Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions common.h
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@
#include <linux/version.h>
#include <net/arp.h>
#include <net/udp.h>
#include <linux/netfilter_bridge.h>
#include <linux/if_vlan.h>
#include <linux/moduleparam.h>

#endif

5 changes: 1 addition & 4 deletions main.c
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,7 @@
#include "rate_limit.h"
#include "vlan.h"
#include "errno.h"
#include <linux/netfilter_bridge.h>
#include <linux/if_vlan.h>
#include <linux/moduleparam.h>
#include <linux/module.h>
#include "common.h"


bool globally_enabled_DAI = false; //Default is false
Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_above_rate_limit.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -64,7 +64,7 @@ echo
echo "=== Testing DAI Drops Packets When Rate Limit is Reached ==="
echo
#Send arp packets above the rate limit
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/send_ARP_Packets_Above_Limit.py
sudo ip netns exec ns1 python3 ../python_helpers/send_arp_packets_above_limit.py
sudo dmesg | grep "DROPPING"
sudo dmesg | grep "Packet hit the rate limit."

Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_arp_poisoning.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -65,7 +65,7 @@ echo
echo "=== Testing DAI Drops Spoofed Packets ==="
echo
#Update the DHCP table with 192.168.1.1 and 192.168.1.2
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/DHCP_without_VLAN.py
sudo ip netns exec ns1 python3 ../python_helpers/dhcp_without_vlan.py
#Tell 192.168.1.11 you are somebody else already on the network (Perform Arp poisoning attack)
sudo ip netns exec ns1 sudo arpspoof -i veth0 -t 192.168.1.11 192.168.1.2 &
sleep 3
Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_below_rate_limit.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -65,7 +65,7 @@ echo "=== Testing DAI Accepts Packets when Rate Limit is Not Yet Reached ==="
echo

#Send arp packets above the rate limit
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/send_ARP_Packets_Below_Limit.py
sudo ip netns exec ns1 python3 ../python_helpers/send_arp_packets_below_limit.py
if ! dmesg | grep -q "Packet hit the rate limit."; then
# Pattern not found
echo "Packet hit the rate limit.' was NOT found"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -64,9 +64,9 @@ echo
echo "=== Testing DAI Accepts Packets From DHCP Acknowledged Sources ==="
echo
# Create and send the switch a Cusotm DHCP packet ACK for both 192.168.1.1 and 192.168.1.2 with VLAN_ID 10
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/DHCP_with_VLAN_10.py
sudo ip netns exec ns1 python3 ../python_helpers/dhcp_with_vlan_10.py
#Send and ARP Request and wait for a Response
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py

sudo dmesg | grep "ACCEPTING"
sudo dmesg | grep "The DHCP Snooping table matched."
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -63,7 +63,7 @@ echo
echo "=== Testing DAI Filtering From Unacknowledged Sources ==="
echo
#Send arp request without first being added to the DHCP or Static ARP table
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py

sudo dmesg | tail -n 20 | grep "DROPPING"
sudo dmesg | tail -n 20 | grep "It is not possible to Validate Source."
Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_static_entry_in_the_arp_table.sh
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -71,7 +71,7 @@ sudo ip netns exec ns2 ip link set veth3 up
sudo arp -s 192.168.1.1 e2:c8:14:a6:4f:ed -i veth1
sudo arp -s 192.168.1.2 3a:18:70:ca:91:b2 -i veth2
#Test communicaiton after static entries were added
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py

sudo dmesg | grep "ACCEPTING"
sudo dmesg | grep "A Known Mac Adress with the same Source IP was the same as the received Mac Address"
Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_trusted_interfaces.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -66,7 +66,7 @@ echo "=== Testing DAI Accepts Packets From Trusted Interfaces ==="
echo
#Send and ARP Request and wait for a Response
#Requests will default to VLAN 1, and will match with veth0 and veth3
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py

sudo dmesg | grep "ACCEPTING"
sudo dmesg | grep "The Interface was Trusted"
Expand Down
4 changes: 2 additions & 2 deletions tests/core_dai_features/test_untrusted_interfaces.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -64,7 +64,7 @@ echo
echo "=== Testing DAI Accepts Packets From Untrusted Interfaces ==="
echo
#Send and ARP Request and wait for a Response
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg | grep "Interface is UNTRUSTED"
sudo dmesg | grep "It is not possible to Validate Source."

