# known services

**URL:** <https://community.zeek.org/t/known-services/5754>\
**Category:** Zeek\
**Created:** [July 8, 2019, 10:19am UTC](https://community.zeek.org/t/known-services/5754 "2019-07-08T10:19:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Palumbo\_Mauro](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@Palumbo\_Mauro](https://community.zeek.org/u/Palumbo_Mauro)\
**Post date:** [July 8, 2019, 10:19am UTC](https://community.zeek.org/t/known-services/5754/1 "2019-07-08T10:19:17Z")

</div>

Hi all,

I am looking at the known-services log and it seems to me that when multiple services are detected on the conn.log, not all of them are reported in the known-services.log. For example, http+ssl in the conn.log is logged in known-services.log as only http, while other multiple protocols (for exmaple NTLM,DCE\_RPC or even as many as SMB,DCE\_RPC,KRB,GSSAPI) are correctly logged. Is there any rationale for this behaviour or it is just a bug? I saw there is an issue (#419) open on github about it, but it’s not clear to me why this happens only for some combinations of multiple protocols.

Besides, I noticed that the know-services script does not detect all DNS conns. I opened an issue on this #455.

Last a minor thing. In the script known-services.zeek, in the event connection\_state\_remove, there is an if statement (below) which is filtering all non-estabilshed tcp conns, but also all udp conns.

if ( c$resp$state != TCP\_ESTABLISHED )

return;

Despite this, everything works fine because all udp analyzers rise an event protocol\_confirmation. Would it be better changing the if statement into something like:

if ( c$resp$state != TCP\_ESTABLISHED && c$resp$state != UDP\_ACTIVE )

return;

In this way, if an udp analyzer does not rise the event protocol\_confirmation, the connection will still be logged into known-services.

Any thoughts?

Thanks.

Mauro

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [July 8, 2019, 4:02pm UTC](https://community.zeek.org/t/known-services/5754/2 "2019-07-08T16:02:00Z")

</div>

Some connections are decoded as multiple protocols. Something like a  
SMTP connection that runs STARTTLS and turns into SSL. This will end  
up in the conn log as smtp,ssl and also show up in known services as  
smtp,ssl. The problem is that services are tracked by ip+port,  
instead of ip+port+service, so whatever the protocol was on the first  
seen connection is the one that gets logged. This means that if the  
first seen connection is just 'smtp', it will get logged as 'smtp' and  
then further 'smtp,ssl' connections will not get logged.

I had an earlier patch to update the service tracking to include the  
service, it just needs to be updated for 2.6 and tested.

---

<div class="post-metadata">

**Author:** ![Palumbo\_Mauro](https://avatars.discourse-cdn.com/v4/letter/p/7c8e57/32.png) [@Palumbo\_Mauro](https://community.zeek.org/u/Palumbo_Mauro)\
**Post date:** [July 9, 2019, 7:30am UTC](https://community.zeek.org/t/known-services/5754/3 "2019-07-09T07:30:32Z")

</div>

Ok, thanks. Are you planning to release the patch soon?

-----Messaggio originale-----

---

<div class="post-metadata">

**Author:** ![JustinAzoff](https://avatars.discourse-cdn.com/v4/letter/j/13edae/32.png) [@JustinAzoff](https://community.zeek.org/u/JustinAzoff)\
**Post date:** [July 9, 2019, 2:09pm UTC](https://community.zeek.org/t/known-services/5754/4 "2019-07-09T14:09:53Z")

</div>

Hopefully.. it's not super complicated but making sure all of the edge  
cases are tested properly is most of the work.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/known-services/5754/5 "2022-05-06T15:46:36Z")

</div>


