# Adding new signatures

**URL:** <https://community.zeek.org/t/adding-new-signatures/982>\
**Category:** Zeek\
**Created:** [June 27, 2006, 6:53pm UTC](https://community.zeek.org/t/adding-new-signatures/982 "2006-06-27T18:53:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [June 27, 2006, 6:53pm UTC](https://community.zeek.org/t/adding-new-signatures/982/1 "2006-06-27T18:53:39Z")

</div>

> Though my final intention is to make the BRO-IDS support bittorrent  
> protocol .

If that's your goal, then you should start quite differently. For Bro,  
signatures are a handy add-on, but not the heart of its analysis. Instead,  
you should develop a protocol analyzer for Bro's event engine. Often a  
good way to develop one of these is to start with an existing one for a  
similar protocol and progressively modify it.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [June 27, 2006, 7:54pm UTC](https://community.zeek.org/t/adding-new-signatures/982/2 "2006-06-27T19:54:09Z")

</div>

Though they can be used to detect the protocol in the first place,  
to then trigger further analysis via a protocol-specific analyzer.

Robin

---

<div class="post-metadata">

**Author:** ![Anandraj](https://avatars.discourse-cdn.com/v4/letter/a/6a8cbe/32.png) [@Anandraj](https://community.zeek.org/u/Anandraj)\
**Post date:** [June 28, 2006, 4:04pm UTC](https://community.zeek.org/t/adding-new-signatures/982/3 "2006-06-28T16:04:43Z")

</div>

Hi Guys,  
Thanks for your suggestions.

Kindly excuse me for this lenthy mail 😉 !

I have decided to take gnutella as my framework for bitorrent .

create bittorrent.cc with a frame like

BittorrentMsgState::BittorrentMsgState()  
{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/\*Intialize the msg fields\*/  
}

BittorrentConn::BittorrentConn(....)  
{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/\*Intialize the Origin and Responder msg states \*/  
}

BittorrentConn::BuildEndpoints()  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/\*Building the Origin and Responder Endpoints \*/  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

BittorrentConn::Done()  
{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/\*Check for the Connection Establishment \*/  
}

BittorrentConn::NextLine()  
{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/\*Traversing the Packet \*/  
}

A Few more API's to be defined based on the Bittorrent Protocol 😉

A rough frame for the bittorrent.bro file will be like

redef capture\_filters += { ["bittorrent"] = "port 6881 or port 6882" };  
event bittorrent\_text\_msg(c: connection, orig: bool, headers: string)  
event bittorrent\_establish(....)

and a few more event defintions !!

Adding a few Coustom Signatures like this

signature bittorrent\_announce {  
&nbsp;&nbsp;ip-proto == tcp  
&nbsp;&nbsp;src-port== 6881  
&nbsp;&nbsp;payload /\*announce\* /  
&nbsp;&nbsp;tcp-state established  
}

Kindly let me know if a frame work like this would work for a Bittorrent  
Support on BRO-IDS or do i need to dig more on BRO-IDS . All your  
Suggestions are welcome !!

Between, Comming back to the question which i, posted yestrday , i m  
sorry for not beign clear on my question .

For the follwing signature built-in the ../site/signatures.bro  
signature s2b-719-7-BRO { /\*a rename from s2b-719-7 to s2b-719-7-BRO \*/  
&nbsp;&nbsp;ip-proto == tcp  
&nbsp;&nbsp;src-port == 23  
&nbsp;&nbsp;event "TELNET root login"  
&nbsp;&nbsp;tcp-state established,responder  
&nbsp;&nbsp;payload /.\*login\x3A root/  
}

I could find a log in the Signatures-xxx.log

1151508123.667965:SensitiveSignature:10.50.27.117:23/tcp:10.50.25.122:2089/tcp:s2b-719-7-BRO:10.50.27.117:  
TELNET root login:t::

But when i added the following coustom signature in  
../site/signatures.bro  
i could not find a log in Signatures-xxx.log (The event occured i did a  
login as anand 😉 )

/\*Signature for the event when the user name is anand \*/  
signature telnet\_test{  
ip-proto == tcp  
src-port == 23  
event "TELNET anand login"  
tcp-state established,responder  
payload /.\*login: anand/  
}

i did try bro -s ../site/signatures.bro ! there was no response .. i had  
to do a ctrl + c !

Could someone help me on this !! 🙂

Thanks ,  
Anand

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/adding-new-signatures/982/4 "2022-05-06T15:37:53Z")

</div>


