next up previous contents
Next: About this document ... Up: The Bro 0.8 User Previous: Bibliography   Contents


Index

! operator
Expressions
!in operator
Expressions | Expressions
$ record constructor operator
Expressions | Expressions
$ record field access operator
Accessing Fields Using ``$''
( operator
Expressions
) operator
Expressions
+ operator
Expressions
++ operator
Expressions
+ addition operator
Arithmetic Operators | Temporal Addition | Expressions
+ unary operator
Arithmetic Operators
- subtraction operator
Arithmetic Operators | Temporal Subtraction | Expressions
- unary operator
Arithmetic Operators | Temporal Negation
* multiplication operator
Arithmetic Operators | Temporal Multiplication | Expressions
/ division operator
Arithmetic Operators | Temporal Division | Expressions
+= operator
Filtering
- operator
Expressions
- operator
Expressions
4Dgifts username
The hot-ids Module
: operator
Expressions
"|"| short-circuit ``or''
Logical Operators | Expressions
&& short-circuit ``and''
Logical Operators | Expressions
! ``not'' operator
Logical Operators
<
Arithmetic Operators
T
Boolean Constants
F
Boolean Constants
%modulus operator
Expressions
% format
Predefined Functions
= operator
Expressions
== equality operator
Comparison Operators | Exact Pattern Matching | Expressions | Expressions
"!$\tilde{~}~~$ exact match negation
Exact Pattern Matching
$~\tilde{~}~~~$  exact pattern match operator
Exact Pattern Matching
"!= inequality operator
Comparison Operators | Exact Pattern Matching | Expressions | Expressions
< less-than operator
Comparison Operators | Expressions
<= less-or-equal operator
Comparison Operators | Expressions
> greater-than operator
Comparison Operators | Expressions
>= greater-or-equal operator
Comparison Operators | Expressions
? operator
Expressions
?$ record field test
Expressions
[ operator
Expressions | Expressions
] operator
Expressions | Expressions
aborted execution
Flags
absolute time
Temporal Types
access
allowable /16 network pairs
hot variables
allowable address pairs
hot variables
allowable services
hot variables
fatal inbound services
hot variables
forbidden attempted services
hot variables
forbidden inbound services
hot variables
forbidden services
hot variables
sensitive /24 destination networks
hot variables
sensitive /24 source networks
hot variables
sensitive destination addresses
hot variables
sensitive source addresses
hot variables
service allowed to a particular host
hot variables
service allowed to particular host pairs
hot variables
account_tried event
scan event handlers
accounts_tried variable
scan.bro
ack above a hole (possible packet drop message)
Additional handlers for ``weird''
ack_above_hole event
General Processing Events | Additional handlers for ``weird''
acknowledgment holes
Additional handlers for ``weird''
actions
The signature Module | The signature Module | The signature Module | The signature Module | Actions for ``weird'' events | Actions for ``weird'' events | Actions for ``weird'' events | Actions for ``weird'' events | Actions for ``weird'' events | Actions for ``weird'' events | Actions for ``weird'' events
SIG_FILE
The signature Module
SIG_IGNORE
The signature Module
SIG_LOG
The signature Module
SIG_QUIET
The signature Module
WEIRD_FILE
Actions for ``weird'' events
WEIRD_IGNORE
Actions for ``weird'' events
WEIRD_LOG_ALWAYS
Actions for ``weird'' events
WEIRD_LOG_ONCE
Actions for ``weird'' events
WEIRD_LOG_PER_CONN
Actions for ``weird'' events
WEIRD_LOG_PER_ORIG
Actions for ``weird'' events
WEIRD_UNSPECIFIED
Actions for ``weird'' events
activating_encryption event
login event handlers
active module
The active Module
active_conn variable
active.bro | The active Module
active_connection function
Predefined Functions
active_connection_reuse (``weird'' event)
Events handled by conn_weird
active_file function
Predefined Functions
actually_rejected_PTR_anno variable
dns.bro
add keyword
Statements
add statement
Statements
&add_func attribute
Refinement
add_interface function
Predefined Functions
add_tcpdump_filter function
Predefined Functions
addition
numeric
Arithmetic Operators
temporal
Temporal Addition
additional information associated with a connection
The connection record | Connection summaries
addl
The connection record
connection field
The connection record
addl_web variable
scan.bro | scan variables
addr
see types, addr
address masking
