Uploaded image for project: 'Spot (Retired)'
  1. Spot (Retired)
  2. SPOT-26

[ML] DNS Packets with dns.flags.rcode=1 cause ml_ops.sh to crash

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Workaround
    • None
    • None
    • RHEL7.2/CDH5.8.2

    Description

      The workaround is to exclude packets with that rcode (via appending "and dns.flags.rcode != 1" to process_opt in ingest_conf.json), but this is not desirable as it could be a threat..
      Stack trace:
      16/12/23 16:55:46 INFO SuspiciousConnectsAnalysis: Training the model
      16/12/23 16:55:46 INFO SuspiciousConnectsAnalysis: Training DNS suspicious connects model from /user/spotuser/dns/hive/y=2016/m=12/d=23/
      16/12/23 16:56:12 WARN scheduler.TaskSetManager: Lost task 0.0 in stage 31.0 (TID 24, ip-172-31-10-235.us-west-2.compute.internal): scala.MatchError: [199.74.222.42,null] (of class org.apache.spark.sql.catalyst.expressions.GenericRowWit
      hSchema)
      at org.apache.spot.dns.model.DNSSuspiciousConnectsModel$$anonfun$9.apply(DNSSuspiciousConnectsModel.scala:191)
      at org.apache.spot.dns.model.DNSSuspiciousConnectsModel$$anonfun$9.apply(DNSSuspiciousConnectsModel.scala:191)
      at scala.collection.Iterator$$anon$11.next(Iterator.scala:328)
      at org.apache.spark.util.collection.ExternalSorter.insertAll(ExternalSorter.scala:194)
      at org.apache.spark.shuffle.sort.SortShuffleWriter.write(SortShuffleWriter.scala:64)
      at org.apache.spark.scheduler.ShuffleMapTask.runTask(ShuffleMapTask.scala:73)
      at org.apache.spark.scheduler.ShuffleMapTask.runTask(ShuffleMapTask.scala:41)
      at org.apache.spark.scheduler.Task.run(Task.scala:89)
      at org.apache.spark.executor.Executor$TaskRunner.run(Executor.scala:214)
      at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
      at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
      at java.lang.Thread.run(Thread.java:745)

      16/12/23 16:56:13 ERROR scheduler.TaskSetManager: Task 0 in stage 31.0 failed 4 times; aborting job
      Exception in thread "main" org.apache.spark.SparkException: Job aborted due to stage failure: Task 0 in stage 31.0 failed 4 times, most recent failure: Lost task 0.3 in stage 31.0 (TID 27, ip-172-31-10-233.us-west-2.compute.internal): s
      cala.MatchError: [199.74.222.42,null] (of class org.apache.spark.sql.catalyst.expressions.GenericRowWithSchema)
      at org.apache.spot.dns.model.DNSSuspiciousConnectsModel$$anonfun$9.apply(DNSSuspiciousConnectsModel.scala:191)
      at org.apache.spot.dns.model.DNSSuspiciousConnectsModel$$anonfun$9.apply(DNSSuspiciousConnectsModel.scala:191)
      at scala.collection.Iterator$$anon$11.next(Iterator.scala:328)
      at org.apache.spark.util.collection.ExternalSorter.insertAll(ExternalSorter.scala:194)
      at org.apache.spark.shuffle.sort.SortShuffleWriter.write(SortShuffleWriter.scala:64)
      at org.apache.spark.scheduler.ShuffleMapTask.runTask(ShuffleMapTask.scala:73)
      at org.apache.spark.scheduler.ShuffleMapTask.runTask(ShuffleMapTask.scala:41)
      at org.apache.spark.scheduler.Task.run(Task.scala:89)
      at org.apache.spark.executor.Executor$TaskRunner.run(Executor.scala:214)
      at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
      at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
      at java.lang.Thread.run(Thread.java:745)

      Attachments

        Activity

          People

            brandonedwards Brandon Edwards
            jprosser Joseph Prosser
            Votes:
            1 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: