ntop / ntopng

Web-based Traffic and Security Network Traffic Monitoring
http://www.ntop.org
GNU General Public License v3.0
6.18k stars 648 forks source link

JA3 is Obsolete #8668

Open lucaderi opened 3 weeks ago

lucaderi commented 3 weeks ago

JA3 support has been removed from ntopng but there are some leftovers that need to be fixed. For instance lists_utils.lua contains the list of JA3 signatures that can be loaded. This means that ntopng is currently broken.

Replace it with JA4 (e.g. see https://ja4db.com)

Note that flow_alert_ndpi_malicious_ja3 contained scripts/lua/modules/alert_keys/flow_alert_keys.lua needs to be updated as well locale strings

cardigliano commented 2 weeks ago

3b0b60c422dbb4071da03c7b8c4de87fc2022168 removes JA3 leftovers, updates ndpi alert keys, renames malicious JA3 to malicious fingerprint to match the new generic name in ndpi. d1ff848a8dd1daa88ab49786472ed2588af0f47d updates locale