1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 // Client side phishing and malware detection request and response
6 // protocol buffers. Those protocol messages should be kept in sync
7 // with the server implementation.
9 // If you want to change this protocol definition or you have questions
10 // regarding its format please contact chrome-anti-phishing@googlegroups.com.
14 option optimize_for = LITE_RUNTIME;
16 package safe_browsing;
18 message ClientPhishingRequest {
19 // URL that the client visited. The CGI parameters are stripped by the
21 optional string url = 1;
23 // A 5-byte SHA-256 hash prefix of the URL. Before hashing the URL is
24 // canonicalized, converted to a suffix-prefix expression and broadened
25 // (www prefix is removed and everything past the last '/' is stripped).
27 // Marked OBSOLETE because the URL is sent for all users, making the hash
28 // prefix unnecessary.
29 optional bytes OBSOLETE_hash_prefix = 10;
31 // Score that was computed on the client. Value is between 0.0 and 1.0.
32 // The larger the value the more likely the url is phishing.
33 required float client_score = 2;
35 // Note: we're skipping tag 3 because it was previously used.
37 // Is true if the features for this URL were classified as phishing.
38 // Currently, this will always be true for all client-phishing requests
39 // that are sent to the server.
40 optional bool is_phishing = 4;
43 // Feature name. E.g., 'PageHasForms'.
44 required string name = 1;
46 // Feature value is always in the range [0.0, 1.0]. Boolean features
48 required double value = 2;
51 // List of features that were extracted. Those are the features that were
52 // sent to the scorer and which resulted in client_score being computed.
53 repeated Feature feature_map = 5;
55 // The version number of the model that was used to compute the client-score.
56 // Copied from ClientSideModel.version().
57 optional int32 model_version = 6;
59 // Field 7 is only used on the server.
61 // List of features that are extracted in the client but are not used in the
62 // machine learning model.
63 repeated Feature non_model_feature_map = 8;
65 // The referrer URL. This field might not be set, for example, in the case
66 // where the referrer uses HTTPs.
67 // OBSOLETE: Use feature 'Referrer=<referrer>' instead.
68 optional string OBSOLETE_referrer_url = 9;
70 // Field 11 is only used on the server.
72 // List of shingle hashes we extracted.
73 repeated uint32 shingle_hashes = 12 [packed = true];
76 message ClientPhishingResponse {
77 required bool phishy = 1;
79 // A list of SafeBrowsing host-suffix / path-prefix expressions that
80 // are whitelisted. The client must match the current top-level URL
81 // against these whitelisted expressions and only apply a positive
82 // phishing verdict above if the URL does not match any expression
83 // on this whitelist. The client must not cache these whitelisted
84 // expressions. This whitelist will be empty for the vast majority
85 // of the responses but might contain up to 100 entries in emergency
88 // Marked OBSOLETE because the URL is sent for all users, so the server
89 // can do whitelist matching.
90 repeated string OBSOLETE_whitelist_expression = 2;
93 message ClientMalwareRequest {
94 // URL that the client visited. The CGI parameters are stripped by the
96 required string url = 1;
98 // Field 2 is deleted and no longer in use.
100 // Field 3 is only used on the server.
102 // The referrer URL. This field might not be set, for example, in the case
103 // where the referrer uses HTTPS.
104 optional string referrer_url = 4;
106 // Field 5 and 6 are only used on the server.
109 required string ip = 1;
110 required string url = 2;
111 optional string method = 3;
112 optional string referrer = 4;
113 // Resource type, the int value is a direct cast from the Type enum
114 // of ResourceType class defined in //src/webkit/commom/resource_type.h
115 optional int32 resource_type = 5;
118 // List of resource urls that match the malware IP list.
119 repeated UrlInfo bad_ip_url_info = 7;
122 message ClientMalwareResponse {
123 required bool blacklist = 1;
124 // The confirmed blacklisted bad IP and its url, which will be shown in
125 // malware warning, if the blacklist verdict is true.
126 // This IP string could be either in IPv4 or IPv6 format, which is the same
127 // as the ones client sent to server.
128 optional string bad_ip = 2;
129 optional string bad_url = 3;
132 message ClientDownloadRequest {
133 // The final URL of the download (after all redirects).
134 required string url = 1;
136 // This message contains various binary digests of the download payload.
138 optional bytes sha256 = 1;
139 optional bytes sha1 = 2;
140 optional bytes md5 = 3;
142 required Digests digests = 2;
144 // This is the length in bytes of the download payload.
145 required int64 length = 3;
147 // Type of the resources stored below.
149 // The final URL of the download payload. The resource URL should
150 // correspond to the URL field above.
152 // A redirect URL that was fetched before hitting the final DOWNLOAD_URL.
153 DOWNLOAD_REDIRECT = 1;
154 // The final top-level URL of the tab that triggered the download.
