2019-12-09 08:12:48 +01:00
|
|
|
#!/usr/bin/env python3
|
|
|
|
|
|
|
|
import argparse
|
2019-12-14 17:27:46 +01:00
|
|
|
import database
|
2019-12-13 21:59:35 +01:00
|
|
|
import json
|
2019-12-13 00:11:21 +01:00
|
|
|
import logging
|
2019-12-14 17:27:46 +01:00
|
|
|
import sys
|
2019-12-13 12:36:11 +01:00
|
|
|
import typing
|
2019-12-14 17:27:46 +01:00
|
|
|
import multiprocessing
|
2019-12-14 23:59:50 +01:00
|
|
|
import enum
|
2019-12-14 17:27:46 +01:00
|
|
|
|
2019-12-14 23:59:50 +01:00
|
|
|
RecordType = enum.Enum('RecordType', 'A AAAA CNAME PTR')
|
|
|
|
Record = typing.Tuple[RecordType, int, str, str]
|
2019-12-14 17:27:46 +01:00
|
|
|
|
|
|
|
# select, confirm, write
|
|
|
|
FUNCTION_MAP: typing.Any = {
|
2019-12-14 23:59:50 +01:00
|
|
|
RecordType.A: (
|
2019-12-14 17:27:46 +01:00
|
|
|
database.Database.get_ip4,
|
|
|
|
database.Database.get_domain_in_zone,
|
|
|
|
database.Database.set_hostname,
|
|
|
|
),
|
2019-12-14 23:59:50 +01:00
|
|
|
RecordType.CNAME: (
|
2019-12-14 17:27:46 +01:00
|
|
|
database.Database.get_domain,
|
|
|
|
database.Database.get_domain_in_zone,
|
|
|
|
database.Database.set_hostname,
|
|
|
|
),
|
2019-12-14 23:59:50 +01:00
|
|
|
RecordType.PTR: (
|
2019-12-14 17:27:46 +01:00
|
|
|
database.Database.get_domain,
|
|
|
|
database.Database.get_ip4_in_network,
|
|
|
|
database.Database.set_ip4address,
|
|
|
|
),
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
class Reader(multiprocessing.Process):
|
2019-12-13 12:36:11 +01:00
|
|
|
def __init__(self,
|
2019-12-14 23:59:50 +01:00
|
|
|
recs_queue: multiprocessing.Queue,
|
2019-12-14 17:27:46 +01:00
|
|
|
write_queue: multiprocessing.Queue,
|
2019-12-13 12:36:11 +01:00
|
|
|
index: int = 0):
|
2019-12-14 17:27:46 +01:00
|
|
|
super(Reader, self).__init__()
|
|
|
|
self.log = logging.getLogger(f'rd{index:03d}')
|
2019-12-14 23:59:50 +01:00
|
|
|
self.recs_queue = recs_queue
|
2019-12-13 12:36:11 +01:00
|
|
|
self.write_queue = write_queue
|
|
|
|
self.index = index
|
2019-12-09 08:12:48 +01:00
|
|
|
|
2019-12-13 12:36:11 +01:00
|
|
|
def run(self) -> None:
|
|
|
|
self.db = database.Database(write=False)
|
|
|
|
self.db.log = logging.getLogger(f'db{self.index:03d}')
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('line_wait')
|
|
|
|
block: typing.List[str]
|
|
|
|
try:
|
2019-12-14 23:59:50 +01:00
|
|
|
for block in iter(self.recs_queue.get, None):
|
|
|
|
record: Record
|
|
|
|
for record in block:
|
|
|
|
# print(55, record)
|
|
|
|
dtype, updated, name, value = record
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('feed_switch')
|
|
|
|
select, confirm, write = FUNCTION_MAP[dtype]
|
|
|
|
for rule in select(self.db, value):
|
2019-12-14 23:59:50 +01:00
|
|
|
# print(60, rule, list(confirm(self.db, name)))
|
2019-12-14 17:27:46 +01:00
|
|
|
if not any(confirm(self.db, name)):
|
2019-12-14 23:59:50 +01:00
|
|
|
# print(62, write, name, updated, rule)
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('wait_put')
|
2019-12-14 23:59:50 +01:00
|
|
|
self.write_queue.put((write, name, updated, rule))
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('line_wait')
|
|
|
|
except KeyboardInterrupt:
|
|
|
|
self.log.error('Interrupted')
|
|
|
|
|
|
|
|
self.db.enter_step('end')
