microsoft / microsoft/SysmonForLinux
Network Accept tracker to handle empty address
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- C
- Star
- 2.2k
- Fork
- 220
- Merge trung bình
- 11 ngày 22 giờ
- Pull request đã merge (30 ngày)
- 2
Mô tả
If an application calls accept() with the addr argument set to NULL, then the remote IP address and port will be set to 0. The networkTracker::seenAccept() function needs to recognise this situation and look up the details in /proc using the file descriptor. If the connection isn't in /proc then it should return true with both addresses and ports set to 0, so that the received connection is still reported, even though the addresses and ports are empty.
A further enhancement would be to track calls to bind() and store the local address and port against the file descriptor, so that in the condition where addr is NULL, the local port can be used to match against the cache of connections.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu tại networkTracker::seenAccept() và theo dõi cách accept() xử lý đối số addr NULL. Kiểm tra việc tra cứu /proc bằng bộ mô tả tệp và đường dẫn báo cáo kết nối hiện có; được xem là hoàn thành khi các kết nối vẫn được báo cáo với địa chỉ và cổng được đặt về 0 khi không có mục nhập /proc. Việc theo dõi bind() tùy chọn là một cải tiến riêng biệt.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- c
- Lĩnh vực
- networking
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 38/100