# Bro Anomaly Detection

**URL:** <https://community.zeek.org/t/bro-anomaly-detection/3006>\
**Category:** Zeek\
**Created:** [February 18, 2014, 1:10pm UTC](https://community.zeek.org/t/bro-anomaly-detection/3006 "2014-02-18T13:10:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr\_Smith](https://avatars.discourse-cdn.com/v4/letter/m/d26b3c/32.png) [@Mr\_Smith](https://community.zeek.org/u/Mr_Smith)\
**Post date:** [February 18, 2014, 1:10pm UTC](https://community.zeek.org/t/bro-anomaly-detection/3006/1 "2014-02-18T13:10:20Z")

</div>

Hi, I have two questions regarding the Bro anomaly detection capability.  
1.How does the Bro detect anomalies? Using writing rules(anomaly rules) or using a separate module ?  
2.Is it possible to run the signature-based and anomaly-based parts of Bro separately?  
I mean, can the Bro be used only for the detection of anomalies.If it is possible, how?

Thanks

---

<div class="post-metadata">

**Author:** ![Slagell\_Adam\_J](https://avatars.discourse-cdn.com/v4/letter/s/e9c0ed/32.png) [@Slagell\_Adam\_J](https://community.zeek.org/u/Slagell_Adam_J)\
**Post date:** [February 18, 2014, 3:49pm UTC](https://community.zeek.org/t/bro-anomaly-detection/3006/2 "2014-02-18T15:49:03Z")

</div>

Bro doesn’t fit well into either the anomaly-based or signature based paradigm and is often referred to as a specification-based IDS. However, it is probably best understood as more than an IDS, as a network analysis framework that combines a powerful state engine with a full computer language aimed at network analysis.

So to answer your question, there are not separate “modules”. There are a set of scripts [1] that come with Bro, and the ability to customize and add to these. If you are interested in doing signature-based detection, look at [2].

I hope this helps to get you started.

:Adam Slagell

[1] [http://www.bro.org/sphinx/scripts/index.html](http://www.bro.org/sphinx/scripts/index.html)  
[2] [http://www.bro.org/sphinx/frameworks/signatures.html](http://www.bro.org/sphinx/frameworks/signatures.html)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/bro-anomaly-detection/3006/3 "2022-05-06T15:41:35Z")

</div>


