# RE : Re:  Emerging Threats signatures on Bro ids ?

**URL:** <https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401>\
**Category:** Zeek\
**Created:** [August 13, 2012, 4:38pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401 "2012-08-13T16:38:22Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmkml2](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@rmkml2](https://community.zeek.org/u/rmkml2)\
**Post date:** [August 13, 2012, 4:38pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/1 "2012-08-13T16:38:22Z")

</div>

Hi Seth,  
I don’t have quick internet access, only a \*dsl access.  
This is why I need feedback please.  
Anyone tested please?  
What’s performance impact? (only 33sigs)  
Regards  
Rmkml

Seth Hall

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 13, 2012, 5:00pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/2 "2012-08-13T17:00:05Z")

</div>

There are a number of potential and definite problems.

- For each http\_request event, you are doing a lot of if & if else statements which \*could\* impact performance.

- For each http header you are similarly doing a lot of if statements which will almost certainly cause a performance impact. Also, you are accessing collected state in the c$http record when you should probably be using the name and value variables directly. If you want to look through data before things are logged, your best bet is to use the HTTP::log\_http logging framework event.

- Again, lots of if statements for every dns request is probably going to have a severe performance impact.

- For every single chunk of http entity data, you are running lots of if statements with pattern conditions again.  
  
- Handling the packet\_contents event at all is generally really bad. The auto-generated documentation even comments on the fact that using that event is not really feasible for any traffic volume:  
&nbsp;&nbsp;[http://www.bro-ids.org/documentation/scripts/base/event.bif.html?highlight=packet\_contents#id-packet\_contents](http://www.bro-ids.org/documentation/scripts/base/event.bif.html?highlight=packet_contents#id-packet_contents)

This is one of the interesting things about Bro. Due to it primarily being a programming language, you can absolutely do things that will negatively impact performance and break other analysis. So like any other language you have to constantly be aware of what you are doing and the potential impacts. We are actively working now to make it possible for you and others to do these detections more easily and with less potential performance impact. Unfortunately we're still at the very beginning of a newly-found operational security engineering focus so this stuff is taking a bit longer than most people would like (me included!).

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 13, 2012, 5:02pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/3 "2012-08-13T17:02:40Z")

</div>

Oh! I forgot to include an alternate approach I thought of. If you are still interested in going down this route, could you start by pulling out malicious software user-agents from the ET signatures? That's something that would fit well and easily into Bro right now and into the intelligence framework in the future.

What do you think about that? We can certainly start small with very well defined goals and move from there.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Clark\_Gilbert](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@Clark\_Gilbert](https://community.zeek.org/u/Clark_Gilbert)\
**Post date:** [August 13, 2012, 6:26pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/4 "2012-08-13T18:26:10Z")

</div>

Hi:

You might try obtaining a few rather large traces and running bro against those traces with '-r'. Record how long it takes to process these traces both without the changes you've made and with the changes you've made. The difference in these two times might give you a rough idea of how your modifications impact bro's performance (given observed traffic similar to that of the analyzed trace).

--Gilbert

---

<div class="post-metadata">

**Author:** ![rmkml2](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@rmkml2](https://community.zeek.org/u/rmkml2)\
**Post date:** [August 13, 2012, 9:29pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/5 "2012-08-13T21:29:32Z")

</div>

Thx you for reply Seth,

ok I have started very small bench on my local network: (wget, one cnx)

-without et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 40%-45%

-all sigs et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

-disabled only "packet\_contents" on et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

-disabled only "entity\_data" on et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

-disabled only "dns\_request" on et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

-disabled only "http\_header" on et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

-disabled only "http\_request" on et\_bro2\_11aug, download http at --limit-rate=85m, bro cpu around (top) 75%-90%

well, no special sig penalty.

I have discovered one pb on my case: in ids mode, bro not fire immediatly, after 5mn not fire, fire only when I kill bro, it's possible to fire immediatly on my rule set please?

Best Regards  
Rmkml

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 13, 2012, 7:36pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/6 "2012-08-13T19:36:15Z")

</div>

You need to do this with a decent sized tracefile (\>1GB) of mixed traffic and run Bro with the "time" command to see how long it takes for it to analyze the full file. I suspect the performance degradation will become much more obvious there.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![rmkml2](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@rmkml2](https://community.zeek.org/u/rmkml2)\
**Post date:** [August 13, 2012, 9:33pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/7 "2012-08-13T21:33:03Z")

</div>

ok Im look on user-agent ET sigs.  
Regards  
Rmkml

---

<div class="post-metadata">

**Author:** ![rmkml2](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@rmkml2](https://community.zeek.org/u/rmkml2)\
**Post date:** [August 14, 2012, 12:13am UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/8 "2012-08-14T00:13:38Z")

</div>

starting hard works...

question please: it's possible to detect POST and uri (/abc) and argument (arg=test) ?  
example:  
&nbsp;&nbsp;POST /abc HTTP/1.0  
&nbsp;&nbsp;...  
&nbsp;&nbsp;\r\n  
&nbsp;&nbsp;arg=test

not work but like:  
("POST"==c$http$method)&&(/\/abc/ in c$http$uri)&&(/arg\=test/ in c$http$body???)

Regards  
Rmkml

---

<div class="post-metadata">

**Author:** ![rmkml2](https://avatars.discourse-cdn.com/v4/letter/r/b487fb/32.png) [@rmkml2](https://community.zeek.org/u/rmkml2)\
**Post date:** [August 15, 2012, 12:16am UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/9 "2012-08-15T00:16:06Z")

</div>

Hi,  
ok I have advance my performance penalty, simply disable "packet\_contents" and "entity\_data", results my performance go to 40%-45%...  
(download one file size 1.9Go with wget multiple times)  
good news.

Anyone tested partial ET open-gpl on live trafic please ?  
Regards  
Rmkml

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/re-re-emerging-threats-signatures-on-bro-ids/2401/10 "2022-05-06T15:40:30Z")

</div>


