# wrong size computation

**URL:** <https://community.zeek.org/t/wrong-size-computation/900>\
**Category:** Zeek\
**Created:** [November 28, 2005, 6:34pm UTC](https://community.zeek.org/t/wrong-size-computation/900 "2005-11-28T18:34:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vincenzo\_Falletta](https://avatars.discourse-cdn.com/v4/letter/v/ea666f/32.png) [@Vincenzo\_Falletta](https://community.zeek.org/u/Vincenzo_Falletta)\
**Post date:** [November 28, 2005, 6:34pm UTC](https://community.zeek.org/t/wrong-size-computation/900/1 "2005-11-28T18:34:54Z")

</div>

Hi folks,  
As regards the way bro deals with the number of bytes transferred for  
each connection, it seems that bro DOES NOT keep a variable in which  
incrementally stores the sum of each packet size for all the packets  
involved in that very connection, but instead does a certain computation  
(i wonder how...) involving only the first and the last packet in the  
connection... Am I correct?  
I'm asking this question because I've found something very strange.  
In bro's conn.log file there are lines like this:

Dec 1 00:22:53 1.058870 A B http 49331 80 tcp 886477697 ? RSTOS0 L

(yes it's correct, 800MB in 1 second) but if I look at the trace, this  
is what I see:

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;A B  
&nbsp;&nbsp;&nbsp;49331 --\> 80 (SYN) Seq=0,Ack=0  
&nbsp;&nbsp;&nbsp;49331 \<-- 80 (ACK) Seq=0,Ack=0  
&nbsp;&nbsp;&nbsp;49331 --\> 80 (RST) Seq=0,Ack=188164531

(Only 3 packets transferred...)

Of course there's some bug in these hosts, but bro should not be  
misleaded in computing the amount of bytes transferred inside a  
connection. Could someone explain me what's happening here?

Best regards,

&nbsp;&nbsp;Vincenzo

---

<div class="post-metadata">

**Author:** ![Ruoming\_Pang](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@Ruoming\_Pang](https://community.zeek.org/u/Ruoming_Pang)\
**Post date:** [November 28, 2005, 8:11pm UTC](https://community.zeek.org/t/wrong-size-computation/900/2 "2005-11-28T20:11:54Z")

</div>

> As regards the way bro deals with the number of bytes transferred for  
> each connection, it seems that bro DOES NOT keep a variable in which  
> incrementally stores the sum of each packet size for all the packets  
> involved in that very connection, but instead does a certain computation  
> (i wonder how...) involving only the first and the last packet in the  
> connection... Am I correct?

Yes, for TCP connections Bro computes connection sizes based on TCP sequence numbers.

> I'm asking this question because I've found something very strange.  
> In bro's conn.log file there are lines like this:
> 
> Dec 1 00:22:53 1.058870 A B http 49331 80 tcp 886477697 ? RSTOS0 L
> 
> (yes it's correct, 800MB in 1 second) but if I look at the trace, this  
> is what I see:
> 
> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;A B  
> &nbsp;&nbsp;&nbsp;49331 --\> 80 (SYN) Seq=0,Ack=0  
> &nbsp;&nbsp;&nbsp;49331 \<-- 80 (ACK) Seq=0,Ack=0  
> &nbsp;&nbsp;&nbsp;49331 --\> 80 (RST) Seq=0,Ack=188164531
> 
> (Only 3 packets transferred...)
> 
> Of course there's some bug in these hosts, but bro should not be  
> misleaded in computing the amount of bytes transferred inside a  
> connection. Could someone explain me what's happening here?

This is weird. Could you please send me the trace file?

I think there are two separate issues here:

1. How Bro comes up with the 800MB number and whether the ack sequence in the RST packet should be taken into computation. We need to look at the trace to find out.

2. In general, Bro connection sizes can be incorrect in weird cases, and if you want accurate numbers in your measurements, my suggestions (and what we did in our measurements) are: (a) if you have all packets in your traces, there's a Bro script (Vern?) to sample packets very efficiently to estimate connection size, even in the case the sequence numbers wrap around a number of times, which then can be used to validate the connection size; (b) if all you have are SYN, FIN, and RST packets, you can make some assumption about the bandwidth of the link to check if the connection size makes sense.

Ruoming

---

<div class="post-metadata">

**Author:** ![Vincenzo\_Falletta](https://avatars.discourse-cdn.com/v4/letter/v/ea666f/32.png) [@Vincenzo\_Falletta](https://community.zeek.org/u/Vincenzo_Falletta)\
**Post date:** [December 7, 2005, 5:38pm UTC](https://community.zeek.org/t/wrong-size-computation/900/3 "2005-12-07T17:38:31Z")

</div>

Here it is a sample... it is just an handshake but if you run

$bro -r to-brolist\_anonym.pcap brolite

you will see in the conn.log file the BIG computation mistake...

Cheers,  
&nbsp;&nbsp;Vincenzo 🙂

Ruoming Pang (庞若鸣) wrote:

[to-brolist\_anonym.pcap](https://community.zeek.org/uploads/short-url/8MFQDc24oDfYbanA9AxrJGPZD3O.pcap) (212 Bytes)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/wrong-size-computation/900/4 "2022-05-06T15:37:45Z")

</div>


