# mask\_addr?

**URL:** <https://community.zeek.org/t/mask-addr/1946>\
**Category:** Development\
**Tags:** development\
**Created:** [July 23, 2011, 3:19am UTC](https://community.zeek.org/t/mask-addr/1946 "2011-07-23T03:19:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [July 23, 2011, 3:19am UTC](https://community.zeek.org/t/mask-addr/1946/1 "2011-07-23T03:19:48Z")

</div>

I think the existing mask\_addr function may be named wrong. Here's the current prototype:  
&nbsp;&nbsp;function mask\_addr(a: addr, top\_bits\_to\_keep: count): addr

I want it to do this (and I think it makes more sense based on the name):  
&nbsp;&nbsp;function mask\_addr(a: addr, top\_bits\_to\_keep: count): subnet

I'm not sure how the existing function was ever used, but it seems like it must have been a fairly limited use case. Does that seem reasonable to change what that function does and steal the name? I suppose the existing function could be renamed to something else if someone still knows of a use for it.

In case it's not obvious from the prototypes above, what I'm aiming to do is take addresses and mask them off to subnets (I need it for aggregation with the metrics framework).  
For example...  
print mask\_addr(1.2.3.4, 24)  
&nbsp;&nbsp;=\> 1.2.3.0/24

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [July 23, 2011, 3:23am UTC](https://community.zeek.org/t/mask-addr/1946/2 "2011-07-23T03:23:04Z")

</div>

> I want it to do this (and I think it makes more sense based on the name):  
> &nbsp;&nbsp;function mask\_addr(a: addr, top\_bits\_to\_keep: count): subnet

Yeah, it predates the introduction of subnets into Bro.

> I'm not sure how the existing function was ever used

It was things like:

&nbsp;&nbsp;if ( mask\_addr(c$id$orig\_h, 24) == 1.2.3.0 )  
&nbsp;&nbsp;&nbsp;&nbsp;# Whoops, it's coming from 1.2.3/24 ...

See {backdoor,ftp,scan}.bro (at least, the 1.5 versions 🙂 for such uses.

> but it seems like it must have been a fairly limited use case. Does  
> that seem reasonable to change what that function does and steal the name?

Yes.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [July 23, 2011, 3:24am UTC](https://community.zeek.org/t/mask-addr/1946/3 "2011-07-23T03:24:58Z")

</div>

Ah, that would be why I couldn't find anything about it in the CHANGES file. 🙂

I'll file a ticket. Thanks.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/mask-addr/1946/4 "2022-05-06T15:39:41Z")

</div>


