# (no subject)

**URL:** <https://community.zeek.org/t/no-subject/5748>\
**Category:** Zeek\
**Created:** [June 27, 2019, 5:00pm UTC](https://community.zeek.org/t/no-subject/5748 "2019-06-27T17:00:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Enki](https://avatars.discourse-cdn.com/v4/letter/e/b5ac83/32.png) [@Enki](https://community.zeek.org/u/Enki)\
**Post date:** [June 27, 2019, 5:00pm UTC](https://community.zeek.org/t/no-subject/5748/1 "2019-06-27T17:00:41Z")

</div>

I’m trying to create my first protocol analyzer with BinPac for the synchrophasor protocol (IEEE Std C37.118) – from what I can tell, nobody has made an analyzer for it yet. I’m trying to define the message format in synchrophasor-protocol.pac. However, stuff like the format of data packets are based on a previously sent configuration packet. How do I write synchrophasor-protocol.pac so I can parse them based on the previously sent packet? Here’s some documentation on the protocol if you need it: [http://smartgridcenter.tamu.edu/resume/pdf/1/SynPhasor\_std.pdf](http://smartgridcenter.tamu.edu/resume/pdf/1/SynPhasor_std.pdf)

Again, this is my first time trying to write a protocol analyzer with BinPac, so sorry if this is obvious.

Thank you

---

<div class="post-metadata">

**Author:** ![Hugo](https://avatars.discourse-cdn.com/v4/letter/h/b38774/32.png) [@Hugo](https://community.zeek.org/u/Hugo)\
**Post date:** [June 27, 2019, 8:08pm UTC](https://community.zeek.org/t/no-subject/5748/2 "2019-06-27T20:08:55Z")

</div>

Hi Enki,

I have not read C37.118 in details before. But I contributed the DNP3 analyzer in Bro both on top of TCP and UPD, may be you can take a look. DNP3 also have some similar characteristics, like the parsing of the current packets depends on the previous packet. Hope this helps.

Best,

Hui Lin

---

<div class="post-metadata">

**Author:** ![Enki](https://avatars.discourse-cdn.com/v4/letter/e/b5ac83/32.png) [@Enki](https://community.zeek.org/u/Enki)\
**Post date:** [July 1, 2019, 9:16pm UTC](https://community.zeek.org/t/no-subject/5748/3 "2019-07-01T21:16:17Z")

</div>

I took a look at the dp3 files, but I couldn’t find anything that helps with my use case - - maybe I’m just blind and I missed it. However, I did find this older question that fits pretty close to mine:  
[https://marc.info/?l=bro&m=146194027831545&w=2](https://marc.info/?l=bro&m=146194027831545&w=2)

I still feel like there’s probably a better way to solve this issue than what’s presented. I’ll try it out though, unless anyone knows of any better methods.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/no-subject/5748/4 "2022-05-06T15:46:36Z")

</div>


