# Zeek script to look for first few packets

**URL:** <https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687>\
**Category:** Zeek\
**Created:** [May 3, 2019, 4:38pm UTC](https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687 "2019-05-03T16:38:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manju\_Lalwani](https://avatars.discourse-cdn.com/v4/letter/m/f19dbf/32.png) [@Manju\_Lalwani](https://community.zeek.org/u/Manju_Lalwani)\
**Post date:** [May 3, 2019, 4:38pm UTC](https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687/1 "2019-05-03T16:38:09Z")

</div>

how can I make Zeek look for the first ten packets only in a tcp session ? The first ten packets are enough to fingerprint the traffic I am trying to identify and so would like to ensure my script looks at only the first 10 packets to save processing time.

Also the communication can be identified based on 7 packets immediately following the tcp handshake and using a custom service not categorised by zeek… tcp\_packet event has been the closest match for my script . Is there any Zeek event that can be a better match for this communication ?

Thanks in advance,  
Manju

---

<div class="post-metadata">

**Author:** ![Aashish\_Sharma1](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@Aashish\_Sharma1](https://community.zeek.org/u/Aashish_Sharma1)\
**Post date:** [May 3, 2019, 5:38pm UTC](https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687/2 "2019-05-03T17:38:52Z")

</div>

Manju,

zeek conceptually works better at connection and protocol events than at packet levels. Infact  
thats one of the strengths of it that it does all low level tcp and protocol  
understandings for you and hands you events which are at more easier levels to  
work with.

While you can work on packet, it is generally not recommended. More so if you  
desire to operate at packet levels to save processing time, on the contrary you  
are going on an non-optimal path.

You should consider event based approach. Your message doesn't quite explain  
what your specifics are that helps you identify when you are done but here are  
couple of examples which might help understand other approaches or way to think:

Problem: I'd like to only process if all three conditions are T

- IP is in local\_nets  
- dst port is acceptable port list &&  
- response IP is not in list of acceptable hosts

event new\_connection(c: connection)  
{

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local orig = c$id$orig\_h ;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local resp = c$id$resp\_h ;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;local dport = c$id$resp\_p ;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if (orig !in Site::local\_nets)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return ;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if (dport !in ok\_ports)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return ;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if (resp !in ok\_hosts )  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return ;

&nbsp;&nbsp;# do your processing

}

Similarly: lets say you want to only operate on Apache Server stuff:

event http\_header(c: connection, is\_orig: bool, name: string, value: string) &priority=5  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if (name != "SERVER")  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;return ;

&nbsp;&nbsp;&nbsp;&nbsp;if (/Apache/ in value)  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;# do your processing  
&nbsp;&nbsp;&nbsp;&nbsp;}

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

&nbsp;&nbsp;or alternatively:

&nbsp;&nbsp;if ( name == "SERVER" && /Apache/ in value)  
&nbsp;&nbsp;&nbsp;&nbsp;# do processing

The way is you eliminate all the un-interesting traffic you don't care about -  
this saves more processing than to go per packet level heuristics.

You should probably look at connection events:

[https://docs.zeek.org/en/stable/scripts/base/bif/plugins/Bro\_TCP.events.bif.bro.html](https://docs.zeek.org/en/stable/scripts/base/bif/plugins/Bro_TCP.events.bif.bro.html)

and definitely try avoiding working on packet events

Hope this helps,

Aashish

---

<div class="post-metadata">

**Author:** ![Jim\_Mellander](https://avatars.discourse-cdn.com/v4/letter/j/e47c2d/32.png) [@Jim\_Mellander](https://community.zeek.org/u/Jim_Mellander)\
**Post date:** [May 3, 2019, 5:57pm UTC](https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687/3 "2019-05-03T17:57:32Z")

</div>

If you’re working on a protocol currently unknown to zeek, you could try your hand at writing a protocol analyzer plugin. A recent thread on that subject: [http://mailman.icsi.berkeley.edu/pipermail/zeek-dev/2019-March/013196.html](http://mailman.icsi.berkeley.edu/pipermail/zeek-dev/2019-March/013196.html)

As an enhancement to zeek, it might be nice to trigger an event if the protocol analyzers were unable to identify the connection, with some representation of the traffic seen to allow script level analysis. Haven’t spent much time thinking about the syntax or efficiency of such an event, though, although it might be an interesting topic for conversation.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/zeek-script-to-look-for-first-few-packets/5687/4 "2022-05-06T15:46:29Z")

</div>


