Protocol Detection Capabilities in Bro
Roger Larsen · 2012
Network Intrusion Detection Systems (NIDS) focus generally on 3 main detection methods; (i) signature, (ii) anomaly network traffic behaviour, and (iii) protocol analyses. The challenge in protocol analyses is to detect the correct protocol used and initiate the proper analyzing method(s). The TCP/IP suite have a standard scheme which predefines port numbers for each protocol by IANA. However, both benign and evil software are continuously getting more and more sophisticated and do not follow these predefined rules. Bro is a open source framework for network traffic analyses 1 [33]. We will in this paper focus mainly on protocol analyzing mechanisms in Bro. With Bro we can analyze network traffic and detect odd protocol/port pairs usage. We will also look at what Bro can contribute regarding digital forensics. Does the present version of Bro 2 hold any machine learning functionality?