc activity |
| 231 | | </td> |
| 232 | | </tr> |
| 233 | | |
| 234 | | <tr> |
| 235 | | <td> |
| 236 | | 105.175.203.246 |
| 237 | | </td> |
| 238 | | <td> |
| 239 | | name:name |
| 240 | | </td> |
| 241 | | <td> |
| 242 | | ICMP Destination Unreachable Port Unreachable |
| 243 | | </td> |
| 244 | | </tr> |
| 245 | | <tr> |
| 246 | | |
| 247 | | <td> |
| 248 | | 105.175.203.246 |
| 249 | | </td> |
| 250 | | <td> |
| 251 | | payload:type |
| 252 | | </td> |
| 253 | | <td> |
| 254 | | ICMP |
| 255 | | </td></tr></tbody></table> |
| 256 | | }}} |