# Traffic analysis by Bro

**URL:** <https://community.zeek.org/t/traffic-analysis-by-bro/1054>\
**Category:** Zeek\
**Created:** [November 9, 2006, 6:32pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054 "2006-11-09T18:32:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abhinay\_Kampasi](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@Abhinay\_Kampasi](https://community.zeek.org/u/Abhinay_Kampasi)\
**Post date:** [November 9, 2006, 6:32pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/1 "2006-11-09T18:32:31Z")

</div>

Hi,

What traffic does Bro monitor by default (i.e. what pcap capture filter does it use)?

Suppose one of the policy scripts redefines the capture filter to monitor SSH traffic as follows:

"redef capture\_filters += { ["xxxx"] = "tcp port 22" };"

Does this modify the global filter? I mean do all the policy scripts (and not only my script) see the SSH traffic?

Thanks,  
Abhinay

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [November 10, 2006, 5:10pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/2 "2006-11-10T17:10:41Z")

</div>

> What traffic does Bro monitor by default (i.e. what pcap capture filter  
> does it use)?

It builds the pcap filter dynamically at startup depending on which  
scripts you load. Just load the script print-filter to see how it  
looks like in your particular setup.

> Does this modify the global filter? I mean do all the policy scripts  
> (and not only my script) see the SSH traffic?

Yes. Yes. There's always only one pcap filter in use.

Robin

---

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [November 10, 2006, 5:16pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/3 "2006-11-10T17:16:03Z")

</div>

> There's always only one pcap filter in use.

(Nit: there can be two, if you use Bro's "secondary filter" capability,  
which is designed to provide a lightweight, additional packet stream to  
supplement the main analysis.)

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![Abhinay\_Kampasi](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@Abhinay\_Kampasi](https://community.zeek.org/u/Abhinay_Kampasi)\
**Post date:** [November 10, 2006, 6:47pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/4 "2006-11-10T18:47:02Z")

</div>

Thanks Robin,

So suppose my script wants to analyze only interactive traffic (for example  
telnet, ssh), it will be have to explicitly ignore all packets not on ports  
22/23 because the capture filter may have been modified by other scripts to  
capture other traffic.

Regards,  
Abhinay

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [November 11, 2006, 6:09pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/5 "2006-11-11T18:09:16Z")

</div>

Hmm... Yes and no. Yes because in terms of filtering Bro does not  
keep track not which traffic is requested which script. But no  
because you script will contain event handlers to implement your  
detection logic. Many (though not all) events are thrown by  
application-specific analyzers which only analyze "their" traffic.  
E.g., the HTTP analyzer looks only at HTTP connections and thus  
you're only going to see HTTP events for traffic on port 80 (or  
whichever port it happens to use).

So, the bottom-line is that it depends on which events you're going  
to analyze. Depending on that, you may or may not need to filter out  
events which are irrlevant for you.

Robin

---

<div class="post-metadata">

**Author:** ![Abhinay\_Kampasi](https://avatars.discourse-cdn.com/v4/letter/a/7993a0/32.png) [@Abhinay\_Kampasi](https://community.zeek.org/u/Abhinay_Kampasi)\
**Post date:** [November 11, 2006, 6:15pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/6 "2006-11-11T18:15:36Z")

</div>

Thanks Robin,

Right now my script has the tcp\_packet(...) event handler. I am assuming  
that this event handler will be invoked for all TCP packets. Is that right?

Regards,  
Abhinay

---

<div class="post-metadata">

**Author:** ![Christian\_Kreibich3](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Christian\_Kreibich3](https://community.zeek.org/u/Christian_Kreibich3)\
**Post date:** [November 11, 2006, 8:20pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/7 "2006-11-11T20:20:18Z")

</div>

Abhinay, you don't need to worry about this: the semantic level at which  
you're writing your script is far beyond the pcap filter specification.

Typically you will write your script based on event types that are  
relevant to the traffic you are interested. For example, in the case of  
an SSH policy script, you might implement handlers for the  
ssh\_client\_version() and ssh\_server\_version() events, which only ever  
get triggered for SSH traffic (potentially in a port-independent fashion  
thanks to the new dynamic protocol detection framework).

Think of it this way: you configure Bro using a number of policy  
scripts. These scripts together (and through other scripts they @load)  
make sure that Bro captures all traffic and only the traffic necessary  
to trigger the events you are interested in. At the same time, no events  
can ever be triggered (with some caveats) on traffic they are not meant  
for.

Cheers,  
Christian.

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [November 13, 2006, 12:32am UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/8 "2006-11-13T00:32:32Z")

</div>

Yes, that's right.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:38pm UTC](https://community.zeek.org/t/traffic-analysis-by-bro/1054/9 "2022-05-06T15:38:02Z")

</div>


