Skip to content

Add TCP payload flow-volume telemetry - #186

Open
Adam-Ghanem wants to merge 2 commits into
mainfrom
codex/tcp-payload-flow-volume
Open

Adam-Ghanem wants to merge 2 commits into
mainfrom
codex/tcp-payload-flow-volume

Conversation

@Adam-Ghanem

Copy link
Copy Markdown
Owner

Summary

  • extend bounded TCP payload evidence with payload-bearing flow count
  • report the largest observed payload flow in bytes and as a share of observed TCP payload
  • keep analysis metadata-only: no packet payload content is retained
  • add regression coverage for single-flow, multi-flow, missing-metadata, and zero-payload cases

Rationale

Zeek-style connection telemetry makes per-connection byte volume a core investigation primitive, while Wireshark exposes conversation/stream-oriented analysis. NetWatch already tracks directional TCP payload bytes; this increment adds bounded flow-level volume concentration so analysts can quickly tell whether one conversation dominates a capture without storing payload content.

Safety

Offline metadata analysis only. No new active scanning, capture, replay, injection, payload retention, or credential behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant