new Bro CURRENT release (1.3.1)

Bro release 1.3.1 is now available from:

  ftp://bro-ids.org/bro-1.X-current.tar.gz

This version fixes three bugs found in the recent 1.3 release:

  1.3.1 Thu Jul 19 09:39:33 PDT 2007

  - Bug fix for dynamic protocol detection (Robin Sommer).

  - Bug fix for zip-encoded Web items (Robin Sommer).

  - Configuration fix for installation (Brian Tierney).

Patch appended.

    Vern

Is there any paper or documentation on how the dynamic protocol detection works?

Thanks

Is there any paper or documentation on how the dynamic protocol detection works?

There's a paper at

  Dynamic Application-Layer Protocol Analysis for Network Intrusion Detection <- HTML
  http://www.icir.org/robin/papers/usenix06.pdf

- Vern

.. and there's also some documentation on usage in the Wiki.

Robin