156 // A redirect URL thas was fetched before hitting the final TAB_URL.
161 required string url = 1;
162 required ResourceType type = 2;
163 optional bytes remote_ip = 3;
164 // This will only be set if the referrer is available and if the
165 // resource type is either TAB_URL or DOWNLOAD_URL.
166 optional string referrer = 4;
168 // TODO(noelutz): add the transition type?
171 // This repeated field will store all the redirects as well as the
172 // final URLs for the top-level tab URL (i.e., the URL that
173 // triggered the download) as well as for the download URL itself.
174 repeated Resource resources = 4;
176 // A trust chain of certificates. Each chain begins with the signing
177 // certificate of the binary, and ends with a self-signed certificate,
178 // typically from a trusted root CA. This structure is analogous to
179 // CERT_CHAIN_CONTEXT on Windows.
180 message CertificateChain {
181 // A single link in the chain.
183 // DER-encoded X.509 representation of the certificate.
184 optional bytes certificate = 1;
185 // Fields 2 - 7 are only used on the server.
187 repeated Element element = 1;
190 message SignatureInfo {
191 // All of the certificate chains for the binary's signing certificate.
192 // If no chains are present, the binary is not signed. Multiple chains
193 // may be present if any certificate has multiple signers.
194 repeated CertificateChain certificate_chain = 1;
196 // True if the signature was trusted on the client.
197 optional bool trusted = 2;
200 // This field will only be set if the binary is signed.
201 optional SignatureInfo signature = 5;
203 // True if the download was user initiated.
204 optional bool user_initiated = 6;
206 // Fields 7 and 8 are only used on the server.
208 // Name of the file where the download would be stored if the
209 // download completes. E.g., "bla.exe".
210 optional string file_basename = 9;
212 // Starting with Chrome M19 we're also sending back pings for Chrome
213 // extensions that get downloaded by users.
215 WIN_EXECUTABLE = 0; // Currently all .exe, .cab and .msi files.
216 CHROME_EXTENSION = 1; // .crx files.
217 ANDROID_APK = 2; // .apk files.
218 // .zip files containing one of the other executable types.
219 ZIPPED_EXECUTABLE = 3;
220 MAC_EXECUTABLE = 4; // .dmg, .pkg, etc.
222 optional DownloadType download_type = 10 [default = WIN_EXECUTABLE];
224 // Locale of the device, eg en, en_US.
225 optional string locale = 11;
227 message PEImageHeaders {
229 optional bytes dos_header = 1;
230 // IMAGE_FILE_HEADER.
231 optional bytes file_header = 2;
232 // IMAGE_OPTIONAL_HEADER32. Present only for 32-bit PE images.
233 optional bytes optional_headers32 = 3;
234 // IMAGE_OPTIONAL_HEADER64. Present only for 64-bit PE images.
235 optional bytes optional_headers64 = 4;
236 // IMAGE_SECTION_HEADER.
237 repeated bytes section_header = 5;
238 // Contents of the .edata section.
239 optional bytes export_section_data = 6;
242 // IMAGE_DEBUG_DIRECTORY.
243 optional bytes directory_entry = 1;
244 optional bytes raw_data = 2;
247 repeated DebugData debug_data = 7;
250 message ImageHeaders {
251 // Windows Portable Executable image headers.
252 optional PEImageHeaders pe_headers = 1;
255 // Fields 12-17 are reserved for server-side use and are never sent by the
258 optional ImageHeaders image_headers = 18;
260 // Fields 19-21 are reserved for server-side use and are never sent by the
263 // A binary contained in an archive (e.g., a .zip archive).
264 message ArchivedBinary {
265 optional string file_basename = 1;
266 optional DownloadType download_type = 2;
267 optional Digests digests = 3;
268 optional int64 length = 4;
269 optional SignatureInfo signature = 5;
270 optional ImageHeaders image_headers = 6;
273 repeated ArchivedBinary archived_binary = 22;
276 message ClientDownloadResponse {
278 // Download is considered safe.
280 // Download is considered dangerous. Chrome should show a warning to the
283 // Download is unknown. Chrome should display a less severe warning.
285 // The download is potentially unwanted.
286 POTENTIALLY_UNWANTED = 3;
287 // The download is from a dangerous host.
290 required Verdict verdict = 1;
293 // A human-readable string describing the nature of the warning.
294 // Only if verdict != SAFE. Localized based on request.locale.
295 optional string description = 1;
297 // A URL to get more information about this warning, if available.
298 optional string url = 2;
300 optional MoreInfo more_info = 2;
302 // An arbitrary token that should be sent along for further server requests.
303 optional bytes token = 3;
306 // The following protocol buffer holds the feedback report gathered
307 // from the user regarding the download.
