# About signatures

**URL:** <https://community.zeek.org/t/about-signatures/3858>\
**Category:** Zeek\
**Created:** [October 5, 2015, 4:34pm UTC](https://community.zeek.org/t/about-signatures/3858 "2015-10-05T16:34:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vito\_Logrillo](https://avatars.discourse-cdn.com/v4/letter/v/e9bcb4/32.png) [@Vito\_Logrillo](https://community.zeek.org/u/Vito_Logrillo)\
**Post date:** [October 5, 2015, 4:34pm UTC](https://community.zeek.org/t/about-signatures/3858/1 "2015-10-05T16:34:21Z")

</div>

Hi All,  
i'm studying your signature framework  
[https://www.bro.org/sphinx/frameworks/signatures.html](https://www.bro.org/sphinx/frameworks/signatures.html)  
and i've found this explanation

" However, in our experience this didn’t turn out to be a very useful  
thing to do because by simply using Snort signatures, one can’t  
benefit from the additional capabilities that Bro provides; the  
approaches of the two systems are just too different"

I understand that Bro and Snort have different approaches, but if i  
need a detailed research on a specific string (for example) should i  
write a script?And for several strings?  
Which is the best approach to avoid signatures?  
Thanks

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [October 5, 2015, 4:54pm UTC](https://community.zeek.org/t/about-signatures/3858/2 "2015-10-05T16:54:34Z")

</div>

You might want to read this paper for more context about Bro's  
signature framework: [http://www.icir.org/robin/papers/ccs03.ps](http://www.icir.org/robin/papers/ccs03.ps).

The comment you cite below is not saying signatures that aren't useful  
at all in Bro; it's just saying that blindly converting Snort  
signatures to Bro signatures hasn't proven to be a very useful thing  
to do in practice.

Robin

---

<div class="post-metadata">

**Author:** ![Vito\_Logrillo](https://avatars.discourse-cdn.com/v4/letter/v/e9bcb4/32.png) [@Vito\_Logrillo](https://community.zeek.org/u/Vito_Logrillo)\
**Post date:** [October 5, 2015, 7:11pm UTC](https://community.zeek.org/t/about-signatures/3858/3 "2015-10-05T19:11:40Z")

</div>

Thanks Robin for your reply.  
I've read your paper and i think i've understood why a blindy  
convertion is not so useful: one reason is the possible generation of  
many false positives(correct me if i'm wrong).  
Can you suggest me a repository or a link where i can find signatures  
specifically written for Bro?  
Thanks  
Vito

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [October 5, 2015, 7:38pm UTC](https://community.zeek.org/t/about-signatures/3858/4 "2015-10-05T19:38:21Z")

</div>

Bro’s use of signatures is focussed more on protocol identification than on alerting an operator to malicious/benign packets.

-AK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/about-signatures/3858/5 "2022-05-06T15:43:08Z")

</div>


