Network Accept tracker to handle empty address

Open
#48 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
c
Domain
networking

Research direction

Start at networkTracker::seenAccept() and trace how accept() handles a NULL addr argument. Inspect /proc lookup by file descriptor and the existing connection-reporting path; done means connections are still reported with zeroed addresses and ports when no /proc entry exists. The optional bind() tracking is a separate enhancement.

Written by the indexing model from the issue text.

Description

enhancement

If an application calls accept() with the addr argument set to NULL, then the remote IP address and port will be set to 0. The networkTracker::seenAccept() function needs to recognise this situation and look up the details in /proc using the file descriptor. If the connection isn't in /proc then it should return true with both addresses and ports set to 0, so that the received connection is still reported, even though the addresses and ports are empty.

A further enhancement would be to track calls to bind() and store the local address and port against the file descriptor, so that in the condition where addr is NULL, the local port can be used to match against the cache of connections.

Dominant language
C
Stars
2.2k
Forks
220
Avg merge
11d 22h
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/SysmonForLinux

All issues in microsoft/SysmonForLinux

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.