|
|
|
|
self.db.close()
|
|
|
|
|
|
|
|
|
|
|
|
class Writer(multiprocessing.Process):
|
|
|
|
def __init__(self,
|
|
|
|
write_queue: multiprocessing.Queue,
|
|
|
|
):
|
|
|
|
super(Writer, self).__init__()
|
|
|
|
self.log = logging.getLogger(f'wr ')
|
|
|
|
self.write_queue = write_queue
|
|
|
|
|
|
|
|
def run(self) -> None:
|
|
|
|
self.db = database.Database(write=True)
|
|
|
|
self.db.log = logging.getLogger(f'dbw ')
|
|
|
|
self.db.enter_step('line_wait')
|
|
|
|
block: typing.List[str]
|
|
|
|
try:
|
|
|
|
fun: typing.Callable
|
|
|
|
name: str
|
|
|
|
updated: int
|
2019-12-14 23:59:50 +01:00
|
|
|
source: int
|
|
|
|
for fun, name, updated, source in iter(self.write_queue.get, None):
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('exec')
|
2019-12-14 23:59:50 +01:00
|
|
|
fun(self.db, name, updated, source=source)
|
2019-12-14 17:27:46 +01:00
|
|
|
self.db.enter_step('line_wait')
|
|
|
|
except KeyboardInterrupt:
|
|
|
|
self.log.error('Interrupted')
|
2019-12-13 12:36:11 +01:00
|
|
|
|
|
|
|
self.db.enter_step('end')
|
|
|
|
self.db.close()
|
|
|
|
|
|
|
|
|
2019-12-14 23:59:50 +01:00
|
|
|
class Parser():
|
|
|
|
def __init__(self,
|
|
|
|
buf: typing.Any,
|
|
|
|
recs_queue: multiprocessing.Queue,
|
|
|
|
block_size: int,
|
|
|
|
):
|
|
|
|
super(Parser, self).__init__()
|
|
|
|
self.buf = buf
|
|
|
|
self.log = logging.getLogger('pr ')
|
|
|
|
self.recs_queue = recs_queue
|
|
|
|
self.block: typing.List[Record] = list()
|
|
|
|
self.block_size = block_size
|
|
|
|
self.db = database.Database() # Just for timing
|
|
|
|
self.db.log = logging.getLogger('pr ')
|
|
|
|
|
|
|
|
def register(self, record: Record) -> None:
|
|
|
|
self.db.enter_step('register')
|
|
|
|
self.block.append(record)
|
|
|
|
if len(self.block) >= self.block_size:
|
|
|
|
self.db.enter_step('put_block')
|
|
|
|
self.recs_queue.put(self.block)
|
|
|
|
self.block = list()
|
|
|
|
|
|
|
|
def run(self) -> None:
|
|
|
|
self.consume()
|
|
|
|
self.recs_queue.put(self.block)
|
|
|
|
self.db.close()
|
|
|
|
|
|
|
|
def consume(self) -> None:
|
|
|
|
raise NotImplementedError
|
|
|
|
|
|
|
|
|
|
|
|
class Rapid7Parser(Parser):
|
|
|
|
TYPES = {
|
|
|
|
'a': RecordType.A,
|
|
|
|
'aaaa': RecordType.AAAA,
|
|
|
|
'cname': RecordType.CNAME,
|
|
|
|
'ptr': RecordType.PTR,
|
|
|
|
}
|
|
|
|
|
|
|
|
def consume(self) -> None:
|
|
|
|
for line in self.buf:
|
|
|
|
self.db.enter_step('parse_rapid7')
|
|
|
|
try:
|
|
|
|
data = json.loads(line)
|
|
|
|
except json.decoder.JSONDecodeError:
|
|
|
|
continue
|
|
|
|
record = (
|
|
|
|
Rapid7Parser.TYPES[data['type']],
|
|
|
|
int(data['timestamp']),
|
|
|
|
data['name'],
|
|
|
|
data['value']
|
|
|
|
)
|
|
|
|
self.register(record)
|
|
|
|
|
|
|
|
|
|
|
|
class DnsMassParser(Parser):
|
|
|
|
# dnsmass --output Snrql
|
|
|
|
# --retry REFUSED,SERVFAIL --resolvers nameservers-ipv4
|
|
|
|
TYPES = {
|
|
|
|
'A': (RecordType.A, -1, None),
|
|
|
|
'AAAA': (RecordType.AAAA, -1, None),
|
|
|
|
'CNAME': (RecordType.CNAME, -1, -1),
|
|
|
|
}
|
|
|
|
|
|
|
|
def consume(self) -> None:
|
|
|
|
self.db.enter_step('parse_dnsmass')
|
|
|
|
timestamp = 0
|
|
|
|
header = True
|
|
|
|
for line in self.buf:
|
|
|
|
line = line[:-1]
|
|
|
|
if not line:
|
|
|
|
header = True
