First (rushed) implementation of pattern seach at the MAC layer. Not pretty, but...
[pingpong.git] / Code / Projects / SmartPlugDetector / src / main / java / edu / uci / iotproject / Main.java
index e5a685f654fab5cee1caa9ab85c04a9e68298b4f..9696bd6d56053e2d34a576e042a08b77a00fe2a6 100644 (file)
@@ -1,12 +1,10 @@
 package edu.uci.iotproject;
 
+import edu.uci.iotproject.maclayer.MacLayerFlowPattern;
+import edu.uci.iotproject.maclayer.MacLayerFlowPatternFinder;
 import org.pcap4j.core.*;
-import org.pcap4j.packet.*;
-import org.pcap4j.packet.DnsPacket;
-import org.pcap4j.packet.namednumber.DnsResourceRecordType;
 
 import java.io.EOFException;
-import java.net.Inet4Address;
 import java.net.UnknownHostException;
 import java.util.*;
 import java.util.concurrent.TimeoutException;
@@ -25,19 +23,49 @@ public class Main {
 
 
     public static void main(String[] args) throws PcapNativeException, NotOpenException, EOFException, TimeoutException, UnknownHostException {
-        //final String fileName = "/users/varmarken/Desktop/wlan1.local.dns.pcap";
-        final String fileName = "/home/rtrimana/pcap_processing/smart_home_traffic/Code/Projects/SmartPlugDetector/pcap/wlan1.local.dns.pcap";
-
-        // ====== Debug code ======
+        // -------------------------------------------------------------------------------------------------------------
+        // Example/debug code for searching for a pattern at the MAC layer.
+        String fileName = "./pcap/mac-tplink.local.pcapng";
         PcapHandle handle;
         try {
             handle = Pcaps.openOffline(fileName, PcapHandle.TimestampPrecision.NANO);
         } catch (PcapNativeException pne) {
             handle = Pcaps.openOffline(fileName);
         }
-        FlowPatternFinder fpf = new FlowPatternFinder(handle, FlowPattern.TP_LINK_LOCAL_ON);
-        fpf.start();
+//        Arrays.asList(1590, 1590, 1590, 1001, 337, 197, 636, 1311, 177) // Full pattern (all non-zero payload packets).
+        MacLayerFlowPattern pattern = new MacLayerFlowPattern("TP_LINK_LOCAL_OFF_MAC", "50:c7:bf:33:1f:09", Arrays.asList(637, 1312));
+        MacLayerFlowPatternFinder finder = new MacLayerFlowPatternFinder(handle, pattern);
+        finder.findFlowPattern();
+        // -------------------------------------------------------------------------------------------------------------
 
-        // ========================
+//        final String fileName = args.length > 0 ? args[0] : "/home/rtrimana/pcap_processing/smart_home_traffic/Code/Projects/SmartPlugDetector/pcap/wlan1.local.remote.dns.pcap";
+//        final String trainingFileName = "./pcap/TP_LINK_LOCAL_ON_SUBSET.pcap";
+//        //final String trainingFileName = "./pcap/TP_LINK_REMOTE_ON.pcap";
+//
+//        // ====== Debug code ======
+//        PcapHandle handle;
+//        PcapHandle trainingPcap;
+//        try {
+//            handle = Pcaps.openOffline(fileName, PcapHandle.TimestampPrecision.NANO);
+//            trainingPcap = Pcaps.openOffline(trainingFileName, PcapHandle.TimestampPrecision.NANO);
+//        } catch (PcapNativeException pne) {
+//            handle = Pcaps.openOffline(fileName);
+//            trainingPcap = Pcaps.openOffline(trainingFileName);
+//        }
+//
+//        // TODO: The followings are the way to extract multiple hostnames and their associated packet lengths lists
+//        //List<String> list = new ArrayList<>();
+//        //list.add("events.tplinkra.com");
+//        //FlowPattern fp = new FlowPattern("TP_LINK_LOCAL_ON", list, trainingPcap);
+//        //List<String> list2 = new ArrayList<>();
+//        //list2.add("devs.tplinkcloud.com");
+//        //list2.add("events.tplinkra.com");
+//        //FlowPattern fp3 = new FlowPattern("TP_LINK_REMOTE_ON", list2, trainingPcap);
+//
+//        FlowPattern fp = new FlowPattern("TP_LINK_LOCAL_ON", "events.tplinkra.com", trainingPcap);
+//        FlowPatternFinder fpf = new FlowPatternFinder(handle, fp);
+//        fpf.start();
+//
+//        // ========================
     }
 }