[Bro] invoking the "protocol_confirmation" event
earl.eiland at root9b.com
Fri Jul 10 14:08:40 PDT 2015
I'm working on cataloging service-level protocols seen on a network. event.bif.bro lists "protocol_confirmation: event(c: connection , atype: Analyzer::Tag , aid: count)", which seems to be just the ticket. However, it is not invoked by some of the protocol analyzers of interest (e.g., MODBUS/TCP). It is invoked by DNS, but I don't see it in /scripts/base/protocols/dns/main.bro<https://www.bro.org/sphinx/_downloads/main25.bro>. How do I modify the other protocol analyzer scripts to invoke protocol_confirmation?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro