76 lines
3.1 KiB
JavaScript
76 lines
3.1 KiB
JavaScript
// backend/routes/dashboard/threatsHelper.js
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// Intelligence data mapping helpers for threats routes
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
const { getTimeFilter, getBaseFilter } = require('./helpers');
|
|
const { generateMacFromIp } = require('../../deviceResolver');
|
|
|
|
async function getIntelData(Threat, req, threatTypeRegex = null, limit = 0) {
|
|
const timeFilter = getTimeFilter(req);
|
|
const query = getBaseFilter(req, timeFilter);
|
|
|
|
if (threatTypeRegex) {
|
|
query.threat_type = { $regex: threatTypeRegex, $options: 'i' };
|
|
}
|
|
|
|
let dbQuery = Threat.find(query).sort({ detected_at: -1, timestamp: -1 });
|
|
if (limit > 0) dbQuery = dbQuery.limit(limit);
|
|
|
|
const list = await dbQuery.lean();
|
|
|
|
return list.map((t) => {
|
|
const ip = t.ip_address || t.src_ip || t.dst_ip || '0.0.0.0';
|
|
const mac = t.mac_address || t.src_mac || generateMacFromIp(ip);
|
|
const eTime = t.detected_at || t.timestamp?.toISOString() || new Date().toISOString();
|
|
return {
|
|
id: t._id?.toString(),
|
|
detected_at: eTime,
|
|
ip_address: ip,
|
|
mac_address: mac,
|
|
pool_host: t.domain || null,
|
|
pool_ip: t.dst_ip || null,
|
|
protocol: t.protocol || 'TCP',
|
|
app_label: t.app_label || 'Unknown',
|
|
confidence: t.severity === 'Critical' ? 99 : (t.severity === 'High' ? 90 : 75),
|
|
download: t.download || 0,
|
|
upload: t.upload || 0,
|
|
exit_node: t.dst_ip || null,
|
|
circuit_id: t.flow_id || null,
|
|
country: 'Unknown',
|
|
vpn_type: t.app_label || 'Unknown VPN',
|
|
remote_ip: t.dst_ip || null,
|
|
device_label: ip,
|
|
device_type: 'Unknown',
|
|
os_label: 'Unknown',
|
|
manufacturer: 'Unknown',
|
|
risk_level: t.severity || 'Medium',
|
|
risk: t.severity || 'Medium',
|
|
reputation: t.threat_type || 'Malicious IP',
|
|
severity: t.severity || 'Warning'
|
|
};
|
|
});
|
|
}
|
|
|
|
function mapThreatData(threats) {
|
|
return threats.map((t) => {
|
|
return {
|
|
id: t._id?.toString(),
|
|
threat_type: t.threat_type || 'Unknown Threat',
|
|
severity: t.severity || 'Medium',
|
|
ip_address: t.src_ip || t.ip_address || null,
|
|
dst_ip: t.dst_ip || null,
|
|
mac_address: t.src_mac || t.mac_address || null,
|
|
app_label: t.app_label || t.protocol || null,
|
|
domain: t.domain || t.dst_ip || null,
|
|
detected_at: t.detected_at || t.event_at || t.timestamp?.toISOString() || new Date().toISOString(),
|
|
description: t.description || null
|
|
};
|
|
});
|
|
}
|
|
|
|
module.exports = {
|
|
getIntelData,
|
|
mapThreatData
|
|
};
|