# RE : bro signature http-request double encoded cause FN ?

**URL:** <https://community.zeek.org/t/re-bro-signature-http-request-double-encoded-cause-fn/2410>\
**Category:** Zeek\
**Created:** [August 20, 2012, 3:16pm UTC](https://community.zeek.org/t/re-bro-signature-http-request-double-encoded-cause-fn/2410 "2012-08-20T15:16:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu2](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@Vlad\_Grigorescu2](https://community.zeek.org/u/Vlad_Grigorescu2)\
**Post date:** [August 20, 2012, 3:16pm UTC](https://community.zeek.org/t/re-bro-signature-http-request-double-encoded-cause-fn/2410/1 "2012-08-20T15:16:24Z")

</div>

Hi rmkml,

First off, let me just thank you for all the work you've been doing recently. I think a lot of people are interested in integrating additional intelligence sources (like Emerging Threats) into Bro.

However, I'm concerned that a lot of your work seems to be based on just passing content through a bunch of regular expressions. A few others have also expressed concern with this approach. As a result, I think most people here are wary to try your scripts on their clusters. Even a 10% slowdown translates to one or two extra 16-core machines that would need to be added to the cluster in some places. Apart from that, at least to me, this approach goes against a lot of the Bro philosophy. If people just wanted basic signature-matching, they'd use one of the many much more simplistic tools out there. With Bro, this is really viewed as intelligence instead of an amalgamation of signatures.

Personally, I think you'd get much more interest if you could just create a text-file with known bad user-agents from the Emerging Threats sigs. I think that's a good place to start, and once that's in place, we can help you figure out the best way to extend that to domain names, URIs, filenames, etc.

Just my 2 cents on why all the time you've been investing into this isn't getting the interest and response one would expect.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/re-bro-signature-http-request-double-encoded-cause-fn/2410/2 "2022-05-06T15:40:31Z")

</div>


