Latest Release |
|
Supported Versions |
|
Supported Platforms |
|
Build Status |
|
Documentation Status |
|
Code Coverage |
|
Code Quality |
|
Discussions Channel |
nfstream main features
Performance: nfstream is designed to be fast (x10 faster with pypy3 support) with a small CPU and memory footprint.
Layer-7 visibility: nfstream deep packet inspection engine is based on nDPI library. It allows nfstream to perform reliable encrypted applications identification and metadata extraction (e.g. TLS, SSH, DNS, HTTP).
Flexibility: add a flow feature in 2 lines as an NFPlugin.
Machine Learning oriented: add your trained model as an NFPlugin.
How to use it?
Dealing with a big pcap file and just want to aggregate it as network flows? nfstream make this path easier in few lines:
from nfstream import NFStreamer
my_awesome_streamer = NFStreamer(source="facebook.pcap") # or capture from a network interface (source="eth0")
for flow in my_awesome_streamer:
print(flow) # print, append to pandas Dataframe or whatever you want :)!
NFEntry(
flow_id=0,
first_seen=1472393122365,
last_seen=1472393123665,
version=4,
src_port=52066,
dst_port=443,
protocol=6,
vlan_id=0,
src_ip='192.168.43.18',
dst_ip='66.220.156.68',
total_packets=19,
total_bytes=5745,
duration=1300,
src2dst_packets=9,
src2dst_bytes=1345,
dst2src_packets=10,
dst2src_bytes=4400,
expiration_id=0,
master_protocol=91,
app_protocol=119,
application_name='TLS.Facebook',
category_name='SocialNetwork',
client_info='facebook.com',
server_info='*.facebook.com',
j3a_client='bfcc1a3891601edb4f137ab7ab25b840',
j3a_server='2d1eb5817ece335c24904f516ad5da12'
)
Didn’t find a specific flow feature? add a plugin to nfstream in few lines:
from nfstream import NFPlugin
class my_awesome_plugin(NFPlugin):
def on_update(self, obs, entry):
if obs.length >= 666:
entry.my_awesome_plugin += 1
streamer_awesome = NFStreamer(source='devil.pcap', plugins=[my_awesome_plugin()])
for flow in streamer_awesome:
print(flow.my_awesome_plugin) # now you will see your dynamically created metric in generated flows
More example and details are provided on the official Documentation.
Getting Started
Prerequisites
apt-get install libpcap-dev
Installation
using pip
Binary installers for the latest released version are available:
pip3 install nfstream
from source
If you want to build nfstream on your local machine:
apt-get install autogen
git clone https://github.com/aouinizied/nfstream.git
cd nfstream
python3 setup.py install
Contributing
Please read Contributing for details on our code of conduct, and the process for submitting pull requests to us.
Ethics
nfstream is intended for network data research and forensics. Researchers and network data scientists can use these framework to build reliable datasets, train and evaluate network applied machine learning models. As with any packet monitoring tool, nfstream could potentially be misused. Do not run it on any network of which you are not the owner or the administrator.
License
This project is licensed under the GPLv3 License - see the License file for details
Metadata
Release files for nfstream 3.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| nfstream-3.0.2-pp371-pypy3_71-manylinux1_x86_64.whl | PyPy 3.71 | PyPy 3 | Linux glibc 2.5+ x86-64 | Details |
| nfstream-3.0.2-cp38-cp38-manylinux1_x86_64.whl | CPython 3.8 | CPython 3.8 | Linux glibc 2.5+ x86-64 | Details |
| nfstream-3.0.2-cp37-cp37m-manylinux1_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | Linux glibc 2.5+ x86-64 | Details |
| nfstream-3.0.2-cp37-cp37m-macosx_10_15_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | macOS 10.15+ x86-64 | Details |
| nfstream-3.0.2-cp37-cp37m-macosx_10_14_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | macOS 10.14+ x86-64 | Details |
| nfstream-3.0.2-cp37-cp37m-macosx_10_13_x86_64.whl | CPython 3.7 | CPython 3.7 pymalloc | macOS 10.13+ x86-64 | Details |
