Network Connection Information
The Network Connection Information object describes characteristics of a network connection. Defined by D3FEND d3f:NetworkSession.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Boundary | boundary |
String |
The boundary of the connection, normalized to the caption of 'boundary_id'. In the case of 'Other', it is defined by the event source. For cloud connections, this translates to the traffic-boundary(same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External. |
Boundary ID | boundary_id |
Integer |
The normalized identifier of the boundary of the connection. For cloud connections, this translates to the traffic-boundary (same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External.
|
Direction | direction |
String | The direction of the initiated connection, traffic, or email, normalized to the caption of the direction_id value. In the case of 'Other', it is defined by the event source. |
Direction ID | direction_id |
Integer |
The normalized identifier of the direction of the initiated connection, traffic, or email.
|
Protocol Name | protocol_name |
String |
The TCP/IP protocol name in lowercase, as defined by the Internet Assigned Numbers Authority (IANA). See Protocol Numbers. For example: tcp or udp .
|
Protocol Number | protocol_num |
Integer |
The TCP/IP protocol number, as defined by the Internet Assigned Numbers Authority (IANA). Use -1 if the protocol is not defined by IANA. See Protocol Numbers. For example: 6 for TCP and 17 for UDP.
|
IP Version | protocol_ver |
String | The Internet Protocol version. |
IP Version ID | protocol_ver_id |
Integer |
The Internet Protocol version identifier.
|
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Session | session |
Session[] | The authenticated user or service session. |
TCP Flags | tcp_flags |
Integer | The network connection TCP header flags (i.e., control bits). |
Connection UID | uid |
String | The unique identifier of the connection. |
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Relationships
Inbound Relationships
These objects and events reference Network Connection Information in their attributes:
- Windows Evidence Artifacts
- SSH Activity
- Network Activity
- Network File Activity
- RDP Activity
- Network
- SMB Activity
- Web Resources Activity
- Tunnel Activity
- HTTP Activity
- FTP Activity
- Network Remediation Activity
- NTP Activity
- File Hosting Activity
- DHCP Activity
- Network Connection Query
- DNS Activity
- Web Resource Access Activity
Outbound Relationships
Network Connection Information references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated 2 months ago