Net Type | Predefined Functions | Predefined Functions
address scanning
The scan Analyzer
address type
Address Type to Address Operators
constants
Address Constants
operators
Address Operators
addresses
hot destinations
hot variables
hot sources
hot variables
in a connection
Connection summaries
local
Site variables | Site variables | Site variables | Site-specific functions
mapping to hostnames
The hf utility
neighbor
Site variables | Site variables | Site variables
addrs
The dns_mapping record
dns_mapping field
The dns_mapping record
\a alert escape
String Constants
alert_action_filters variable
alert.bro
alert_file variable
alert.bro
allow_16_net_pairs variable
hot.bro | hot variables
allow_excessive_ntp_requests variable
ntp.bro
allow_pairs variable
hot.bro | hot variables
allow_PTR_scans variable
dns.bro
allow_service_pairs variable
hot.bro
allow_services variable
hot.bro | hot variables
allow_services_pairs variable
hot variables
allow_services_to variable
hot.bro | hot variables
allow_spoof_services variable
hot.bro | hot variables
allowable /16 network pairs
hot variables
allowable address pairs
hot variables
altering log files
login variables
always_hot_ids variable
hot-ids.bro | The hot-ids Module
always_hot_login_ids variable
login.bro | login variables
analy analyzer
The analy Analyzer
analysis
bidirectional vs. unidirectional
Events handled by conn_weird
off-line
Traffic traces | Flags | Predefined Functions | Connection functions
on-line
Live traffic | Flags | Uncategorized | Predefined Functions | Connection functions
analyzers
Analyzers and Events to The interconn Analyzer
load
Loading Analyzers
print-filter
Filtering | Filtering
print-filter
Filtering
conn
Generic Connection Analysis
tcp
no title
udp
no title
site
Site-specific information
hot
The hot Analyzer
scan
The scan Analyzer
finger
The finger Analyzer
ftp
The ftp Analyzer
http
The http Analyzer
ident
The ident Analyzer
login
The login Analyzer
portmapper
The portmapper Analyzer
analy
The analy Analyzer
signature
The signature Module
SSL
The SSL Analyzer
activating
Activating an Analyzer
application-specific
The finger Analyzer to portmapper event handlers
filtering
Filtering to Filtering
finger
event handlers
finger event handlers to finger event handlers
variables
finger variables to finger variables
ftp
event handlers
ftp event handlers to ftp event handlers
functions
ftp functions to ftp functions
variables
ftp variables to ftp variables
generic
Generic Connection Analysis to Connection functions
hot
functions
hot functions to hot functions
variables
hot variables to hot variables
http
event handlers
http event handlers to http event handlers
variables
http variables to http variables
ident
event handlers
ident event handlers to ident event handlers
variables
ident variables to ident variables
instantiating
Activating an Analyzer
loading
Loading Analyzers
login
event handlers
login event handlers to login event handlers
functions
login functions to login functions
variables
login variables to login variables
portmapper
event handlers
portmapper event handlers to portmapper event handlers
functions
portmapper functions to portmapper functions
variables
portmapper variables to portmapper variables
scan
event handlers
scan event handlers to scan event handlers
functions
scan functions to scan functions
variables
scan variables to scan variables
site-specific information
Site-specific information to Site-specific functions
SSL
event handlers
SSL event handlers to SSL event handlers
variables
SSL variables to SSL variables
&& ``and'' operator
Logical Operators | Expressions
anon_log variable
anon.bro
anonymize_ip_addr variable
bro.init
anonymous function expression
Expressions
anticode.com
login variables
``any'' type
The any type to The any type
replacing with union type
Predefined Functions
any_RPC_okay variable
portmapper.bro | portmapper variables
appending to a file
Predefined Functions
arithmetic expression
Expressions
array
associative
Tables
multi-dimensional
Declaring Tables
as
Files
RLIMIT_NOFILE
Files
ASCII
as usual character set
String Operators
assigning records
Record Assignment to Record Assignment
assignment expression
Expressions
associative array
Tables
attack
Land
hot functions
attackers
weenie
The hot-ids Module
attacks
smurf
login variables
ATTEMPT_INTERVAL internal variable
Generic TCP connection events
attempted connections
Generic TCP connection events
attempted services
