1 package edu.uci.iotproject;
3 import io.kaitai.struct.ByteBufferKaitaiStream;
4 import io.kaitai.struct.KaitaiStruct;
5 import io.kaitai.struct.KaitaiStream;
6 import java.io.IOException;
7 import java.util.ArrayList;
9 import java.util.HashMap;
13 * This is a system that reads PCAP files to compare
14 * patterns of DNS hostnames, packet sequences, and packet
15 * lengths with training data to determine certain events
16 * or actions for smart home devices.
18 * @author Janus Varmarken
19 * @author Rahmadi Trimananda (rtrimana@uci.edu)
26 * Private class properties
29 private List<Pcap.Packet> listPacket;
30 private Map<String, List<byte[]>> mapHostnamesToIPAddresses;
33 * Private class constants
35 private static final int DNS_PORT = 53;
40 * @param file name of the analyzed PCAP file
42 public Main(String file) throws IOException {
44 pcap = Pcap.fromFile(file);
45 listPacket = pcap.packets();
46 mapHostnamesToIPAddresses = new HashMap<String, List<byte[]>>();
51 * Private method that maps DNS hostnames to their
52 * respected IP addresses. This method iterates
53 * through the List<Pcap.Packet>, gets DNS packets,
54 * and gets the IP addresses associated with them.
56 private void mapHostnamesToIPAddresses() {
59 for(Pcap.Packet packet : listPacket) {
60 System.out.print("# " + counter++);
61 // Check the packet type
62 if (packet._root().hdr().network() == Pcap.Linktype.ETHERNET) {
63 EthernetFrame ethFrame = (EthernetFrame) packet.body();
64 if (ethFrame.etherType() == EthernetFrame.EtherTypeEnum.IPV4) {
65 Ipv4Packet ip4Packet = (Ipv4Packet) ethFrame.body();
67 System.out.print(" - Protocol: " + ip4Packet.protocol());
69 if (ip4Packet.protocol() == Ipv4Packet.ProtocolEnum.UDP) {
71 UdpDatagram udpData = (UdpDatagram) ip4Packet.body();
72 System.out.print(" - Source Port: " + udpData.srcPort());
73 System.out.print(" - Dest Port: " + udpData.dstPort());
75 // Source port 53 means this is DNS response
76 if (udpData.srcPort() == DNS_PORT) {
77 KaitaiStream dnsStream = new ByteBufferKaitaiStream(udpData.body());
78 DnsPacket dnsPacket = new DnsPacket(dnsStream);
79 ArrayList<DnsPacket.Answer> answers = dnsPacket.answers();
80 System.out.print(" - this DNS packet has " + answers.size() + " answers.");
89 /*private String cloudIPAddress(String hostName) {
90 if (hostName.equals("events.tplinkra.com"))
91 return "205.251.203.26";
96 // TODO move to separate class
97 // Add parameter that is the trace to be analyzed (most like the pcap library's representation of a flow)
98 public String findPattern(Map<String, List<Integer>> hostnameToPacketLengths, String smartPlugIp) {
100 // No difference, output "Complete match"
101 // If difference, output <Packet no, deviation from expected> for each packet
105 public static void main(String[] args) {
106 System.out.println("it works");
107 //String file = "/scratch/traffic_measurements/Switches-Feb2018/wemo/wlan1/wlan1.setup.pcap";
108 String file = "/home/rtrimana/pcap_processing/smart_home_traffic/Code/Projects/SmartPlugDetector/pcap/wlan1.local.dns.pcap";
111 Main main = new Main(file);
112 main.mapHostnamesToIPAddresses();
114 /*Pcap data = Pcap.fromFile(file);
115 List<Pcap.Packet> listPacket = data.packets();
116 System.out.println("Number of packets: " + listPacket.size());
117 System.out.println("===================");
118 for(Pcap.Packet packet : listPacket) {
119 if (packet._root().hdr().network() == Pcap.Linktype.ETHERNET) {
120 EthernetFrame eFrame = (EthernetFrame) packet.body();
121 if (eFrame.etherType() == EthernetFrame.EtherTypeEnum.IPV4) {
122 Ipv4Packet ip4Packet = (Ipv4Packet) eFrame.body();
123 byte[] srcIp = ip4Packet.srcIpAddr();
124 byte[] dstIp = ip4Packet.dstIpAddr();
125 System.out.println("Byte length source: " + srcIp.length + " Byte length dest: " + dstIp.length);
126 System.out.print("Source: ");
127 for(int i = 0; i < srcIp.length; i++) {
128 System.out.print(Byte.toUnsignedInt(srcIp[i]));
129 if(i < srcIp.length-1)
130 System.out.print(".");
132 System.out.print(" - Dest: ");
133 for(int i = 0; i < dstIp.length; i++) {
134 System.out.print(Byte.toUnsignedInt(dstIp[i]));
135 if(i < dstIp.length-1)
136 System.out.print(".");
138 System.out.println("\n");
144 } catch (Exception e) {