Skip to content
cad_log.txt 1.27 MiB
Newer Older
INFO:__main__:Starting...
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorService:Starting Service (tentative endpoint: 0.0.0.0:10001, max_workers: 10)...
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Creating Centralized Attack Detector Service
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Cryptomining Detector Features: [3.0, 5.0, 7.0, 8.0, 9.0, 17.0, 19.0, 21.0, 22.0, 23.0]
DEBUG:monitoring.client.MonitoringClient:Creating channel to 10.152.183.5:7070...
DEBUG:monitoring.client.MonitoringClient:Channel created
DEBUG:l3_attackmitigator.client.l3_attackmitigatorClient:Creating channel to l3-attackmitigatorservice:10002...
DEBUG:l3_attackmitigator.client.l3_attackmitigatorClient:Channel created
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorService:Listening on 0.0.0.0:10001...
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorService:Service started
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:GetFeaturesIds request: {"message": ""}
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:GetFeaturesIds reply: {"auto_features": [3.0, 5.0, 7.0, 8.0, 9.0, 17.0, 19.0, 21.0, 22.0, 23.0]}
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:GetScalabilityConfig request: {"max_connection_time": 0.8, "time_to_stabilize": 1.0}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Received scalability config request
E0421 10:39:05.237784321      92 fork_posix.cc:76]           Other threads are currently calling into gRPC, skipping fork() handlers
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:GetScalabilityConfig reply: {"message": "CSV generated"}
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Starting async prediction accuracy analysis 2
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Correct csv load: True
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:AnalyzeConnectionStatistics request: {"connection_metadata": {"endpoint_id": {"device_id": {"device_uuid": {"uuid": "ed2388eb-5fb9-5888-a4f4-160267d3e19b"}}, "endpoint_uuid": {"uuid": "ff900d5d-2ac0-576c-9628-a2d016681f9d"}, "topology_id": {"context_id": {"context_uuid": {"uuid": "43813baf-195e-5da6-af20-b3d0922e71a7"}}, "topology_uuid": {"uuid": "c76135e3-24a8-5e92-9bed-c3c9139359c8"}}}, "flow_id": "10.100.200.3:13309:192.168.1.198:443", "ip_d": "192.168.1.198", "ip_o": "10.100.200.3", "port_d": "443", "port_o": "13309", "protocol": "TCP", "service_id": {"context_id": {"context_uuid": {"uuid": "43813baf-195e-5da6-af20-b3d0922e71a7"}}, "service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}, "time_end": 1682073600.0, "time_start": 1682073600.0}, "features": [{"feature": 4.0}, {"feature": 2.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 2.0}, {"feature": 2.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 0.0}]}
INFO:root:Performing inference...
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:x_data.shape: (1, 10)
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:batch_size: 1
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:x_data.shape: (1, 10)
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Inference performed in 0.05719923973083496 seconds
INFO:root:Inference performed correctly
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:inference_results length: 1
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Creating KPIs for service context_id {
  context_uuid {
    uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
  }
}
service_uuid {
  uuid: "635973d9-976c-4c6f-bb6d-cadca6dd2147"
}

DEBUG:monitoring.client.MonitoringClient:SetKpi: {"kpi_description": "L3 - Confidence of the cryptomining detector in the security status in the last time interval of the service 635973d9-976c-4c6f-bb6d-cadca6dd2147", "kpi_id_list": [], "kpi_sample_type": "KPISAMPLETYPE_L3_SECURITY_STATUS_CRYPTO", "service_id": {"service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}}
DEBUG:monitoring.client.MonitoringClient:SetKpi result: {"kpi_id": {"uuid": "13"}}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPI l3_security_status
DEBUG:monitoring.client.MonitoringClient:SetKpi: {"kpi_description": "L3 - Security status of the service in a time interval of the service 635973d9-976c-4c6f-bb6d-cadca6dd2147 (\u201c0\u201d if no attack has been detected on the service and \u201c1\u201d if a cryptomining attack has been detected)", "kpi_id_list": [], "kpi_sample_type": "KPISAMPLETYPE_ML_CONFIDENCE", "service_id": {"service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}}
DEBUG:monitoring.client.MonitoringClient:SetKpi result: {"kpi_id": {"uuid": "14"}}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPI l3_ml_model_confidence
DEBUG:monitoring.client.MonitoringClient:SetKpi: {"kpi_description": "L3 - Number of attack connections detected in a time interval of the service 635973d9-976c-4c6f-bb6d-cadca6dd2147 (attacks of the same connection [origin IP, origin port, destination IP and destination port] are only considered once)", "kpi_id_list": [], "kpi_sample_type": "KPISAMPLETYPE_L3_UNIQUE_ATTACK_CONNS", "service_id": {"service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}}
