[Bro] Detecting OpenVPN

Mike Eriksson mike at swedishmike.org
Fri Jun 15 00:47:53 PDT 2018


All,

Before I set out to re-invent the wheel, yet again, I thought I'd post the
question to this list first. Is anyone aware of any work that's been done
to get OpenVPN detection in Bro?

Just getting detection on the handshake/initial connection should be a good
enough start in my book. Wireshark have OpenVPN protocol support so it
seems to be doable.

Any feedback/ideas out there?

Thanks in advance, Mike
-- 

website: http://swedishmike.org
twitter: https://twitter.com/swedishmike
github: http://github.com/swedishmike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20180615/98a80284/attachment.html 


More information about the Bro mailing list