Files
ai-security-xdr/haobang-security-dm/syslog-consumer/target/classes/com/common/util/AlgorithmResultParser.class
T

109 lines
10 KiB
Plaintext
Raw Normal View History

Êþº¾4'
µ
¬




¬  ¬ 
  !
" #$
%
&'
&(
¬)
*
+
¬,
-
./
0
12
34
¬5
67
89
:
;
<=
>?
@A
BCÈ
DE
¬F
GH
I
J
K
L
MN
OP
Q
RS
TU
VW
XY
Z
¬[\] ^_
3`
3ab
3c
d
¬e
f
3ghi
jk
lm
n
o
pqrst
uvw
3xyz{|}~ƒˆŠŒŽ˜šœžŸ ¡¢£¤¥¦§¨©ª« ¬¬
.­® ®¯
3°
3±²
¡
¡³´
¡(
.µ ·
¸¹
¸º
¸»¼
½¾¿À
®ÁÂÃÄÅÆlogLorg/slf4j/Logger;DATE_FORMATTERS%[Ljava/time/format/DateTimeFormatter;<init>()VCodeLineNumberTableLocalVariableTablethis'Lcom/common/util/AlgorithmResultParser;buildNewLogsFromExample()Ljava/util/List; exampleJsonLjava/lang/String; Signature8()Ljava/util/List<Lcom/common/entity/SyslogNormalData;>;parseJsonToLogs$(Ljava/lang/String;)Ljava/util/List;jsonObj!Lcom/alibaba/fastjson/JSONObject;logData$Lcom/common/entity/SyslogNormalData;iI jsonArray Lcom/alibaba/fastjson/JSONArray;eLjava/lang/Exception;jsonStrlogsLjava/util/List;LocalVariableTypeTable6Ljava/util/List<Lcom/common/entity/SyslogNormalData;>;
StackMapTableÇÈ¼É J(Ljava/lang/String;)Ljava/util/List<Lcom/common/entity/SyslogNormalData;>;convertJsonObjectG(Lcom/alibaba/fastjson/JSONObject;)Lcom/common/entity/SyslogNormalData;logTimeLjava/time/LocalDateTime;now
accessTime originFieldÊ$ËextractAdditionalInfo9(Lcom/common/entity/SyslogNormalData;Ljava/lang/String;)VfileInfoparts[Ljava/lang/String;maliciousRequestídetermineFileType&(Ljava/lang/String;)Ljava/lang/String;fileName
parseDateTime-(Ljava/lang/String;)Ljava/time/LocalDateTime; formatter$Ljava/time/format/DateTimeFormatter;dateParttimeStr¹¿ getStringG(Lcom/alibaba/fastjson/JSONObject;Ljava/lang/String;)Ljava/lang/String;keyY(Lcom/alibaba/fastjson/JSONObject;Ljava/lang/String;Ljava/lang/String;)Ljava/lang/String;value defaultValuegetLongU(Lcom/alibaba/fastjson/JSONObject;Ljava/lang/String;Ljava/lang/Long;)Ljava/lang/Long;Ljava/lang/Long;Ì
getInteger[(Lcom/alibaba/fastjson/JSONObject;Ljava/lang/String;Ljava/lang/Integer;)Ljava/lang/Integer;Ljava/lang/Integer;Í<clinit>
SourceFileAlgorithmResultParser.javaRuntimeVisibleAnnotations*Lorg/springframework/stereotype/Component; º» [
{
"_index": "es:skyeye-weblog-2025.09.30",
"access_time": "2025-09-30 12:05:00",
"dip": "10.20.30.51",
"dname": "网页木马æµé‡",
"dtype": "疑似木马活动",
"host": "",
"log_id": "hidden-002",
"origin_field": "匹é…到文件å: shell.php:.jpg 与 匹é…åˆ°æ¶æ„请求: exec=dir",
"reason": "æºIP 203.0.113.51 访问 目的IP 10.20.30.51 异常,入度=0, 出度=0, 独立访客=1,匹é…到文件å: shell.php:.jpg,匹é…åˆ°æ¶æ„请求: exec=dir",
"referer": "",
"sip": "203.0.113.51",
"status_code": 200,
"url": "/admin/shell.php:.jpg"
}
] ÇÈjava/util/ArrayListÎ ÏÐÈ ÑÒ ÓÔ ßàÇ ÕÖ ·æˆåŠŸè§£æž {} æ¡æ—¥å¿—æ•°æ®Í ×ØÙ ÚÛjava/lang/Exceptionè§£æžJSON失败: {} ÜÝ Þß"com/common/entity/SyslogNormalDatalog_idà áâ ãÝ ûþ äå æå ûü çåË ãè éê ëê access_timeÉ ìí óô îêsip ïådip ðå ñå òåurl óåhost ôåreferer õå status_codeÌ ×ö  ÷øGET ùå úû üû ýû þûdtype ÿådname å åreason å origin_field åhttp åalgorithm_detection å éê_index转æ¢JSON对象失败: {} ÞÛ
文件å:   与 
Ý  å ðñ  å 
Ýshellç–‘ä¼¼Webshell å 网页åŽé—¨ å
æ¶æ„请求: å å åexec=cmd=system( 命令执行 å.php .php:php.jspjsp.asp.aspxasp.jpg.jpegimage.png.gif.bmp.exe
executable.dlllibrary.bat.cmdbatch.sh.pypython.js
javascript.html.htmhtml.csscss.xmlxml.jsonjson.txttext.pdfpdf.doc.docxdocument.xls.xlsx spreadsheet.zip.rar.7z.tar.gzarchiveunknown ¸¹ T ö Ò java/lang/StringBuilder  T00:00:00 3æ— æ³•è§£æžæ—¶é—´å­—符串: {}, ä½¿ç”¨å½“å‰æ—¶é—´ ÛÊ ûñ  !%com/common/util/AlgorithmResultParser" #$"java/time/format/DateTimeFormatteryyyy-MM-dd HH:mm:ss %&yyyy/MM/dd HH:mm:ssyyyy-MM-dd HH:mm:ss.SSSyyyy-MM-dd'T'HH:mm:ssyyyy-MM-dd'T'HH:mm:ss.SSSjava/lang/Objectjava/util/Listcom/alibaba/fastjson/JSONArrayjava/lang/Stringcom/alibaba/fastjson/JSONObjectjava/time/LocalDateTimejava/lang/Longjava/lang/Integercom/alibaba/fastjson/JSON
parseArray4(Ljava/lang/String;)Lcom/alibaba/fastjson/JSONArray;size()I
getJSONObject$(I)Lcom/alibaba/fastjson/JSONObject;add(Ljava/lang/Object;)ZvalueOf(I)Ljava/lang/Integer;org/slf4j/Loggerinfo'(Ljava/lang/String;Ljava/lang/Object;)V
getMessage()Ljava/lang/String;error9(Ljava/lang/String;Ljava/lang/Object;Ljava/lang/Object;)Vjava/util/UUID
randomUUID()Ljava/util/UUID;toStringsetId(Ljava/lang/String;)V
setSyslogUuidsetLogId()Ljava/time/LocalDateTime; setCreatedAt(Ljava/time/LocalDateTime;)V setEventDateisEmpty()Z
setLogTimesetSrcIp setDestIp setSrcIpStr setDestIpStr
setHttpUrl setHttpHostsetHttpReferer(J)Ljava/lang/Long;setHttpStatusCode(Ljava/lang/Long;)V
setHttpMethodsetAttackResult(Ljava/lang/Integer;)VsetEventCategory setEventType
setEventLevel