Expand Down
4 changes: 2 additions & 2 deletions tests/edge_cases/test_malformed_arp_request.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -63,7 +63,7 @@ echo
echo "=== Testing DAI Malformed ARP Request ==="
echo
#Send a Malformed ARP request
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/Test_Malformed_ARP_with_VLAN.py
sudo ip netns exec ns1 python3 ../python_helpers/test_malformed_arp_with_vlan.py


sudo dmesg | grep "DROPPING"
Expand Down
6 changes: 3 additions & 3 deletions tests/param_behavior/test_dai_vlan_filtering.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -64,9 +64,9 @@ echo
echo "=== Testing DAI compares VLAN_IDs to added entries ==="
echo
#Send ARP Request with a VLAN that is configured for inspection
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py
#Send ARP Request with a VLAN that is NOT configured for inspection (Default VLAN_ID)
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py

sudo dmesg | grep "vlan_id 10 WAS FOUND in the hash table. INSPECTING"
sudo dmesg | grep "vlan_id 1 was NOT in the HASH TABLE"
Expand Down
6 changes: 3 additions & 3 deletions tests/param_behavior/test_globally_enabled_dai.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -65,9 +65,9 @@ echo
echo "=== Testing DAI Inspects all packets ==="
echo
# Create and send the switch a Cusotm DHCP packet ACK for both 192.168.1.1 and 192.168.1.2 with VLAN_ID 10
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/DHCP_with_VLAN_10.py
sudo ip netns exec ns1 python3 ../python_helpers/dhcp_with_vlan_10.py
#Send and ARP Request and wait for a Response
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py

sudo dmesg | grep "globally_enabled_DAI was ENABLED"

Expand Down
6 changes: 3 additions & 3 deletions tests/param_behavior/test_static_acl_enabled.sh
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand All @@ -66,9 +66,9 @@ echo
echo "=== Testing DAI rejcets all non Static Configurations ==="
echo
# Create and send the switch a Cusotm DHCP packet ACK for both 192.168.1.1 and 192.168.1.2 with VLAN_ID 10
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/DHCP_with_VLAN_10.py
sudo ip netns exec ns1 python3 ../python_helpers/dhcp_with_vlan_10.py
#Send and ARP Request and wait for a Response
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_With_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_with_vlan_id.py

sudo dmesg | grep "DROPPING"
sudo dmesg | grep "Implicit Drop was Added since static_ACL was Enabled"
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_trusted_interface.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_trusted_interfaces.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_trusted_interfaces_malformed.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
#sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
#sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_vlan.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_vlans.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_add_vlans_malformed.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo dmesg -n 3
echo
echo "=== Ensure Working Test Environment ==="
echo
#sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
#sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_set_globally_enabled_dai.sh
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo dmesg -n 3
echo
echo "=== Ensure Working Test Environment ==="
echo
#sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
#sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_set_static_acl_enabled.sh
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ sudo ../testenv/setup_test_env.sh
echo
echo "=== Ensure Working Test Environment ==="
echo
sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down
2 changes: 1 addition & 1 deletion tests/set_params/test_set_static_acl_enabled_malformed.sh
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ sudo dmesg -n 3
echo
echo "=== Ensure Working Test Environment ==="
echo
#sudo ip netns exec ns1 python3 ../helperPythonFilesForCustomPackets/ARP_Request_And_Response_Without_VLAN_ID.py
#sudo ip netns exec ns1 python3 ../python_helpers/arp_request_and_response_without_vlan_id.py
sudo dmesg -C

echo
Expand Down