That's right, the size in the endpoint record is cumulative and 
reflects the total size of the flow so far. 

I see two options for you:

- you could remember the flows' size with every udp_reply and then
calculate the increase when the next udp_reply comes in. 

- you could use the new_packet() event which gives you the size for
each packet.

None of the two approaches is very nice and both can also turn out to
be pretty expensive. The main problem here is that Bro isn't really
well-suited for expressing policies at the level of indivdual packets
as it tries to abstract from packets o high-level activity as much as


