Protocol Detection Capabilities in Bro - The Practical Approach

Roger Larsen · 2012

Network Intrusion Detection Systems (NIDS) capability in protocol analyses is crucial. The TCP/IP suite have a standard scheme which predefines port numbers for each protocol by IANA 1 [4]. However, both benign and evil software are continuously getting more and more sophisticated and do not follow these predefined schemes. In this article we test Bro’s protocol detection capability with a honeypot server as the target and NMAP as network scanner. Will Bro manage to detect the protocols generated against our honeypot?

Read the paper · More papers on PaperTik