308 message ClientDownloadReport {
309 // The information of user who provided the feedback.
310 // This is going to be useful for handling appeals.
311 message UserInformation {
312 optional string email = 1;
321 // The type of feedback for this report.
322 optional Reason reason = 1;
324 // The original download ping
325 optional ClientDownloadRequest download_request = 2;
327 // Stores the information of the user who provided the feedback.
328 optional UserInformation user_information = 3;
330 // Unstructed comments provided by the user.
331 optional bytes comment = 4;
333 // The original download response sent from the verdict server.
334 optional ClientDownloadResponse download_response = 5;
337 // This is used to send back upload status to the client after upload completion
338 message ClientUploadResponse {
340 // The upload was successful and a complete response can be expected
343 // The upload was unsuccessful and the response is incomplete.
347 // Holds the upload status
348 optional UploadStatus status = 1;
350 // Holds the permalink where the results of scanning the binary are available
351 optional string permalink = 2;
354 message ClientIncidentReport {
355 message IncidentData {
356 message TrackedPreferenceIncident {
360 WEAK_LEGACY_OBSOLETE = 2;
362 UNTRUSTED_UNKNOWN_VALUE = 4;
365 optional string path = 1;
366 optional string atomic_value = 2;
367 repeated string split_key = 3;
368 optional ValueState value_state = 4;
370 message BinaryIntegrityIncident {
371 optional string file_basename = 1;
372 optional ClientDownloadRequest.SignatureInfo signature = 2;
374 message BlacklistLoadIncident {
375 optional string path = 1;
376 optional ClientDownloadRequest.Digests digest = 2;
377 optional string version = 3;
378 optional bool blacklist_initialized = 4;
379 optional ClientDownloadRequest.SignatureInfo signature = 5;
380 optional ClientDownloadRequest.ImageHeaders image_headers = 6;
382 message VariationsSeedSignatureIncident {
383 optional string variations_seed_signature = 1;
385 message ScriptRequestIncident {
386 optional bytes script_digest = 1;
387 optional string inclusion_origin = 2;
389 optional int64 incident_time_msec = 1;
390 optional TrackedPreferenceIncident tracked_preference = 2;
391 optional BinaryIntegrityIncident binary_integrity = 3;
392 optional BlacklistLoadIncident blacklist_load = 4;
393 // Note: skip tag 5 because it was previously used.
394 optional VariationsSeedSignatureIncident variations_seed_signature = 6;
395 optional ScriptRequestIncident script_request = 7;
398 repeated IncidentData incident = 1;
400 message DownloadDetails {
401 optional bytes token = 1;
402 optional ClientDownloadRequest download = 2;
403 optional int64 download_time_msec = 3;
404 optional int64 open_time_msec = 4;
407 optional DownloadDetails download = 2;
409 message EnvironmentData {
411 optional string os_name = 1;
412 optional string os_version = 2;
416 optional string cpu_architecture = 1;
417 optional string cpu_vendor = 2;
418 optional uint32 cpuid = 3;
420 optional Machine machine = 2;
422 optional string version = 1;
423 repeated string OBSOLETE_dlls = 2;
425 optional string function = 1;
426 optional string target_dll = 2;
428 repeated Patch patches = 3;
429 message NetworkProvider {}
430 repeated NetworkProvider network_providers = 4;
438 optional Channel chrome_update_channel = 5;
439 optional int64 uptime_msec = 6;
440 optional bool metrics_consent = 7;
441 optional bool extended_consent = 8;
447 optional string path = 1;
448 optional uint64 base_address = 2;
449 optional uint32 length = 3;
450 repeated Feature feature = 4;
451 optional ClientDownloadRequest.ImageHeaders image_headers = 5;
453 repeated Dll dll = 9;
454 repeated string blacklisted_dll = 10;
455 message ModuleState {
458 MODULE_STATE_UNKNOWN = 1;
459 MODULE_STATE_UNMODIFIED = 2;
460 MODULE_STATE_MODIFIED = 3;
462 optional string name = 1;
463 optional ModifiedState modified_state = 2;
464 repeated string modified_export = 3;
466 message Modification {
467 optional uint32 file_offset = 1;
468 optional int32 byte_count = 2;
469 optional bytes modified_bytes = 3;
470 optional string export_name = 4;
472 repeated Modification modification = 4;
474 repeated ModuleState module_state = 11;
476 optional Process process = 3;
479 optional EnvironmentData environment = 3;
482 message ClientIncidentResponse {
483 optional bytes token = 1;
484 optional bool download_requested = 2;
486 message EnvironmentRequest { optional int32 dll_index = 1; }
488 repeated EnvironmentRequest environment_requests = 3;
491 message DownloadMetadata {
492 optional uint32 download_id = 1;
494 optional ClientIncidentReport.DownloadDetails download = 2;