Ephemeral Images with Cloudflare Workers
Intro
Navigating the intricacies of network monitoring often calls for a blend of ingenuity and the right set of tools. In this article, we explore how we transformed Suricata logs into dynamic network diagrams, leveraged Cloudflare Workers to generate ephemeral image URLs, and employed ChatGPT to interpret and summarize our visuals. We'll explore the intersection of network security, serverless computing, and AI-driven analysis to demonstrate how they come together to streamline and enhance otherwise unimpressive feats.
The Problem: GPT-4o’s Appetite for Tokens
We use Suricata for its IDS capabilities, but it also moonlights as a topology cartographer. Using eve.json logs, a Python script programmatically generates diagrams to help visualize the network's residents and their relationships. These diagrams are uploaded to a Tines webhook and relayed to the OpenAI API for interpretation and analysis.
So far, so good—until gpt-4o's token became an unexpected challenge. Sending raw images to the API consumed a staggering 37,000 tokens per request. One option was to downgrade to GPT-4o-mini, but sacrificing analytical depth wasn't very enticing.
The original request payload looked like this, which directly passed the base64-encoded data to ChatGPT:
[
{
"role": "system",
"content": [
{
"type": "text",
"text": "You are a network analyst tasked with interpreting network topology diagrams to generate actionable insights."
}
]
},
{
"role": "user",
"content": [
{
"type": "text",
"text": "Analyze the provided network topology diagram and provide insights based on the following criteria:\n\n1. **Central Nodes or Hubs:** Identify nodes that appear central to the topology and their potential role.\n2. **Device Roles:** Categorize devices by their roles (e.g., endpoints, gateways, servers).\n3. **Communication Patterns:** Highlight any communication protocols, clustering, or patterns evident in the topology.\n4. **Notable Observations:** Point out any unusual or noteworthy behavior that may indicate performance, scalability, or security issues.\n\nDeliver your analysis in a structured format for clarity and technical accuracy."
},
{
"type": "image_url",
"image_url": {
"url": "data:image/png;base64,<<receive_net_analysis_requests.body.file.base64encodedcontents>>"
}
}
]
}
]
The Solution: Short-Lived URLs with Cloudflare Workers
To tackle the token overhead, we built a Cloudflare Worker to handle ephemeral URL generation for our diagrams. The Worker stores each uploaded diagram in a temporary KV Namespace, creating a URL that self-destructs after 60 seconds. This window is sufficient for ChatGPT to fetch and process the image, bypassing the need to embed raw data and drastically reducing token consumption in the API request.
Working with Workers
Before diving into the details of our ephemeral URL solution, let’s take a step back to understand Cloudflare Workers and why they’re a game-changer in modern serverless computing.
Cloudflare Workers are lightweight, serverless scripts that run at the edge—meaning closer to the end-user—on Cloudflare’s global network. This setup allows you to build applications that are highly performant and scalable without needing to manage traditional infrastructure. Whether you're crafting APIs, running A/B tests, or optimizing workflows (like we did here), Workers are as flexible as they are efficient.
Key Features of Cloudflare Workers:
- Serverless by Design: No need to worry about provisioning or maintaining servers.
- Edge Computing: Scripts are executed across Cloudflare’s vast global network, minimizing latency.
- Fast and Lightweight: Ideal for tasks like API routing, image processing, and custom middleware.
How to Get Started
-
Sign Up for Cloudflare: If you don’t already have an account, start here.
-
Install Wrangler: Cloudflare Workers are managed using the Wrangler CLI tool. Install it with:
bash
npm install -g wrangler
- Create a Worker: Use Wrangler to scaffold a new project:
bash
wrangler init my-worker
- Deploy Your Worker: Once your script is ready, deploy it with a single command:
bash
wrangler deploy
- Access the Worker: Your Worker will be accessible via a unique subdomain (e.g.,
https://my-worker.yourdomain.workers.dev).
Why We Chose Cloudflare Workers
For this project, Cloudflare Workers were the perfect choice for several reasons: - Low (No) Cost: The free tier allowed us to experiment and deploy our solution without incurring additional costs. - Ephemeral Data Storage: The Workers’ flexible KV Namespaces made it incredibly sipmple to store and retrieve data on the fly. - Ease of Integration: Its serverless architecture meant rapid development and deployment.
How It Works
Here’s the play-by-play: 1. Upload: The Python script sends the PNG diagram to Tines. 2. Storage Request: Tines relays the image to the Cloudflare Worker. 3. URL Generation: The Worker stores the image in a Cloudflare KV Namespace with a 60-second expiration and returns the ephemeral URL to Tines. 4. Relay: Tines passes the ephemeral URL to ChatGPT for analysis.
