Skip to content

Add TCP conversation completeness telemetry - #184

Merged
Adam-Ghanem merged 12 commits into
mainfrom
codex/tcp-conversation-completeness
Sep 23, 2026
Merged

Adam-Ghanem merged 12 commits into
mainfrom
codex/tcp-conversation-completeness

Conversation

@Adam-Ghanem

Copy link
Copy Markdown
Owner

Summary

  • add bounded, payload-free TCP conversation completeness telemetry over NetWatch's native direction-aware tcp_history
  • distinguish opening handshake evidence, observed data, closing evidence, complete conversations with/without data, incomplete captures, and truncated/missing history
  • expose completeness in the unified flow investigation snapshot so the metric follows the analyst's active query
  • keep incomplete conversations descriptive rather than treating partial captures as security findings

Rationale

Wireshark exposes TCP conversation completeness so analysts can quickly separate streams with observed opening/closing handshakes from partial captures. NetWatch already records bounded, direction-aware TCP history but did not turn that evidence into an investigation-level completeness view. This increment uses NetWatch's own metadata model and does not copy Wireshark code or representation.

Zeek's connection metadata similarly demonstrates the value of retaining bounded connection history for flow interpretation.

Validation

CI requested on the exact PR head. New regression coverage exercises complete-with-data, complete-without-data, incomplete/partial capture, missing/truncated history, bounds, invalid limits, and query-scoped investigation integration.

Safety

Metadata-only defensive analysis. No payload reconstruction, capture expansion, stealth, exploitation, credential testing, or active scanning behavior is added.

@Adam-Ghanem
Adam-Ghanem merged commit ead6776 into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant