[Bro] Developing a Bro protocol analyzer as a plugin

Slagell, Adam J slagell at illinois.edu
Thu May 5 08:31:31 PDT 2016


> On May 5, 2016, at 10:16 AM, Seth Hall <seth at icir.org> wrote:
> 
>> On May 5, 2016, at 6:54 AM, Luis Martin <martin.liras at gmail.com> wrote:
>> 
>> I've written an entry in my personal blog explaining how I managed to develop an analyzer as a plugin.
> 
> Hi Luis!
> 
> Thanks for writing up your experiences.  It's difficult for us sometimes to see how some of this could be confusing because there are so many technologies and mechanisms that need to be learned in order to write analyzers and other plugins.  People writing about their experiences like you did can be massively helpful for us to make sure that we're on a path to making these things easier and more straight forward and also very helpful for other people learning how to do this.

Yes, thank you. 

I’d like to also look over your post and see if there are specific ways we can improve our manual. In which case, would you mind us incorporating some of what you’ve written into the manual if it makes sense?

:Adam



More information about the Bro mailing list