pub struct Connection {
pub five_tuple: FiveTuple,
pub ts: Instant,
pub duration: Duration,
pub max_inactivity: Duration,
pub time_to_second_packet: Duration,
pub history: Vec<u8>,
pub orig: Flow,
pub resp: Flow,
}Expand description
A connection record.
This subscribable type returns general information regarding TCP and UDP connections but does does not track payload data. If applicable, Retina internally manages stream reassembly. All connections are interpreted using flow semantics.
Fields§
§five_tuple: FiveTupleThe connection 5-tuple.
ts: InstantTimestamp of the first packet.
§Remarks
This represents the time Retina observed the first packet in the connection, and does not reflect timestamps read from a packet capture in offline analysis.
duration: DurationThe duration of the connection.
§Remarks
This does not represent the actual duration of the connection in offline analysis. It approximates the elapsed time between observation of the first and last observed packet in the connection.
max_inactivity: DurationMaximum duration of inactivity (the maximum time between observed segments).
time_to_second_packet: DurationThe duration between the first and second packets.
history: Vec<u8>Connection history.
This represents a summary of the connection history in the order the packets were observed, with letters encoded as a vector of bytes. This is a simplified version of state history in Zeek, and the meanings of each letter are similar: If the event comes from the originator, the letter is uppercase; if the event comes from the responder, the letter is lowercase.
- S: a pure SYN with only the SYN bit set (may have payload)
- H: a pure SYNACK with only the SYN and ACK bits set (may have payload)
- A: a pure ACK with only the ACK bit set and no payload
- D: segment contains non-zero payload length
- F: the segment has the FIN bit set (may have other flags and/or payload)
- R: segment has the RST bit set (may have other flags and/or payload)
Each letter is recorded a maximum of once in either direction.
orig: FlowOriginator flow.
resp: FlowResponder flow.
Implementations§
Source§impl Connection
impl Connection
Sourcepub fn client(&self) -> SocketAddr
pub fn client(&self) -> SocketAddr
Returns the client (originator) socket address.
Sourcepub fn server(&self) -> SocketAddr
pub fn server(&self) -> SocketAddr
Returns the server (responder) socket address.
Sourcepub fn total_pkts(&self) -> u64
pub fn total_pkts(&self) -> u64
Returns the total number of packets observed in the connection.
Sourcepub fn total_bytes(&self) -> u64
pub fn total_bytes(&self) -> u64
Returns the total number of payload bytes observed, excluding those from malformed packets.
Trait Implementations§
Source§impl Debug for Connection
impl Debug for Connection
Source§impl Display for Connection
impl Display for Connection
Source§impl Serialize for Connection
impl Serialize for Connection
Source§impl Subscribable for Connection
impl Subscribable for Connection
type Tracked = TrackedConnection
Source§fn parsers() -> Vec<ConnParser>
fn parsers() -> Vec<ConnParser>
Source§fn process_packet(
mbuf: Mbuf,
subscription: &Subscription<'_, Self>,
conn_tracker: &mut ConnTracker<Self::Tracked>,
)
fn process_packet( mbuf: Mbuf, subscription: &Subscription<'_, Self>, conn_tracker: &mut ConnTracker<Self::Tracked>, )
Auto Trait Implementations§
impl Freeze for Connection
impl RefUnwindSafe for Connection
impl Send for Connection
impl Sync for Connection
impl Unpin for Connection
impl UnsafeUnpin for Connection
impl UnwindSafe for Connection
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more