# Development of layer 4 protocol parser (ESP)

**URL:** <https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024>\
**Category:** Zeek\
**Created:** [February 25, 2020, 6:17pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024 "2020-02-25T18:17:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bart\_Hermans](https://avatars.discourse-cdn.com/v4/letter/b/ac8455/32.png) [@Bart\_Hermans](https://community.zeek.org/u/Bart_Hermans)\
**Post date:** [February 25, 2020, 6:17pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024/1 "2020-02-25T18:17:05Z")

</div>

Recently I got into Zeek and started to play around with BinPAC plugin  
development. BinPAC allowed me to pretty easily write a protocol parser  
for IKE messages. However, I stumbled upon a problem. As I already read  
on the mailing list, BinPAC is aimed at parsing protocols which run on  
top of UDP or TCP. I also read that to parse protocols on lower layers  
(let's say the transport layer), BinPAC won't be able to help you  
anymore. The solution that was proposed in a few messages that I read  
was to modify the source code of Zeek to support layer 4 protocols other  
than TCP, UDP and ICMP.

First and foremost; before posting this message, that's exactly what I  
did. My approach was to look at the implementation of ICMP and UDP in  
Zeek (which are also layer 4 protocols). Based on this I tried my best  
at writing a protocol analyzer alongside these protocols. However, after  
spending a good amount of hours trying to write a protocol parser for  
ESP-messages (protocol number 50) I came to the conclusion that the code  
had become quite messy. Most importantly I didn't get the ESP-parser to  
work properly. Even if I would have got it working, the code wouldn't be  
patch safe anymore from future versions of Zeek.

My issue is as follows; I only want to be able to detect that a protocol  
number 50 packet has been seen with the parsing of the very first field.  
Is the only way to get this working to give another shot at modifying  
the source code or is there a more cleaner/patch friendly path to  
travel? Even a gentle push in the right direction would very much be  
appreciated.

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [February 26, 2020, 12:09pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024/2 "2020-02-26T12:09:35Z")

</div>

Hi Bart,

Regarding patch safety, support for pluggable low-lever analyzers would help. This is actually a long-standing request: [https://github.com/zeek/zeek/issues/248](https://github.com/zeek/zeek/issues/248) There is a first approach that needs some more improvements and reviews. We are working on it.

Jan

---

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vlad\_Grigorescu](https://community.zeek.org/u/Vlad_Grigorescu)\
**Post date:** [February 26, 2020, 3:58pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024/3 "2020-02-26T15:58:34Z")

</div>

Jan,

Is that branch publicly available somewhere? Thanks!

—Vlad

---

<div class="post-metadata">

**Author:** ![Jan](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@Jan](https://community.zeek.org/u/Jan)\
**Post date:** [February 27, 2020, 5:55pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024/4 "2020-02-27T17:55:06Z")

</div>

Hi Vlad,

as the code was written in context of a thesis, we were not able to publish it yet. I'll keep you posted.

Jan

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:47pm UTC](https://community.zeek.org/t/development-of-layer-4-protocol-parser-esp/6024/5 "2022-05-06T15:47:06Z")

</div>


