I just read an article (http://citeseerx.ist.psu.edu/viewdoc/download?doi= which compares performances of Bro and Snort. The authors stated at section 5.6 that Bro does not have a Unicode decoder for HTTP URI. Since their work were based on Bro 0.9a9, I guess this is not applicable for the current versions of Bro.

Can someone confirm or infirm my point of view ?


Bro does not consider unicode in any way right now. Strings are only considered to be strings of individual bytes but low order ascii characters will be printed as such. Does that answer your question? I've been thinking about how to appropriately add unicode support for quite a while but I don't have a completely clear notion yet.