final case class TCPState(toByte: Byte) extends AnyVal with Product with Serializable
A SiLK TCP state flag vector, encoding various properties of TCP packets in a TCP flow, as encoded in a Byte value.
- toByte
The byte value representing this state vector.
- Grouped
- Alphabetic
- By Inheritance
- TCPState
- Serializable
- Product
- Equals
- AnyVal
- Any
- Hide All
- Show All
- Public
- Protected
Instance Constructors
Value Members
- final def !=(arg0: Any): Boolean
- Definition Classes
- Any
- final def ##: Int
- Definition Classes
- Any
- def &(o: TCPState): TCPState
The bitwise AND of two TCP state flag sets.
- final def ==(arg0: Any): Boolean
- Definition Classes
- Any
- def ^(o: TCPState): TCPState
The bitwise XOR of two TCP state flag sets.
- final def asInstanceOf[T0]: T0
- Definition Classes
- Any
- def continuation: Boolean
True if this flow carries on after truncation due to a timeout or other flush of the sensor's cache.
True if this flow carries on after truncation due to a timeout or other flush of the sensor's cache. There may be a matching flow record with the truncated flag set.
- def expandedFlags: Boolean
True if this record contains expanded flag information (
initFlags
andrestFlags
). - def finFollowed: Boolean
True if additional packets were seen following a packet with the FIN flag set.
- def getClass(): Class[_ <: AnyVal]
- Definition Classes
- AnyVal → Any
- def isIPv6: Boolean
True if this flow's IP addresses are IPv6 addresses.
- final def isInstanceOf[T0]: Boolean
- Definition Classes
- Any
- def productElementNames: Iterator[String]
- Definition Classes
- Product
- val toByte: Byte
- def toString(): String
Returns a string representation of this TCPState value using the following characters:
Returns a string representation of this TCPState value using the following characters:
T
truncatedC
continuationF
finFollowedS
uniformPacketSizex
expandedFlags6
isIPv6
- Definition Classes
- TCPState → Any
- def truncated: Boolean
True if this flow was truncated due to a timeout or other flush of the sensor's cache.
True if this flow was truncated due to a timeout or other flush of the sensor's cache. There may be a matching flow record with the continuation flag set.
- def unary_~: TCPState
The bitwise NOT of a set of TCP state flags.
- def uniformPacketSize: Boolean
True if all packets in the flow had the same size in bytes.
- def |(o: TCPState): TCPState
The bitwise OR of two TCP state flag sets.
This is documentation for Mothra, a collection of Scala and Spark library functions for working with Internet-related data. Some modules contain APIs of general use to Scala programmers. Some modules make those tools more useful on Spark data-processing systems.
Please see the documentation for the individual packages for more details on their use.
Scala Packages
These packages are useful in Scala code without involving Spark:
org.cert.netsa.data
This package, which is collected as the
netsa-data
library, provides types for working with various kinds of information:org.cert.netsa.data.net
- types for working with network dataorg.cert.netsa.data.time
- types for working with time dataorg.cert.netsa.data.unsigned
- types for working with unsigned integral valuesorg.cert.netsa.io.ipfix
The
netsa-io-ipfix
library provides tools for reading and writing IETF IPFIX data from various connections and files.org.cert.netsa.io.silk
To read and write CERT NetSA SiLK file formats and configuration files, use the
netsa-io-silk
library.org.cert.netsa.util
The "junk drawer" of
netsa-util
so far provides only two features: First, a method for equipping Scala scala.collection.Iterators with exception handling. And second, a way to query the versions of NetSA libraries present in a JVM at runtime.Spark Packages
These packages require the use of Apache Spark:
org.cert.netsa.mothra.datasources
Spark datasources for CERT file types. This package contains utility features which add methods to Apache Spark DataFrameReader objects, allowing IPFIX and SiLK flows to be opened using simple
spark.read...
calls.The
mothra-datasources
library contains both IPFIX and SiLK functionality, whilemothra-datasources-ipfix
andmothra-datasources-silk
contain only what's needed for the named datasource.org.cert.netsa.mothra.analysis
A grab-bag of analysis helper functions and example analyses.
org.cert.netsa.mothra.functions
This single Scala object provides Spark SQL functions for working with network data. It is the entirety of the
mothra-functions
library.