# "Faking" connections and http records

**URL:** <https://community.zeek.org/t/faking-connections-and-http-records/2613>\
**Category:** Zeek\
**Created:** [March 22, 2013, 8:04pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613 "2013-03-22T20:04:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [March 22, 2013, 8:04pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613/1 "2013-03-22T20:04:37Z")

</div>

Hi all:

I'm in the process of processing our syslogs for apache logs (which  
will allow us visibility into ssl sessions into our webservers), and  
am at the point where I am able to import the data into bro using the  
input framework. There's enough data to fill in most of a connection  
record, and to fake other stuff. What would be really cool would be  
to create a connection record, and have it go thru the normal  
processing, feed the http data in for processing via the standard http  
processes, and close down the connection. This would allow for  
standard logging, and standard IDS processes to act upon this info.

Does anyone have suggestions on how to proceed with this?

Thanks in advance,

Jim Mellander  
NERSC Cybersecurity  
510-486-7204

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [March 22, 2013, 8:54pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613/2 "2013-03-22T20:54:29Z")

</div>

It wouldn't work very well. 🙂

Nearly all of the detections rely on the various http\_ events. I would go down a slightly different route with logs than I would with raw traffic. This is something that I've been talking about for quite a while and I suspect something related to happen in the next year.

I think it's really cool that you're importing logs into Bro!

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [March 22, 2013, 9:18pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613/3 "2013-03-22T21:18:29Z")

</div>

Well, its unfortunate that we can't feed in data from other sources  
and subject it to the same policies that network traffic is subject  
to.

In the meantime, I may just write some code that fakes the data into  
pcap files that can be read by bro directly.

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [July 3, 2013, 4:51pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613/4 "2013-07-03T16:51:25Z")

</div>

Reviving my old thread - this project was on hiatus for a while, but  
is now generating useful data, although not yet in production.

What I ended up doing was transport the syslogs of interest (apache  
logs) via stunnel to my bro box, which then runs a custom python  
script:

1. Parses and extracts the logs into python variables  
2. Construct plausible http session conversation.  
3. Packetize the session into TCP packets  
4. Push tcp packets onto virtual interface  
5. bro listening to virtual interface performs normal IDS monitoring of traffic.

Here's an example:

Syslog entry:  
Jul 3 09:34:54 128.55.22.194 httpd[4148]: [www.nersc.gov](http://www.nersc.gov) 66.249.73.109  
- - [03/Jul/2013:09:34:54 -0700] "GET /robots.txt HTTP/1.1" 200 82 "-"  
"Mozilla/5.0 (compatible; Googlebot/2.1;  
+http://www.google.com/bot.html)"

Bro http logs:  
Jul 3 09:34:58 u3qPWFy8m9 66.249.73.109 64555 128.55.22.194 80 GET [www.nersc.gov](http://www.nersc.gov) /robots.txt Mozilla/5.0  
(compatible; Googlebot/2.1;  
+http://www.google.com/bot.html) 0 0 200 \<empty\>(empty) - - - - - -

A few points:

1.Tested creating packets to make the conn logs show the correct  
amount of data returned by the server, as reported in the log, but  
eventually chose to not do that, as that is of limited value.  
2. Support both ipv4 & ipv6 - if a host is dual homed, typically the  
syslog entry will be from the ipv4 address, but the requesting ip may  
be ipv6, in which case we convert both address to ipv6 using several  
strategies.

The value of this, from our perspective, is that we can now perform  
the usual http IDS functions on https connections to our syslogging  
webservers, without having to store the certs in our bro system for  
decryption. We also have visibility on intrasite traffic to those  
same webservers.

Alpha quality code available for the asking.

Jim

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/faking-connections-and-http-records/2613/5 "2022-05-06T15:40:52Z")

</div>


