# Protocols in protocols

**URL:** <https://community.zeek.org/t/protocols-in-protocols/3050>\
**Category:** Zeek\
**Created:** [March 26, 2014, 4:49pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050 "2014-03-26T16:49:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [March 26, 2014, 4:49pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050/1 "2014-03-26T16:49:27Z")

</div>

Hello,

I’m writing an analyzer for a few protocols which may or may not be layered. That is, a packet may be IP|TCP|ProtoA|ProtoB, or IP|TCP|ProtoC|ProtoB, or IP|TCP|ProtoB, and perhaps other variations. I envision writing separate protocol analyzers for each of those protocols instead of having to account for all the variations in one protocol analyzer. Does Bro/binPAC allow for this, and if so how? If it makes a difference, in this case most of the protocols cannot have useful DPD signatures.

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [March 26, 2014, 6:34pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050/2 "2014-03-26T18:34:34Z")

</div>

For protocols that sit inside a transport protocol (TCP/UDP), it’s typical to write a DPD signature and/or have a script that calls [1] to have Bro automatically instantiate and manage an analyzer for the inner protocol (e.g. Proto{A,B,C}). If those may encapsulate a known application-layer protocol, then it may just be a matter of putting code inside those outer analyzers to do their own instantiation/management of some inner analyzer (e.g. ProtoB) and feed it the appropriate data. But if the inner protocol can be another IPv4/IPv6 packet or an arbitrary application-layer protocol, it needs a different treatment. I can elaborate if that's the situation.

- Jon

[1] [http://bro.org/sphinx/scripts/base/frameworks/analyzer/main.html#id-Analyzer::register\_for\_ports](http://bro.org/sphinx/scripts/base/frameworks/analyzer/main.html#id-Analyzer::register_for_ports)

---

<div class="post-metadata">

**Author:** ![Eric\_Thomas](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@Eric\_Thomas](https://community.zeek.org/u/Eric_Thomas)\
**Post date:** [March 26, 2014, 6:45pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050/3 "2014-03-26T18:45:23Z")

</div>

Okay let me use a specific case that exemplifies what I¹m hoping to do.  
Take a DCERPC packet that is transported over directed hosted SMB2 over  
TCP/IP. The packet headers look like this: Ethernet|IP|TCP|NetBIOS  
stub\>SMB2|DCERPC.

Taking what you said, I would instantiate the SMB2 analyzer when  
processing the NetBIOS stub, and I would instantiate the DCERPC analyzer  
when processing SMB2. I¹m willing to do that. So how does one  
instantiate/feed data to the inner protocol?

---

<div class="post-metadata">

**Author:** ![Siwek\_Jon](https://avatars.discourse-cdn.com/v4/letter/s/90db22/32.png) [@Siwek\_Jon](https://community.zeek.org/u/Siwek_Jon)\
**Post date:** [March 26, 2014, 9:05pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050/4 "2014-03-26T21:05:00Z")

</div>

There’s not necessarily a particular way it has to be done. If the inner protocols are implementing the Analyzer interface, it might be as simple as “smb2 = new SMB2\_Analyzer(Conn()); smb2-\>DeliverStream(data\_len, data, is\_orig);”. But depending on protocol complexities, there might be a lot more code involved in how you choose to glue/chain analyzers together.

There is some NetBIOS/SMB/DCERPC code sitting around in Bro that might still be useful to you for getting ideas of how analyzer/parsers can interact w/ one another. Another example is the FTP analyzer, which also does some simple SSL processing of ADAT commands and ties the FTP and SSL analyzers together through just the interface of the Analyzer base class and an additional SupportAnalyzer.

- Jon

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/protocols-in-protocols/3050/5 "2022-05-06T15:41:40Z")

</div>


