# Adding new signatures

**URL:** <https://community.zeek.org/t/adding-new-signatures/981>\
**Category:** Zeek\
**Created:** [June 27, 2006, 3:01pm UTC](https://community.zeek.org/t/adding-new-signatures/981 "2006-06-27T15:01:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anandraj](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@Anandraj](https://community.zeek.org/u/Anandraj)\
**Post date:** [June 27, 2006, 3:01pm UTC](https://community.zeek.org/t/adding-new-signatures/981/1 "2006-06-27T15:01:40Z")

</div>

Hi all,  
I am trying to define and add new signatures to the BRO-IDS ( bro-1.1 ).

I tried adding a simple signature like the following in  
site/signatures.bro

/\*Signature for the event when the user name is anand \*/  
signature telnet\_test{  
ip-proto == tcp  
src-port == 23  
event "TELNET anand login"  
tcp-state established,responder  
payload /.\*login: anand/  
}

/\*Signature for the event when the user name is root \*/

signature ssh\_test{  
ip-proto == tcp  
src-port == 22  
event "SSH root login"  
tcp-state established,responder  
payload /.\*login: root/  
}

following was the additional change made to policy/backdoor.bro  
from

const ssh\_sig\_disabled = F &redef;

to

const ssh\_sig\_disabled = T &redef;

Following change was also made to policy/sig-action.bro

["telnet\_test"] = SIG\_FILE,  
["ssh\_test"] = SIG\_FILE,

find that these signature begin detected .. as i added some print  
statements in policy/backdoor.bro for the following functions

function signature\_found(c: connection, sig\_disabled: bool, sig\_name:  
string)

event ssh\_signature\_found(c: connection, is\_orig: bool)

event telnet\_signature\_found(c: connection, is\_orig: bool, len: count)

I did a rename of the existing signatures in site/signatures.bro

signature s2b-719-7-BRO { /\*a rename from s2b-719-7 to s2b-719-7-BRO \*/  
&nbsp;&nbsp;ip-proto == tcp  
&nbsp;&nbsp;src-port == 23  
&nbsp;&nbsp;event "TELNET root login"  
&nbsp;&nbsp;tcp-state established,responder  
&nbsp;&nbsp;payload /.\*login\x3A root/  
}

It did work for root ..telnet login .. and it was logged to the  
signature-0.... log file.

Could somebody shed some light on this , please correct me if i m wrong  
in the process of adding the signatures or, my understanding since ,i m  
a newbie.

Though my final intention is to make the BRO-IDS support bittorrent  
protocol . Any suggestion is welcomed.

TIA ,  
Anand

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [June 27, 2006, 6:50pm UTC](https://community.zeek.org/t/adding-new-signatures/981/2 "2006-06-27T18:50:11Z")

</div>

> Could somebody shed some light on this , please correct me if i m wrong  
> in the process of adding the signatures or, my understanding since ,i m  
> a newbie.

Not sure if I understand the problem. Are you asking whether you  
added your own signatures in the correct way? In general, you can  
put custom signatures into any file and then give that to Bro via  
either the -s command line option or by redefining the script  
variable "signature\_files". Ideally, you shouldn't change the  
shipped signature files to avoid problems when updating to newer  
versions of Bro.

> Though my final intention is to make the BRO-IDS support bittorrent  
> protocol.

Sounds great!

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/adding-new-signatures/981/3 "2022-05-06T15:37:53Z")

</div>


