# Bro: a question regarding type

**URL:** <https://community.zeek.org/t/bro-a-question-regarding-type/195>\
**Category:** Zeek\
**Created:** [October 5, 2001, 6:50am UTC](https://community.zeek.org/t/bro-a-question-regarding-type/195 "2001-10-05T06:50:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [October 5, 2001, 6:50am UTC](https://community.zeek.org/t/bro-a-question-regarding-type/195/1 "2001-10-05T06:50:54Z")

</div>

> I had a general question regarding Bro.  
> Can we classify it under Rule based or Anomaly based as usually IDSs are  
> classified ?  
> I would guess it is a Rule based one. Is there any anomaly detection in  
> Bro ?

I think of Bro as somewhat different from both of these notions. The term  
I've used is "activity based", meaning that its core notion is to first  
describe network activity in generic terms (this is done by the event  
engine), and then to compare that activity against a site's local poilcy  
for policy violations (done by the script interpreter). That said, it's  
in general closer to rule-based than anomaly-based, and a number of the  
attacks detected by the default set of scripts are certainly rule-based/  
signature-based. But some of its detection, such as stepping stones and  
backdoors, is more along the lines of anomaly detection, except you need  
to define the "normal" behavior (e.g., which stepping stones and backdoors  
are benign) by hand. This isn't fundamental to Bro's design - you could  
picture extending it to learn likely normal behavior in this regard - but  
it doesn't do so presently.

> When it is stated that an IDS can withstand upto or greater than 'X'  
> Mbps,  
> do we make any assumptions regarding the number of rules in the  
> rule-based IDS ?

Well, certainly.

> I would think as the rules increases, the traffic that the IDS can  
> withstand should decrease.

In general, yes, though you look for rules that can be matched in parallel.  
For example, by using regular-expression matching, you can look for large  
numbers of text patterns in packet payloads or connection byte streams  
all at the same time, without having to back up.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/bro-a-question-regarding-type/195/2 "2022-05-06T15:36:23Z")

</div>


