# HTTPS Analyzer

**URL:** <https://community.zeek.org/t/https-analyzer/3641>\
**Category:** Zeek\
**Created:** [June 5, 2015, 9:53pm UTC](https://community.zeek.org/t/https-analyzer/3641 "2015-06-05T21:53:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![N\_B](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@N\_B](https://community.zeek.org/u/N_B)\
**Post date:** [June 5, 2015, 9:53pm UTC](https://community.zeek.org/t/https-analyzer/3641/1 "2015-06-05T21:53:28Z")

</div>

Hello,

I am quite new to Bro and need some help. I did go through some of the documentation and some source code but still not clear whether its possible to achieve what we are trying to do.

In a nutshell, we are trying to write an HTTPS analyzer for on the fly decryption of the SSL stream and then feed it to the built in HTTP Analyzer. We will use a crypto library + server keys to achieve the decryption. Is it possible at all do this in Bro?

The high level idea is to derive the HTTPS\_Analyzer from the current HTTP\_Analyzer, feed the stream from TCP\_Analyzer into the HTTPS\_Analyzer and utilize the HTTP\_Analyzer calls for the remainder of the functionality.

Thanks for your help,  
NB

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [June 5, 2015, 10:46pm UTC](https://community.zeek.org/t/https-analyzer/3641/2 "2015-06-05T22:46:47Z")

</div>

Hello,

> In a nutshell, we are trying to write an HTTPS analyzer for on the fly  
> decryption of the SSL stream and then feed it to the built in HTTP  
> Analyzer. We will use a crypto library + server keys to achieve the  
> decryption. Is it possible at all do this in Bro?

Sure, in theory it is possible to do that. You would have to extend the  
current SSL analyzer and start decrypting the packets at the right point  
of time. You should not even have to implement an HTTPS analyzer; you  
basically can just shove the decrypted data back into the Bro processing  
pipeline.

The best example for this happening might potentially be one of the tunnel  
analyzers -- SMTP also does it by attaching SSL as a sub-analyzer in case  
STARTTLS is used.

The biggest problem will probably be to get the SSL analyzer changed to  
decrypt the data. You also will have to get your encryption keys into Bro  
somehow before the first encrypted data packet is parsed by the SSL  
analyzer.

Johanna

---

<div class="post-metadata">

**Author:** ![N\_B](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@N\_B](https://community.zeek.org/u/N_B)\
**Post date:** [June 8, 2015, 8:30pm UTC](https://community.zeek.org/t/https-analyzer/3641/3 "2015-06-08T20:30:12Z")

</div>

Thanks Johanna. Much appreciated for the suggestion of extending the SSL analyzer.

> “you basically can just shove the decrypted data back into the Bro processing pipeline.”

I am assuming that by above you mean to just call the “ForwardStream()” method? Please confirm if that’s the case.

> “The biggest problem will probably be to get the SSL analyzer changed to  
> decrypt the data. You also will have to get your encryption keys into Bro  
> somehow before the first encrypted data packet is parsed by the SSL  
> analyzer.”

Getting the key loaded via the new class’s constructor or as a static initialized value won’t be enough? Maybe I missed something important here. Can you please clarify?

Thanks  
Nikunj

---

<div class="post-metadata">

**Author:** ![N\_B](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@N\_B](https://community.zeek.org/u/N_B)\
**Post date:** [June 11, 2015, 12:03am UTC](https://community.zeek.org/t/https-analyzer/3641/4 "2015-06-11T00:03:29Z")

</div>

Hi Johanna (and everyone else on the list),

I am currently struggling with this as to how to put the decrypted data back into the Bro pipeline? I am able to get the data decrypted (actually its just a test with a simple xor data into it and xor it back in the analyzer) in my analyzer and calling ForwardStream() with the new data and length. I have checked and double checked that everything looks like it should be i.e. the resulting stream is HTTP data (headers, content etc) but for some reason the HTTP analyzer does not get invoked. Please help.

Thanks  
Nikunj

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/https-analyzer/3641/5 "2022-05-06T15:42:44Z")

</div>


