- Move the FRP auth-payload scan out of the SYN-only branch. SYN packets carry
no payload, so payload-based FRP detection never fired; it now runs on every
TCP segment where the frp/auth/proxy_type bytes actually appear.
- Remove the per-packet `bytes_up += 64` approximation in on_tcp_connect, which
double-counted against real ip.len accounting and corrupted bandwidth stats.
- Correlate connections against known Flock cloud IPs (static seed list + IPs
learned from DNS answers) so cameras that reach cloud IPs without their own
DNS/SNI are classified CLOUD_CONNECTED.
- Match the Flock auth0 tenant in DNS detection, consistent with the SNI path.
- Install a SIGINT handler so the report is always produced on Ctrl+C.
- Drop unused scapy TLS imports (SNI is parsed manually).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>