DEBUG:monitoring.client.MonitoringClient:SetKpi result: {"kpi_id": {"uuid": "15"}}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPI l3_unique_attack_conns
DEBUG:monitoring.client.MonitoringClient:SetKpi: {"kpi_description": "L3 - Number of unique compromised clients of the service in a time interval of the service 635973d9-976c-4c6f-bb6d-cadca6dd2147 (attacks from the same origin IP are only considered once)", "kpi_id_list": [], "kpi_sample_type": "KPISAMPLETYPE_L3_UNIQUE_COMPROMISED_CLIENTS", "service_id": {"service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}}
DEBUG:monitoring.client.MonitoringClient:SetKpi result: {"kpi_id": {"uuid": "16"}}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPI l3_unique_compromised_clients
DEBUG:monitoring.client.MonitoringClient:SetKpi: {"kpi_description": "L3 - number of unique attackers of the service in a time interval of the service 635973d9-976c-4c6f-bb6d-cadca6dd2147 (attacks from the same destination IP are only considered once)", "kpi_id_list": [], "kpi_sample_type": "KPISAMPLETYPE_L3_UNIQUE_ATTACKERS", "service_id": {"service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}}
DEBUG:monitoring.client.MonitoringClient:SetKpi result: {"kpi_id": {"uuid": "17"}}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPI l3_unique_attackers
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Created KPIs for service context_id {
  context_uuid {
    uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
  }
}
service_uuid {
  uuid: "635973d9-976c-4c6f-bb6d-cadca6dd2147"
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:self.time_interval_start: 2023-04-21 10:39:05.579445
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:time_interval: 60
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:0:01:00
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:current_time: 2023-04-21 10:39:05.674563
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:time_interval_start: 2023-04-21 10:39:05.579445
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:time_interval_end: 2023-04-21 10:40:05.579445
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:No KPIs sent to monitoring server
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Monitoring KPIs performed in 0.0007340908050537109 seconds
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:cryptomining_detector_output: {'confidence': 1.0, 'timestamp': '21/04/2023 10:39:05', 'ip_o': '10.100.200.3', 'ip_d': '192.168.1.198', 'tag_name': 'Normal', 'tag': 0, 'flow_id': '10.100.200.3:13309:192.168.1.198:443', 'protocol': 'TCP', 'port_o': '13309', 'port_d': '443', 'ml_id': 'crypto_5g_rf_spider_features.onnx', 'service_id': context_id {
  context_uuid {
    uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
  }
}
service_uuid {
  uuid: "635973d9-976c-4c6f-bb6d-cadca6dd2147"
}
, 'endpoint_id': topology_id {
  context_id {
    context_uuid {
      uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
    }
  }
  topology_uuid {
    uuid: "c76135e3-24a8-5e92-9bed-c3c9139359c8"
  }
}
device_id {
  device_uuid {
    uuid: "ed2388eb-5fb9-5888-a4f4-160267d3e19b"
  }
}
endpoint_uuid {
  uuid: "ff900d5d-2ac0-576c-9628-a2d016681f9d"
}
, 'time_start': 1682073600.0, 'time_end': 1682073600.0}
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Number of Attack Connections Correctly Classified: 0
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Number of Attack Connections: 0
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Overall Detection Accuracy: 0.0

INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Cryptomining Attack Detection Accuracy: 0.0
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Cryptomining Detector Confidence: 1.0
INFO:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Time elapsed: 101.0046796798706
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Exporting prediction accuracy and confidence
INFO:root:No attack detected
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:AnalyzeConnectionStatistics reply: {"message": "Ok, information received (no attack detected)"}
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:AnalyzeConnectionStatistics request: {"connection_metadata": {"endpoint_id": {"device_id": {"device_uuid": {"uuid": "ed2388eb-5fb9-5888-a4f4-160267d3e19b"}}, "endpoint_uuid": {"uuid": "ff900d5d-2ac0-576c-9628-a2d016681f9d"}, "topology_id": {"context_id": {"context_uuid": {"uuid": "43813baf-195e-5da6-af20-b3d0922e71a7"}}, "topology_uuid": {"uuid": "c76135e3-24a8-5e92-9bed-c3c9139359c8"}}}, "flow_id": "10.100.200.3:13309:192.168.1.198:443", "ip_d": "192.168.1.198", "ip_o": "10.100.200.3", "port_d": "443", "port_o": "13309", "protocol": "TCP", "service_id": {"context_id": {"context_uuid": {"uuid": "43813baf-195e-5da6-af20-b3d0922e71a7"}}, "service_uuid": {"uuid": "635973d9-976c-4c6f-bb6d-cadca6dd2147"}}, "time_end": 1682073600.0, "time_start": 1682073600.0}, "features": [{"feature": 3.0}, {"feature": 1.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 2.0}, {"feature": 2.0}, {"feature": 0.0}, {"feature": 0.0}, {"feature": 0.0}]}
INFO:root:Performing inference...
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:x_data.shape: (1, 10)
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:batch_size: 1
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:x_data.shape: (1, 10)
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Inference performed in 0.0006234645843505859 seconds
INFO:root:Inference performed correctly
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:inference_results length: 2
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:current_time: 2023-04-21 10:39:05.681895
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:time_interval_start: 2023-04-21 10:39:05.579445
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:time_interval_end: 2023-04-21 10:40:05.579445
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:service_id: context_id {
  context_uuid {
    uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
  }
}
service_uuid {
  uuid: "635973d9-976c-4c6f-bb6d-cadca6dd2147"
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Sending KPIs to monitoring server
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:kpi_security_status: kpi_id {
  kpi_id {
    uuid: "13"
  }
}
timestamp {
  timestamp: 1682073545.6827891
}
kpi_value {
  int32Val: 0
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:kpi_conf: kpi_id {
  kpi_id {
    uuid: "14"
  }
}
timestamp {
  timestamp: 1682073545.6827891
}
kpi_value {
  floatVal: 1
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:kpi_unique_attack_conns: kpi_id {
  kpi_id {
    uuid: "15"
  }
}
timestamp {
  timestamp: 1682073545.6827891
}
kpi_value {
  int32Val: 0
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:kpi_unique_compromised_clients: kpi_id {
  kpi_id {
    uuid: "16"
  }
}
timestamp {
  timestamp: 1682073545.6827891
}
kpi_value {
  int32Val: 0
}

DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:kpi_unique_attackers: kpi_id {
  kpi_id {
    uuid: "17"
  }
}
timestamp {
  timestamp: 1682073545.6827891
}
kpi_value {
  int32Val: 0
}

DEBUG:monitoring.client.MonitoringClient:IncludeKpi: {"kpi_id": {"kpi_id": {"uuid": "13"}}, "kpi_value": {"int32Val": 0}, "timestamp": {"timestamp": 1682073545.682789}}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi result: {}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi: {"kpi_id": {"kpi_id": {"uuid": "14"}}, "kpi_value": {"floatVal": 1.0}, "timestamp": {"timestamp": 1682073545.682789}}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi result: {}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi: {"kpi_id": {"kpi_id": {"uuid": "15"}}, "kpi_value": {"int32Val": 0}, "timestamp": {"timestamp": 1682073545.682789}}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi result: {}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi: {"kpi_id": {"kpi_id": {"uuid": "16"}}, "kpi_value": {"int32Val": 0}, "timestamp": {"timestamp": 1682073545.682789}}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi result: {}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi: {"kpi_id": {"kpi_id": {"uuid": "17"}}, "kpi_value": {"int32Val": 0}, "timestamp": {"timestamp": 1682073545.682789}}
DEBUG:monitoring.client.MonitoringClient:IncludeKpi result: {}
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:KPIs sent to monitoring server
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:Monitoring KPIs performed in 0.062409162521362305 seconds
DEBUG:l3_centralizedattackdetector.service.l3_centralizedattackdetectorServiceServicerImpl:cryptomining_detector_output: {'confidence': 1.0, 'timestamp': '21/04/2023 10:39:05', 'ip_o': '10.100.200.3', 'ip_d': '192.168.1.198', 'tag_name': 'Normal', 'tag': 0, 'flow_id': '10.100.200.3:13309:192.168.1.198:443', 'protocol': 'TCP', 'port_o': '13309', 'port_d': '443', 'ml_id': 'crypto_5g_rf_spider_features.onnx', 'service_id': context_id {
  context_uuid {
    uuid: "43813baf-195e-5da6-af20-b3d0922e71a7"
Loading
Loading full blame…