| nfstream-3.0.2-cp36-cp36m-manylinux1_x86_64.whl | CPython 3.6 | CPython 3.6 pymalloc | Linux glibc 2.5+ x86-64 | Details |
Total release size: 3.9 MB
Release files / nfstream-3.0.2-pp371-pypy3_71-manylinux1_x86_64.whl
| Download URL | nfstream-3.0.2-pp371-pypy3_71-manylinux1_x86_64.whl |
|---|---|
| Size | 783.6 kB |
| Tags | Linux glibc 2.5+ x86-64 PyPy 3 PyPy 3.71 |
|
SHA-256 checksum How to use checksums |
ca25ee07d4bab4297f0a14ec5489cc584e67657fec063a599692ee4bcde21bc4
|
|
BLAKE2b-256 checksum How to use checksums |
1af6aa41972666734170cb80735bdd5061441180dcf5350bfe57fa4d2ab19cea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.40.1 PyPy/7.1.1beta
|
Release files / nfstream-3.0.2-cp38-cp38-manylinux1_x86_64.whl
| Download URL | nfstream-3.0.2-cp38-cp38-manylinux1_x86_64.whl |
|---|---|
| Size | 783.6 kB |
| Tags | CPython 3.8 Linux glibc 2.5+ x86-64 |
|
SHA-256 checksum How to use checksums |
33f85fde9dfd947ddf9a17bbe7ecca33f4de3db3c1ac8be8ba3fd105c63bc44d
|
|
BLAKE2b-256 checksum How to use checksums |
924cbdf2137e2fa13ba5d524aa6a1c61fa37a062122a4bd66f2aa51811a93c05
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.40.1 CPython/3.8.0
|
Release files / nfstream-3.0.2-cp37-cp37m-manylinux1_x86_64.whl
| Download URL | nfstream-3.0.2-cp37-cp37m-manylinux1_x86_64.whl |
|---|---|
| Size | 783.6 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc Linux glibc 2.5+ x86-64 |
|
SHA-256 checksum How to use checksums |
72972ffb48d400a0a7c8e66a394518ceb6c88c5c55baeed1505b4d9e5af8bec4
|
|
BLAKE2b-256 checksum How to use checksums |
2d1675e3972527b2862d10337e83148f7e5980a2928d03e97d82a868f67620aa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.40.1 CPython/3.7.1
|
Release files / nfstream-3.0.2-cp37-cp37m-macosx_10_15_x86_64.whl
| Download URL | nfstream-3.0.2-cp37-cp37m-macosx_10_15_x86_64.whl |
|---|---|
| Size | 250.3 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc macOS 10.15+ x86-64 |
|
SHA-256 checksum How to use checksums |
0e2cb3e1d6281690187b59320dcd437183f076557806f2ba12951818d1738563
|
|
BLAKE2b-256 checksum How to use checksums |
c53264ca6bee621781f320c97a3e72ebf4364bba520573dc592a7a56e668dd52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/41.6.0 requests-toolbelt/0.9.1 tqdm/4.40.2 CPython/3.7.5
|
Release files / nfstream-3.0.2-cp37-cp37m-macosx_10_14_x86_64.whl
| Download URL | nfstream-3.0.2-cp37-cp37m-macosx_10_14_x86_64.whl |
|---|---|
| Size | 249.4 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc macOS 10.14+ x86-64 |
|
SHA-256 checksum How to use checksums |
f2781bbed26b3728b0670781e3bce24ad207abb34ee9bac3abe33e15c6fcfa47
|
|
BLAKE2b-256 checksum How to use checksums |
36aa9db4132c599172cc3266bf4c0258658fef2a3a3bf1036beaa28799899f1d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/41.0.1 requests-toolbelt/0.9.1 tqdm/4.40.1 CPython/3.7.4
|
Release files / nfstream-3.0.2-cp37-cp37m-macosx_10_13_x86_64.whl
| Download URL | nfstream-3.0.2-cp37-cp37m-macosx_10_13_x86_64.whl |
|---|---|
| Size | 251.6 kB |
| Tags | CPython 3.7 CPython 3.7 pymalloc macOS 10.13+ x86-64 |
|
SHA-256 checksum How to use checksums |
8a93b832161ab1aa506ac4f204e5254e7cb0065a8f88805c2abefca2df253cb4
|
|
BLAKE2b-256 checksum How to use checksums |
d8e3aa8e3e92f07f47af8c376092503f0c44807d72d2fb8d90470abcb30f69bd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/41.6.0 requests-toolbelt/0.9.1 tqdm/4.40.1 CPython/3.7.5
|
Release files / nfstream-3.0.2-cp36-cp36m-manylinux1_x86_64.whl
| Download URL | nfstream-3.0.2-cp36-cp36m-manylinux1_x86_64.whl |
|---|---|
| Size | 783.6 kB |
| Tags | CPython 3.6 CPython 3.6 pymalloc Linux glibc 2.5+ x86-64 |
|
SHA-256 checksum How to use checksums |
3952726010159c4abeda3f422225cf3909b97d583d9090dc678574be1fbec496
|
|
BLAKE2b-256 checksum How to use checksums |
a4f2fea2b1202744db7e102a801ce3157f48568bf01a1a1e3ebac7a981ab47c2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/42.0.2 requests-toolbelt/0.9.1 tqdm/4.40.1 CPython/3.6.7
|