And here's the core of the Worker script:
export default {
async fetch(request: Request, env: Env): Promise<Response> {
const url = new URL(request.url);
if (request.method === "POST" && url.pathname === "/upload") {
return handleUpload(request, env);
}
if (request.method === "GET" && url.pathname.startsWith("/image/")) {
return handleRetrieve(url, env);
}
return new Response("Not found", { status: 404 });
},
};
/**
* Handle image uploads
*/
async function handleUpload(request: Request, env: Env): Promise<Response> {
try {
const id = crypto.randomUUID(); // Generate a unique ID for the image
const imageData = await request.arrayBuffer(); // Read binary data from the request
const expirationTime = Math.floor(Date.now() / 1000) + 60; // Expire in 1 minute
// Store the image in the KV namespace
await env.IMAGES_KV.put(id, imageData, { expiration: expirationTime });
You can find the full implementation here.
Why It Works
By swapping raw image uploads for ephemeral URLs, we slashed token utilization to 1,200 per request—just shy of a 97% reduction. On top of that, the short-lived nature of the URLs is just good OpSec in this case (I don't know about you, but I'd rather not have internal network diagrams floating around).
The Workflow: From Logs to Insights
Step 1: Suricata and the Python Script
Suricata outputs flow events into eve.json, which the Python script parses weekly. Using NetworkX and Matplotlib, it generates PNG diagrams illustrating device relationships.
Here’s the core of the script:
import networkx as nx
import matplotlib.pyplot as plt
import json
# Load eve.json
with open('eve.json', 'r') as f:
logs = [json.loads(line) for line in f if '"event_type":"flow"' in line]
# Create a directed graph
G = nx.DiGraph()
for log in logs:
src_ip, dest_ip = log['src_ip'], log['dest_ip']
G.add_edge(src_ip, dest_ip)
# Generate and save the topology diagram
plt.figure(figsize=(10, 10))
nx.draw(G, with_labels=True, node_size=500, font_size=10, node_color="skyblue")
plt.savefig("network_topology.png")
The diagram is then uploaded to a Tines webhook. The full script is available here.
(Overly) Simplified Example Diagram:
Step 2: Integration with Tines
Tines handles the orchestration, relaying the generated URL to ChatGPT along with a slightly revised prompt. This flow is part of a much larger story responsible for an array of other network monitoring duties.
Step 3: ChatGPT and the Summarization
The ChatGPT prompt (available here) guides the model to: - Identify key relationships between devices. - Highlight anomalies. - Summarize critical observations for network security.
Our revised requestto the API:
[
{
"role": "system",
"content": [
{
"type": "text",
"text": "You are a network analyst tasked with interpreting network topology diagrams to generate actionable insights."
}
]
},
{
"role": "user",
"content": [
{
"type": "text",
"text": "Analyze the provided network topology diagram and provide insights based on the following criteria:\n\n1. **Central Nodes or Hubs:** Identify nodes that appear central to the topology and their potential role.\n2. **Device Roles:** Categorize devices by their roles (e.g., endpoints, gateways, servers).\n3. **Communication Patterns:** Highlight any communication protocols, clustering, or patterns evident in the topology.\n4. **Notable Observations:** Point out any unusual or noteworthy behavior that may indicate performance, scalability, or security issues.\n\nDeliver your analysis in a structured format for clarity and technical accuracy."
},
{
"type": "image_url",
"image_url": {
"url": "<<\"https://ephemeral-storage-worker.ttalaga.workers.dev\" & upload_diagram.body.url>>" // Ephemeral URL
}
}
]
}
]
Results: Smarter Workflows, Fewer Tokens
The results speak for themselves:
- Efficiency: Dramatic decrease in token consumption.
- Functionality: Retained GPT-4o for high-quality analysis.
- Security: Ephemeral URLs ensure minimal exposure.
This setup keeps our little network smarter, leaner, and more secure without sacrificing analytical rigor.
Practical Innovation for Complex Challenges
This project demonstrates how combining the right tools—Suricata, Cloudflare Workers, Tines, and ChatGPT—can create an efficient and streamlined workflow. By leveraging each tool’s strengths, we turned a token-heavy challenge into a lightweight, automated solution.
Whether you’re looking to optimize your network monitoring, enhance your analysis capabilities, or simply explore creative integrations, this workflow offers a solid starting point. If you’re ready to dive in, explore the repositories below to get started: