# new bro "CURRENT" release - 0.8a79

**URL:** <https://community.zeek.org/t/new-bro-current-release-0-8a79/478>\
**Category:** Zeek\
**Created:** [March 25, 2004, 5:25pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478 "2004-03-25T17:25:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [March 25, 2004, 5:25pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/1 "2004-03-25T17:25:39Z")

</div>

An updated "CURRENT" version of Bro is now available from the usual location:

&nbsp;&nbsp;ftp://ftp.ee.lbl.gov/bro-pub-0.8-current.tar.gz

This version has a lot of changes, including new analyzers, documentation,  
language features, VLAN support, and the beginnings of IDMEF support. I've  
appended the changes since the last "CURRENT" version (0.8a70).

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Anton\_Chuvakin\_Ph.D](https://avatars.discourse-cdn.com/v4/letter/a/eb8c5e/32.png) [@Anton\_Chuvakin\_Ph.D](https://community.zeek.org/u/Anton_Chuvakin_Ph.D)\
**Post date:** [March 25, 2004, 5:33pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/2 "2004-03-25T17:33:40Z")

</div>

> and the beginnings of IDMEF support.

Just curious, what is the motivation for IDMEF support? Just to be  
consistent with industry "standard" or something else? Basically, I am  
asking how users are supposed to use IDMEF in production enviorment.

Best,

---

<div class="post-metadata">

**Author:** ![Marc\_Spitzer](https://avatars.discourse-cdn.com/v4/letter/m/54ee81/32.png) [@Marc\_Spitzer](https://community.zeek.org/u/Marc_Spitzer)\
**Post date:** [March 25, 2004, 6:19pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/3 "2004-03-25T18:19:37Z")

</div>

This really blows snort out of the water.

Thank you,

marc

---

<div class="post-metadata">

**Author:** ![Anton\_Chuvakin\_Ph.D](https://avatars.discourse-cdn.com/v4/letter/a/eb8c5e/32.png) [@Anton\_Chuvakin\_Ph.D](https://community.zeek.org/u/Anton_Chuvakin_Ph.D)\
**Post date:** [March 25, 2004, 9:39pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/4 "2004-03-25T21:39:56Z")

</div>

0. cat /etc/redhat-release  
Red Hat Linux release 7.3 (Valhalla)

1. ./configure --disable-openssl

2. make

g++ -o bro main.o net\_util.o util.o parse.o scan.o re-parse.o re-scan.o  
rule-parse.o rule-scan.o Act ive.o Anon.o Attr.o BackDoor.o Base64.o  
BroString.o CCL.o ChunkedIO.o CompHash.o Conn.o DCE\_RPC.o DF A.o DNS.o  
DNS\_Mgr.o DbgBreakpoint.o DbgHelp.o DbgWatch.o Debug.o DebugCmds.o Desc.o  
Dict.o Discard.o EquivClass.o Event.o EventHandler.o EventRegistry.o  
Expr.o FTP.o File.o Finger.o Frag.o Frame.o Func.o Gnutella.o HTTP.o  
Hash.o ICMP.o ID.o Ident.o IntSet.o InterConn.o List.o Logger.o Login.o  
MIME.o NFA.o NTP.o NVT.o Net.o NetVar.o NetbiosSSN.o Obj.o PacketFilter.o  
PacketSort.o PktSrc.o PolicyFile .o Portmap.o PrefixTable.o  
PriorityQueue.o Queue.o RE.o RPC.o Reassem.o RemoteSerializer.o Rlogin.o  
Rule.o RuleAction.o RuleCondition.o RuleMatcher.o SMTP.o SSH.o Scope.o  
SerializationFormat.o SerialO bj.o Serializer.o Sessions.o StateAccess.o  
Stats.o SteppingStone.o Stmt.o TCP.o TCP\_Contents.o TCP\_E ndpoint.o  
TCP\_Rewriter.o Telnet.o Timer.o Type.o UDP.o Val.o Var.o XDR.o cq.o md5.o  
patricia.o setsi gnal.o version.o nb\_dns.o -Llibedit -ledit -lresolv  
-lpcap -lpcap /usr/lib/libresolv.a -ltermca p -lm

Sessions.o: In function `NetSessions::NewConn(HashKey \*, double, ConnID  
const \*, tcphdr const \*)':  
Sessions.o(.text+0x41a4): undefined reference to  
`SSL\_ConnectionProxy::SSL\_ConnectionProxy(NetSessio  
ns \*, HashKey \*, double, ConnID const \*, tcphdr const \*)'  
collect2: ld returned 1 exit status  
make: \*\*\* [bro] Error 1

Any ideas?

Same error happens if ssl is not disabled.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [April 2, 2004, 8:15am UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/5 "2004-04-02T08:15:47Z")

</div>

First, it's indeed simply a standardized way to talk to other  
systems. If you're using different kinds of NIDSs (either at  
different locations or even at the same place), they may share their  
results with IDMEF.

Second, it's interesting to see how Bro's semantics map to IDMEF and  
vice versa. Most parts of Bro work on a lower-level than IDMEF. So,  
a large fraction of Bro's state is not (reasonably) convertible to  
IDMEF. On the other hand, Bro's alert framework looks quite similar  
to IDMEF's model. By adding IDMEF support we should be able to  
better understand what kind of information can actually be  
represented in this format (and if it's sufficient for the task its  
supposed to do).

Regarding the question how to use it: if you want to connect  
multiple Bros, IDMEF is probably not the best way; there are other  
mechanisms now (which are still experimental though). But if you  
want to share alerts with other systems, IDMEF could be an option.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/new-bro-current-release-0-8a79/478/6 "2022-05-06T15:36:57Z")

</div>