|
|
|
|
continue
|
|
|
|
|
|
|
|
split = line.split(' ')
|
|
|
|
try:
|
|
|
|
if header:
|
|
|
|
timestamp = int(split[1])
|
|
|
|
header = False
|
|
|
|
else:
|
|
|
|
dtype, name_offset, value_offset = \
|
|
|
|
DnsMassParser.TYPES[split[1]]
|
|
|
|
record = (
|
|
|
|
dtype,
|
|
|
|
timestamp,
|
|
|
|
split[0][:name_offset],
|
|
|
|
split[2][:value_offset],
|
|
|
|
)
|
|
|
|
self.register(record)
|
|
|
|
self.db.enter_step('parse_dnsmass')
|
|
|
|
except KeyError:
|
|
|
|
continue
|
|
|
|
|
|
|
|
|
|
|
|
PARSERS = {
|
|
|
|
'rapid7': Rapid7Parser,
|
|
|
|
'dnsmass': DnsMassParser,
|
|
|
|
}
|
|
|
|
|
2019-12-13 12:36:11 +01:00
|
|
|
if __name__ == '__main__':
|
|
|
|
|
|
|
|
# Parsing arguments
|
|
|
|
log = logging.getLogger('feed_dns')
|
2019-12-14 23:59:50 +01:00
|
|
|
args_parser = argparse.ArgumentParser(
|
2019-12-13 12:36:11 +01:00
|
|
|
description="TODO")
|
2019-12-14 23:59:50 +01:00
|
|
|
args_parser.add_argument(
|
|
|
|
'parser',
|
|
|
|
choices=PARSERS.keys(),
|
|
|
|
help="TODO")
|
|
|
|
args_parser.add_argument(
|
2019-12-13 12:36:11 +01:00
|
|
|
'-i', '--input', type=argparse.FileType('r'), default=sys.stdin,
|
|
|
|
help="TODO")
|
2019-12-14 23:59:50 +01:00
|
|
|
args_parser.add_argument(
|
|
|
|
'-j', '--workers', type=int, default=4,
|
|
|
|
help="TODO")
|
|
|
|
args_parser.add_argument(
|
|
|
|
'-b', '--block-size', type=int, default=100,
|
|
|
|
help="TODO")
|
|
|
|
args = args_parser.parse_args()
|
2019-12-13 12:36:11 +01:00
|
|
|
|
|
|
|
DB = database.Database(write=False) # Not needed, just for timing
|
2019-12-14 17:27:46 +01:00
|
|
|
DB.log = logging.getLogger('db ')
|
|
|
|
|
2019-12-14 23:59:50 +01:00
|
|
|
recs_queue: multiprocessing.Queue = multiprocessing.Queue(
|
|
|
|
maxsize=10*args.workers)
|
|
|
|
write_queue: multiprocessing.Queue = multiprocessing.Queue(
|
|
|
|
maxsize=10*args.workers)
|
2019-12-13 12:36:11 +01:00
|
|
|
|
2019-12-14 17:27:46 +01:00
|
|
|
DB.enter_step('proc_create')
|
|
|
|
readers: typing.List[Reader] = list()
|
2019-12-14 23:59:50 +01:00
|
|
|
for w in range(args.workers):
|
|
|
|
readers.append(Reader(recs_queue, write_queue, w))
|
2019-12-14 17:27:46 +01:00
|
|
|
writer = Writer(write_queue)
|
2019-12-14 23:59:50 +01:00
|
|
|
parser = PARSERS[args.parser](
|
|
|
|
args.input, recs_queue, args.block_size)
|
2019-12-13 12:36:11 +01:00
|
|
|
|
2019-12-14 17:27:46 +01:00
|
|
|
DB.enter_step('proc_start')
|
|
|
|
for reader in readers:
|
|
|
|
reader.start()
|
|
|
|
writer.start()
|
2019-12-09 08:12:48 +01:00
|
|
|
|
|
|
|
try:
|
2019-12-14 23:59:50 +01:00
|
|
|
DB.enter_step('parser_run')
|
|
|
|
parser.run()
|
2019-12-09 08:12:48 +01:00
|
|
|
|
2019-12-13 12:36:11 +01:00
|
|
|
DB.enter_step('end_put')
|
2019-12-14 23:59:50 +01:00
|
|
|
for _ in range(args.workers):
|
|
|
|
recs_queue.put(None)
|
2019-12-14 17:27:46 +01:00
|
|
|
write_queue.put(None)
|
2019-12-13 12:36:11 +01:00
|
|
|
|
2019-12-14 17:27:46 +01:00
|
|
|
DB.enter_step('proc_join')
|
|
|
|
for reader in readers:
|
|
|
|
reader.join()
|
|
|
|
writer.join()
|
2019-12-09 08:12:48 +01:00
|
|
|
except KeyboardInterrupt:
|
2019-12-14 17:27:46 +01:00
|
|
|
log.error('Interrupted')
|
2019-12-13 12:36:11 +01:00
|
|
|
|
2019-12-13 00:11:21 +01:00
|
|
|
DB.close()
|