Files
Deep-Package-Inspection/test/analyze_inter_agent_flows.js
T

102 lines
4.3 KiB
JavaScript

// test/analyze_inter_agent_flows.js — diagnostic script
// Checks if there are real inter-agent flows in MongoDB
const mongoose = require('../backend/node_modules/mongoose');
const path = require('path');
require('dotenv').config({ path: path.join(__dirname, '../.env.local') });
const MONGODB_URI = process.env.MONGODB_URI || 'mongodb://127.0.0.1:27017/backone_dpi';
const { DeviceStat, Flow } = require('../backend/models/Schemas');
const { CustomAgentLocation } = require('../backend/models/SchemasAux');
async function run() {
await mongoose.connect(MONGODB_URI);
console.log('\n✓ Connected to MongoDB\n');
const SIAB_SITE = '6681452d_9cae_4ff4_8ae8_0d504774265e';
// 1. List registered agent coordinates
const locations = await CustomAgentLocation.find({ site_uuid: SIAB_SITE }).lean();
const agentUuids = locations.map(l => l.agent_uuid);
console.log(`=== Agent Locations Registered (${locations.length}) ===`);
for (const loc of locations) {
console.log(` • ${loc.agent_uuid} → ${loc.label || '(no label)'} [${loc.latitude}, ${loc.longitude}]`);
}
// 2. Build IP → agent_uuid map from DeviceStat
const devices = await DeviceStat.find({ site_uuid: SIAB_SITE }).select('ip_address agent_uuid').lean();
const ipToAgent = {};
for (const d of devices) {
if (d.ip_address && d.agent_uuid) ipToAgent[d.ip_address] = d.agent_uuid;
}
console.log(`\n=== DeviceStat Records (total ${devices.length}) ===`);
const agentDeviceCount = {};
for (const [ip, agent] of Object.entries(ipToAgent)) {
agentDeviceCount[agent] = (agentDeviceCount[agent] || 0) + 1;
}
for (const [agent, count] of Object.entries(agentDeviceCount)) {
console.log(` • Agent ${agent}: ${count} unique IP(s) tracked`);
}
// 3. Sample flows to see dst_ip patterns
const since24h = new Date(Date.now() - 24 * 60 * 60 * 1000);
const flowCount = await Flow.countDocuments({ site_uuid: SIAB_SITE, timestamp: { $gte: since24h } });
const flows = await Flow.find({ site_uuid: SIAB_SITE, timestamp: { $gte: since24h } })
.select('agent_uuid src_ip dst_ip download upload app_label')
.limit(200)
.lean();
console.log(`\n=== Flows in Last 24h: ${flowCount} total (inspecting up to 200) ===`);
const interAgentFlowMap = {};
let matchCount = 0;
for (const flow of flows) {
const srcAgent = flow.agent_uuid;
const dstAgent = ipToAgent[flow.dst_ip];
if (srcAgent && dstAgent && srcAgent !== dstAgent) {
matchCount++;
const key = `${srcAgent} → ${dstAgent}`;
if (!interAgentFlowMap[key]) {
interAgentFlowMap[key] = { bytes: 0, count: 0, examples: [] };
}
interAgentFlowMap[key].bytes += (flow.download || 0) + (flow.upload || 0);
interAgentFlowMap[key].count++;
if (interAgentFlowMap[key].examples.length < 2) {
interAgentFlowMap[key].examples.push({ src: flow.src_ip, dst: flow.dst_ip, app: flow.app_label });
}
}
}
console.log(`\n=== Inter-Agent Flows Detected: ${matchCount} (from ${flows.length} sampled) ===`);
if (Object.keys(interAgentFlowMap).length > 0) {
for (const [pair, data] of Object.entries(interAgentFlowMap)) {
const mb = (data.bytes / 1024 / 1024).toFixed(2);
console.log(` ✓ ${pair} — ${data.count} flows, ${mb} MB`);
for (const ex of data.examples) {
console.log(` Example: ${ex.src} → ${ex.dst} (${ex.app || 'Unclassified'})`);
}
}
} else {
console.log(' ✗ No inter-agent flows detected in sampled data.');
console.log('\n — Checking sample of dst_ip values that appear in flows...');
const dstIps = [...new Set(flows.map(f => f.dst_ip).filter(Boolean))].slice(0, 10);
console.log(' dst_ip samples:', dstIps);
const matched = dstIps.filter(ip => ipToAgent[ip]);
console.log(' dst_ip matched to agents:', matched.map(ip => `${ip} → ${ipToAgent[ip]}`));
}
// 4. Check if any flows have dst_ip in the devicestats table at all
const allDstIps = [...new Set(flows.map(f => f.dst_ip).filter(Boolean))];
let trackedCount = 0;
for (const ip of allDstIps) {
if (ipToAgent[ip]) trackedCount++;
}
console.log(`\n=== dst_ip Resolution: ${trackedCount} / ${allDstIps.length} unique dst IPs found in DeviceStat ===`);
await mongoose.disconnect();
console.log('\n✓ Done.\n');
}
run().catch(err => { console.error(err); process.exit(1); });