# Connection History: "connection direction was flipped by Bro’s heuristic"

**URL:** <https://community.zeek.org/t/connection-history-connection-direction-was-flipped-by-bro-s-heuristic/4798>\
**Category:** Zeek\
**Created:** [April 21, 2017, 11:35pm UTC](https://community.zeek.org/t/connection-history-connection-direction-was-flipped-by-bro-s-heuristic/4798 "2017-04-21T23:35:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Crawford](https://avatars.discourse-cdn.com/v4/letter/d/919ad9/32.png) [@Dave\_Crawford](https://community.zeek.org/u/Dave_Crawford)\
**Post date:** [April 21, 2017, 11:35pm UTC](https://community.zeek.org/t/connection-history-connection-direction-was-flipped-by-bro-s-heuristic/4798/1 "2017-04-21T23:35:18Z")

</div>

What does the caret ("_connection direction was flipped by Bro’s heuristic_”) in a connections history mean? If the packet in question was spoofed (like the receiving end of a DNS amplification attack) would that trigger Bro’s heuristics?

Below are entries from dns, conn and weird logs for the same event for which I can’t find any indications that it sourced from my network. Additionally, there are no subsequent connection attempts to the IP contained the response packet.

Dns.log  
1491285594.163321 CFXfdl4zMQrM2T15Wa 57555 194.9.69.193 53 udp 21705 - wfuvsrsrwb.www.91duofenxiang[.]com - - - - 0 NOERROR F F F T 0 193.58.251[.]1 60.000000 F

Conn.log  
1491285594.163321 CFXfdl4zMQrM2T15Wa 57555 194.9.69.193 53 udp dns - - - SHR T ^d 0 0 1 94 (empty) PDC\_NSM-4 US RU

Weird.log  
1491285604.163437 CFXfdl4zMQrM2T15Wa 57555 194.9.69.193 53 dns\_unmatched\_msg - F PDC\_NSM-4

Thanks,  
-Dave

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [April 22, 2017, 2:23am UTC](https://community.zeek.org/t/connection-history-connection-direction-was-flipped-by-bro-s-heuristic/4798/2 "2017-04-22T02:23:02Z")

</div>

> What does the caret ("connection direction was flipped by Bro’s heuristic”) in a connections history mean? If the packet in question was spoofed (like the receiving end of a DNS amplification attack) would that trigger Bro’s heuristics?

Yes..

> Below are entries from dns, conn and weird logs for the same event for which I can’t find any indications that it sourced from my network. Additionally, there are no subsequent connection attempts to the IP contained the response packet.
> 
> Dns.log  
> 1491285594.163321 CFXfdl4zMQrM2T15Wa \<REDACTED\> 57555 194.9.69.193 53 udp 21705 - wfuvsrsrwb.www.91duofenxiang[.]com - - - - 0 NOERROR F F F T 0 193.58.251[.]1 60.000000 F
> 
> Conn.log  
> 1491285594.163321 CFXfdl4zMQrM2T15Wa \<REDACTED\> 57555 194.9.69.193 53 udp dns - - - SHR T ^d 0 0 1 94 (empty) PDC\_NSM-4 US RU
> 
> Weird.log  
> 1491285604.163437 CFXfdl4zMQrM2T15Wa \<REDACTED\> 57555 194.9.69.193 53 dns\_unmatched\_msg - F PDC\_NSM-4

It definitely wasn't sourced from your network. You can see the numbers after the history field(^d) are:

orig\_pkts=0  
orig\_ip\_bytes=0  
resp\_pkts=1  
resp\_ip\_bytes=94

which shows that bro saw that you sent 0 packets and received 1.

The issue is that you were sent a DNS response packet, which in a perfect world where carriers do proper ingress filtering would have only happened if you had sent the corresponding DNS query packet. Bro assumes it didn't see the query due to capture loss and sets up the orig/resp under that assumption.

Unfortunately this doesn't work so well for backscatter, especially when dealing with UDP protocols.

It's easy enough to filter out connections like this to another log file if you wanted, generally anything with a local address as a source and resp\_pkts=1 and orig\_pkts=0 is from backscatter.

I've looked into fixing this inside of Bro, but the code that handles this sort of thing is a bit complicated.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/connection-history-connection-direction-was-flipped-by-bro-s-heuristic/4798/3 "2022-05-06T15:44:52Z")

</div>


