Network Connection Information

network_connection_info

The Network Connection Information object describes characteristics of an OSI Transport Layer communication, including TCP and UDP.

Attributes

CaptionNameTypeDescription
BoundaryboundaryString

The boundary of the connection, normalized to the caption of 'boundary_id'. In the case of 'Other', it is defined by the event source.

For cloud connections, this translates to the traffic-boundary(same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External.

Boundary IDboundary_idInteger

The normalized identifier of the boundary of the connection.

For cloud connections, this translates to the traffic-boundary (same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External.

  • 0: Unknown (UNKNOWN)
  • 1: Localhost (LOCALHOST)
  • 10: Gateway VPC (GATEWAY_VPC)
  • 11: Internet Gateway (INTERNET_GATEWAY)
  • 2: Internal (INTERNAL)
  • 3: External (EXTERNAL)
  • 4: Same VPC (SAME_VPC)
  • 5: Internet/VPC Gateway (INTERNET/VPC_GATEWAY)
  • 6: Virtual Private Gateway (VIRTUAL_PRIVATE_GATEWAY)
  • 7: Intra-region VPC (INTRA_REGION_VPC)
  • 8: Inter-region VPC (INTER_REGION_VPC)
  • 9: Local Gateway (LOCAL_GATEWAY)
  • 99: Other (OTHER)
Community IDcommunity_uidString

The Community ID of the network connection.

DirectiondirectionString

The direction of the initiated connection, traffic, or email, normalized to the caption of the direction_id value. In the case of 'Other', it is defined by the event source.

Direction IDdirection_idInteger

The normalized identifier of the direction of the initiated connection, traffic, or email.

  • 0: Unknown (UNKNOWN)
  • 1: Inbound (INBOUND)
  • 2: Outbound (OUTBOUND)
  • 3: Lateral (LATERAL)
  • 99: Other (OTHER)
Connection Flag Historyflag_historyString

The Connection Flag History summarizes events in a network connection. For example flags ShAD representing SYN, SYN/ACK, ACK and Data exchange.

Protocol Nameprotocol_nameString

The IP protocol name in lowercase, as defined by the Internet Assigned Numbers Authority (IANA). For example: tcp or udp.

Protocol Numberprotocol_numInteger

The IP protocol number, as defined by the Internet Assigned Numbers Authority (IANA). For example: 6 for TCP and 17 for UDP.

IP Versionprotocol_verString

The Internet Protocol version.

IP Version IDprotocol_ver_idInteger

The Internet Protocol version identifier.

  • 0: Unknown (UNKNOWN)
  • 4: Internet Protocol version 4 (IPv4) (INTERNET_PROTOCOL_VERSION_4_(IPV4))
  • 6: Internet Protocol version 6 (IPv6) (INTERNET_PROTOCOL_VERSION_6_(IPV6))
  • 99: Other (OTHER)
Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

SessionsessionSession[]

The authenticated user or service session.

TCP Flagstcp_flagsInteger

The network connection TCP header flags (i.e., control bits).

Connection UIDuidString

The unique identifier of the connection.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Relationships

Network Connection Information shown in context

Inbound Relationships

These objects and events reference Network Connection Information in their attributes:

Outbound Relationships

Network Connection Information references the following objects and events in its attributes:

This page describes ocsf-1.4.0