# Large file ex-filtration revisited

**URL:** <https://community.zeek.org/t/large-file-ex-filtration-revisited/3057>\
**Category:** Zeek\
**Created:** [April 3, 2014, 9:39pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057 "2014-04-03T21:39:05Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [April 3, 2014, 9:39pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/1 "2014-04-03T21:39:05Z")

</div>

So first off a HUGE thank you to Robert Rotsted who posted the original after\_hours\_exfiltrate.bro. ([http://mailman.icsi.berkeley.edu/pipermail/bro/2014-March/007510.html](http://mailman.icsi.berkeley.edu/pipermail/bro/2014-March/007510.html)). Here's how I've modified this:

module Exfil;

export {

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;redef enum Notice::Type += {  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Large\_File\_Upload,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;};  
}

## Each time a connection is logged execute the following code  
event Conn::log\_conn(rec: Conn::Info) {

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;## Ensure orig\_bytes and resp\_bytes exist, if not, return.  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if (! (rec?$orig\_bytes || rec?$resp\_bytes))  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;## Is this connection between a local originator and a  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;## remote responder?  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;## Are the sent bytes greater that 10 x the received bytes?  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;## Has the originator sent more than 3 Megabytes?  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( rec$id$orig\_h in Site::local\_nets &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$id$resp\_h !in Site::local\_nets &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes \> (20 \* rec$resp\_bytes) &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes \>= 13145728 )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NOTICE([$note=Large\_File\_Upload,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$id=rec$id,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$identifier=cat(rec$uid),  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$msg=fmt("Sent Bytes: %s, Received Bytes: %s",  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes, rec$resp\_bytes)]);  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

}

I noticed today an anomaly I guess:

2014-04-03T13:38:45-0600 - x.x.x.x 55023 4.71.33.182 80 - - - tcp Exfil::Large\_File\_Upload Sent Bytes: 1213381425, Received Bytes: 0 - x.x.x.x 4.71.33.182 80 - bro Notice::ACTION\_LOG 3600.000000 F - - - --

2014-04-03T13:38:42-0600 CSZCCe4mZI1T7iJogg x.x.x.x 55023 4.71.33.182 80 tcp - 0.035191 1213381425 0 RSTOS0 T 0 SaR 2 88 1 40 (empty)

I found a RST packet in the capture that matched close to the sent bytes:

Transmission Control Protocol, Src Port: 55023 (55023), Dst Port: http (80), Seq: 1213381426, Len: 0

Did I hose the script by removing the hourly constraint? Thanks for the the assist...this has helped me better understand the scripting (though I'm still just at the copy and paste level :)).

James

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [April 3, 2014, 10:18pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/2 "2014-04-03T22:18:08Z")

</div>

This looks like it may be a “half-open” TCP connection, and Bro may report inaccurate {orig,resp}\_bytes unless you’re running a development version from the git repo which has a fix for this situation. What version of Bro are you running?

A way to improve your detection with only script changes could be to include {orig,resp}\_ip\_bytes in the criteria. The difference is that field counts total bytes of IP packets, not just payload data. It’s also more sensitive to packet loss, where {orig,resp}\_bytes should still work since it’s monitoring the TCP sequence space.

- Jon

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [April 3, 2014, 10:45pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/3 "2014-04-03T22:45:46Z")

</div>

Thanks Jon,

I'm on 2.2 here. I'm going to start fiddling with the script now...thanks again for the help and response.

James

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [April 3, 2014, 10:59pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/4 "2014-04-03T22:59:42Z")

</div>

Ok...I've made the below modification:

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if ( rec$id$orig\_h in Site::local\_nets &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$id$resp\_h in Site::local\_nets &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes \> (10 \* rec$resp\_bytes) &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes \> (10 \* rec$resp\_ip\_bytes) &&  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes \>= 3145728 )

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{

This works in dev when sending a large file, so going to test this out in production....thank you.

James

---

<div class="post-metadata">

**Author:** ![Robert\_Rotsted](https://avatars.discourse-cdn.com/v4/letter/r/8e7dd6/32.png) [@Robert\_Rotsted](https://community.zeek.org/u/Robert_Rotsted)\
**Post date:** [April 4, 2014, 2:38pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/5 "2014-04-04T14:38:50Z")

</div>

James,

Glad to hear that the script was helpful!

–bob

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [April 4, 2014, 3:36pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/6 "2014-04-04T15:36:09Z")

</div>

Well shoot..still seeing these:

1396617228.413862 - x.x.x.x 51859 x.x.x.x 80 - - - tcp Exfil::Large\_File\_Upload Sent Bytes: 1029838798, Received Bytes: 0 - x.x.x.x x.x.x.x 80 - bro Notice::ACTION\_LOG 3600.000000 F - - - - -

1396620769.215111 - x.x.x.x 53522 x.x.x.x 80 - - - tcp Exfil::Large\_File\_Upload Sent Bytes: 569497424, Received Bytes: 0 - x.x.x.x x.x.x.x 80 - bro Notice::ACTION\_LOG 3600.000000 F - - - - -

2014-04-04T07:13:45-0600 CGZlLW2nctAkETr18c x.x.x.x 51859 x.x.x.x 80 tcp - 0.064546 1029838798 0 RSTOS0 T 0 SaR 2 92 1 52 (empty)  
2014-04-04T08:12:46-0600 C7E5mt24LSdkhFVcI5 x.x.x.x 53522 x.x.x.x 80 tcp - 0.064791 569497424 0 RSTOS0 T 0 SaR 2 92 1 52 (empty)

Should I just take the plunge to the latest git? Side question...how to get the bro id (CGZlLW2nctAkETr18c) in the notice file? I have:

&nbsp;&nbsp;NOTICE([$note=Large\_File\_Upload,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$id=rec$id,  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$identifier=cat(rec$uid),  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$msg=fmt("Sent Bytes: %s, Received Bytes: %s",  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;rec$orig\_bytes, rec$resp\_bytes)]);

Thank you.

James

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [April 4, 2014, 3:50pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/7 "2014-04-04T15:50:13Z")

</div>

rec$orig\_bytes \> (10 \* rec$resp\_ip\_bytes) is probably still going to be true if the calculation of orig\_bytes was botched and incorrectly reported as too large. You probably meant rec$orig\_ip\_bytes \> (10 \* rec$resp\_bytes) ?

Another idea might be to just check for ‘d’ or ‘D’ in the history field to verify the value is sane — absence of ‘d’ or ‘D’ means no payload data was seen, just control packets, so large values of {orig,resp}\_bytes can’t possibly make sense.

- Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/large-file-ex-filtration-revisited/3057/8 "2022-05-06T15:41:41Z")

</div>


