# DPD and similar analysis

**URL:** <https://community.zeek.org/t/dpd-and-similar-analysis/1462>\
**Category:** Zeek\
**Created:** [December 1, 2008, 8:06pm UTC](https://community.zeek.org/t/dpd-and-similar-analysis/1462 "2008-12-01T20:06:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [December 1, 2008, 8:06pm UTC](https://community.zeek.org/t/dpd-and-similar-analysis/1462/1 "2008-12-01T20:06:27Z")

</div>

I have a project to do DPD-like offline analysis and was looking for help and feedback. First off, I'm trying to make sure that DPD is working, so I tried to get bro to write ServerFound messages to the notice log. BTW, in all my tests I made sure my capture filter included "or (tcp or udp or icmp)". To get bro to report ALL servers found, I temporarily modified detect-protocols.bro and commented out the two sections that would prevent generating notices for "well known ports" (using dpd\_config). So I would expect to see ServerFound messages for all protocols that have been detected. Here is my command line (zzz-custom just redefines capture\_filters as stated above):

bro -r pcapfile.pcap conn dpd irc-bot dyn-disable detect-protocols detect-protocols-http proxy http ssh zzz-custom

When I run this against the pcap file that contains tons of HTTP, SSH and likely other traffic, the only ServerFound messages are for SSH. If I was getting DPD to work correctly, I would expect to find HTTP ServerFound messages. I'm looking to get bro to output all ProtocolFound and ServerFound messages, so any help to get that to happen would be appreciated.

Once I figure this out, then I'll use DPD for it's intended purpose: to detect protocols on non-standard ports. However, I'm also supposed to do the inverse, that is, detect non-standard protocols on standard ports. Any thoughts on how I could do this?

Thanks,

Eric T  
Sandia National Labs

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [December 2, 2008, 9:30pm UTC](https://community.zeek.org/t/dpd-and-similar-analysis/1462/2 "2008-12-02T21:30:16Z")

</div>

> or icmp)". To get bro to report ALL servers found, I temporarily  
> modified detect-protocols.bro and commented out the two sections that  
> would prevent generating notices for "well known ports" (using  
> dpd\_config). So I would expect to see ServerFound messages for all  
> protocols that have been detected.

Hmm... I can't reproduce that. Likewise commenting out the  
dpd\_config check in detect\_protocols.bro and running with a tiny SSH  
trace I get:

> bro -r ssh.trace ssh dpd detect-protocols

1150485521.634103 ProtocolFound XXX.XXX.XXX.XXX/49244 \> XXX.XXX.XXX.XXX/ssh SSH on port 22/tcp  
1150485521.634103 ServerFound XXX.XXX.XXX.XXX: SSH server on port 22/tcp

> bro -r pcapfile.pcap conn dpd irc-bot dyn-disable detect-protocols  
> detect-protocols-http proxy http ssh zzz-custom

Note that you should use http-request instead of http, and  
potentially also load http-{reply,body}.bro.

> Once I figure this out, then I'll use DPD for it's intended purpose: to  
> detect protocols on non-standard ports. However, I'm also supposed to do  
> the inverse, that is, detect non-standard protocols on standard ports. Any  
> thoughts on how I could do this?

dyn-disable reports ProtocolViolations when the analyzer can't parse  
the protocol, which is an indicator that there might be something  
running on that port which isn't the standard protocol.

Also, if you enable dpd\_conn\_logs in conn.bro, the service field  
indicates the DPD result, including whether it could \*not\* parse the  
protocol. From CHANGES:

&nbsp;&nbsp;The new script variable dpd\_conn\_logs (default F), if true,  
&nbsp;&nbsp;changes the semantics of the service field in connection logs  
&nbsp;&nbsp;written to conn.log, as follows (Robin Sommer). It becomes a  
&nbsp;&nbsp;comma-separated list of analyzers confirmed by DPD to parse the  
&nbsp;&nbsp;connection's payload. If no analyzer could confirm its protocol,  
&nbsp;&nbsp;but the connection uses a well-known port, the service is the name  
&nbsp;&nbsp;of the port with "?" appended (e.g., "http?"), as long as the  
&nbsp;&nbsp;corresponding analyzer has not declined the connection. In  
&nbsp;&nbsp;addition, ftp-data sessions are labeled "ftp-data" and portmapper  
&nbsp;&nbsp;connections are labeled with the specific method-call (just as  
&nbsp;&nbsp;before).

&nbsp;&nbsp;dpd\_conn\_logs defaults to F because the change in semantics may  
&nbsp;&nbsp;break scripts that parse conn.logs; but it will likely change to  
&nbsp;&nbsp;the default in the future. With dpd\_conn\_logs turned off, conn  
&nbsp;&nbsp;logs are generated as they used to be, with a few rare exceptions  
&nbsp;&nbsp;(with previous versions, the service field was sometimes  
&nbsp;&nbsp;determined while the connection was still alive; now it's always  
&nbsp;&nbsp;determined at the time when the conn.log entry is written out).  
&nbsp;&nbsp;  
Robin

---

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [December 9, 2008, 7:21pm UTC](https://community.zeek.org/t/dpd-and-similar-analysis/1462/3 "2008-12-09T19:21:29Z")

</div>

Hi Robin,

When I do the run, I have no trouble getting the SSH ServerFound and ProtocolFound messages either. But I'm not getting the expected ServerFound and ProtocolFound notices for HTTP. I re-ran my test using your suggestion of loading http-request, http-reply and http-body, and I still didn't get those notices for HTTP. So I'd like to know, what does it take to see ServerFound and ProtocolFound notices for HTTP on standard HTTP ports (e.g. 80)? Thanks,

Eric

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/dpd-and-similar-analysis/1462/4 "2022-05-06T15:38:48Z")

</div>


