# Writing a Protocol Analyzer Plugin

**URL:** <https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632>\
**Category:** Development\
**Tags:** development\
**Created:** [March 13, 2019, 3:16pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632 "2019-03-13T15:16:10Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 13, 2019, 3:16pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/1 "2019-03-13T15:16:10Z")

</div>

Hello Zeek Devs,

I would like to write a protocol analyzer and need some direction. I would like to write something simple which works on TCP, similar to the ConnSize analyzer. I would like my analyzer to be distributed as a plugin, similar to MITRE’s HTTP2 analyzer, so I am following the docs here:  
[https://docs.zeek.org/en/stable/devel/plugins.html](https://docs.zeek.org/en/stable/devel/plugins.html)

However, the docs don’t detail much beyond creating a built in function. A colleague pointed me at this quickstart script for binpac:  
[https://github.com/grigorescu/binpac\_quickstart](https://github.com/grigorescu/binpac_quickstart)

The quickstart script seems to be intended for writing a protocol analyzer which gets merged into the Zeek source. This is not how plugins operate.

I’m looking for some guidance on how to proceed. Thanks in advance.

-AK

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [March 13, 2019, 3:29pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/2 "2019-03-13T15:29:02Z")

</div>

See if this helps:  
[https://github.com/zeek/zeek/blob/master/testing/btest/plugins/protocol.bro](https://github.com/zeek/zeek/blob/master/testing/btest/plugins/protocol.bro)

That may be the most compact tutorial on writing a protocol analyzer  
plugin. 🙂

Robin

---

<div class="post-metadata">

**Author:** ![Vlad\_Grigorescu](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vlad\_Grigorescu](https://community.zeek.org/u/Vlad_Grigorescu)\
**Post date:** [March 13, 2019, 3:50pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/3 "2019-03-13T15:50:57Z")

</div>

Oops! Sorry about that. Try this one: [https://github.com/esnet/binpac\_quickstart](https://github.com/esnet/binpac_quickstart)

That has a ‘–plugin’ option. That will at least get the boilerplate stuff built, and then you can start digging into the protocol specifics.

–Vlad

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 13, 2019, 7:34pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/4 "2019-03-13T19:34:24Z")

</div>

Many thanks for the quick responses!

I am receiving these errors:

```auto
error in /usr/local/bro/share/bro/base/init-bare.bro, line 1: plugin
Demo::ConnTaste is not available
fatal error in /usr/local/bro/share/bro/base/init-bare.bro, line 1:
Failed to activate requested dynamic plugin(s).

```

After executing these commands:

```auto
git clone --recursive [https://github.com/zeek/zeek.git](https://github.com/zeek/zeek.git)
cd zeek
./configure
make
DIST=`pwd`

cd aux/bro-aux/plugin-support
./init-plugin -u ./conn-taste Demo ConnTaste
BRO_PLUGIN_PATH=`pwd`

cd ${DIST}
cd ../
git clone [https://github.com/esnet/binpac_quickstart.git](https://github.com/esnet/binpac_quickstart.git)
cd binpac_quickstart
pip install docopt jinja2
./start.py ConnTaste "Connection Byte Offset Tasting"
${BRO_PLUGIN_PATH}/conn-taste/ --tcp --buffered --plugin

cd ${BRO_PLUGIN_PATH}/conn-taste
./configure --bro-dist=${DIST}
make

cd ${DIST}
./configure
make
make install

bro -NN Demo::ConnTaste

```

I’m guessing there is some environment variable I am missing as I tried zeek/testing/btest/plugins/protocol.bro as Robin suggested and the @TEST-EXEC statements worked as expected.

-AK

---

<div class="post-metadata">

**Author:** ![Michael\_Dopheide](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Michael\_Dopheide](https://community.zeek.org/u/Michael_Dopheide)\
**Post date:** [March 13, 2019, 7:43pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/5 "2019-03-13T19:43:25Z")

</div>

I believe you want to change this line:

./start.py ConnTaste “Connection Byte Offset Tasting” …

to

./start.py Demo::ConnTaste “Connection Byte Offset Tasting” …

-Dop

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 13, 2019, 9:44pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/6 "2019-03-13T21:44:11Z")

</div>

I tried changing the name provided to the setup script as suggested. Doing so gives me many errors when I try to ./configure the plugin from within the conn-taste/ directory. CMake states that DEMO::CONNTASTE-events.bif is “reserved or not valid for for certain CMake features”. It complains about many of the file names.

Additionally, all the files in conn-taste/src/ look like DEMO::CONNTASTE.cc ☹

-AK

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 14, 2019, 12:16am UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/7 "2019-03-14T00:16:59Z")

</div>

I’m sure there is at least one other Carl Sagan fan on list. I feel like if I wish to make an analyzer from scratch, I must first invent the universe.

-AK

---

<div class="post-metadata">

**Author:** ![Michael\_Dopheide](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Michael\_Dopheide](https://community.zeek.org/u/Michael_Dopheide)\
**Post date:** [March 14, 2019, 2:25am UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/8 "2019-03-14T02:25:33Z")

</div>

Okay, with your original line for quickstart, this works rather than Demo::ConnTaste.

bash-3.2# /usr/local/bro/bin/bro -NN Bro::CONNTASTE  
Bro::CONNTASTE - This thing analyzer (dynamic, no version information)  
[Analyzer] CONNTASTE (ANALYZER\_CONNTASTE, enabled)  
[Event] conntaste\_event

So we’ve got some plugin naming issues to deal with, which I hope to work out tomorrow. It shouldn’t be about reinventing the universe, binpac is hard enough. 🙂

-Dop

---

<div class="post-metadata">

**Author:** ![Michael\_Dopheide](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Michael\_Dopheide](https://community.zeek.org/u/Michael_Dopheide)\
**Post date:** [March 14, 2019, 4:48pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/9 "2019-03-14T16:48:39Z")

</div>

Heh… this is what I get for not following up on a WIP merge… Try the topic/dopheide/namespace branch of [github.com/esnet/binpac\_quickstart](http://github.com/esnet/binpac_quickstart).

That should allow you to specify Demo::ConnTaste, but it will uppercase that to Demo::CONNTASTE, which I believe was an old convention.

-Dop

---

<div class="post-metadata">

**Author:** ![anthony\_kasza1](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@anthony\_kasza1](https://community.zeek.org/u/anthony_kasza1)\
**Post date:** [March 14, 2019, 7:04pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/10 "2019-03-14T19:04:46Z")

</div>

I’ll give that a whirl. Thanks again for the quick responses on this!

-AK

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/writing-a-protocol-analyzer-plugin/5632/11 "2022-05-06T15:46:22Z")

</div>