forbidden
hot variables
attributes
Attributes
&add_func
Refinement
&create_expire
Table Attributes
&default
Table Attributes
&delete_func
Refinement
&expire_func
Table Attributes
&read_expire
Table Attributes
record fields
Record Assignment
&redef
Refinement
&write_expire
Table Attributes
auth error (RPC status code)
portmapper functions
auth-failed/ authentication annotation
login event handlers
auth/ authentication annotation
login event handlers
authentication
accepted
login event handlers
rejected
login event handlers
skipped
login event handlers
authentication annotations
ident event handlers | login event handlers | login event handlers | login event handlers | login event handlers | login event handlers
auth-failed/
login event handlers
auth/
login event handlers
confused/
login event handlers | login event handlers
ident/
ident event handlers
(skipped)
login event handlers
authentication dialog
Predefined Functions | Predefined Functions | The login Analyzer | login analyzer confusion
evasion
login analyzer confusion
authentication_accepted event
login event handlers
authentication_rejected event
login event handlers
authentication_skipped event
login event handlers
avoiding processing
Predefined Functions
backdoor
avoiding false positives
login variables
prompts
login variables
triggered by ephemeral port
login variables
triggered by terminal type
login variables
backdoor_annotate_standard_ports variable
backdoor.bro
backdoor_demux_disabled variable
backdoor.bro
backdoor_demux_skip_tags variable
backdoor.bro
backdoor_ignore_dst_addrs variable
backdoor.bro
backdoor_ignore_ports variable
backdoor.bro
backdoor_ignore_src_addrs variable
backdoor.bro
backdoor_log variable
backdoor.bro
backdoor_min_7bit_ascii_ratio variable
backdoor.bro
backdoor_min_bytes variable
backdoor.bro
backdoor_min_normal_line_ratio variable
backdoor.bro
backdoor_min_num_lines variable
backdoor.bro
backdoor_prompts variable
login.bro | login variables
backdoor_standard_ports variable
backdoor.bro
backdoor_stat_backoff variable
backdoor.bro
backdoor_stat_period variable
backdoor.bro
backscatter_ports variable
scan.bro
backspace character
Predefined Functions
\b backspace escape
String Constants
bad address mask
run-time error
Predefined Functions
bad fmt date argument
run-time error
Predefined Functions
bad fmt editing character
run-time error
Predefined Functions
bad fmt field width
run-time error
Predefined Functions
bad fmt floating-point argument
run-time error
Predefined Functions
bad fmt format specifier
run-time error
Predefined Functions
bad fmt integer argument
run-time error
Predefined Functions
bad fmt precision
run-time error
Predefined Functions
bad format
Predefined Functions
bad length argument (not a table or set)
run-time error
Predefined Functions
bad second argument to mask_addr()
Predefined Functions
bad time
bad time
format conversion error
Predefined Functions
bad type for Date format
Predefined Functions
bad type for floating-point format
Predefined Functions
bad type for integer format
Predefined Functions
bad_HTTP_reply (``weird'' event)
Events handled by conn_weird
bad_HTTP_version (``weird'' event)
Events handled by conn_weird
bad_ICMP_checksum (``weird'' event)
Events handled by conn_weird
bad_ident_reply (``weird'' event)
Events handled by conn_weird_addl
bad_ident_request (``weird'' event)
Events handled by conn_weird_addl
bad_IP_checksum (``weird'' event)
Events handled by net_weird
bad_option event
login event handlers
bad_option_termination event
login event handlers
bad_pm_port (``weird'' event)
Events generated by the
bad_rlogin_prolog (``weird'' event)
Events handled by conn_weird
bad_RPC (``weird'' event)
Events handled by conn_weird
bad_RPC_program (``weird'' event)
Events handled by conn_weird
bad_SYN_ack (``weird'' event)
Events handled by conn_weird
bad_TCP_checksum (``weird'' event)
Events handled by conn_weird
bad_TCP_header_len (``weird'' event)
Events handled by net_weird
bad_UDP_checksum (``weird'' event)
Events handled by conn_weird
baroque_SYN (``weird'' event)
Events handled by conn_weird
beginning time of a connection
The connection record | Connection summaries
\a bell escape
String Constants
bidirectional vs. unidirectional analysis
Events handled by conn_weird
big endian
Predefined Functions | The analy Analyzer
/bin/eject exploit
login variables
BIND
non-blocking DNS lookups
The Bro source code
blank_in_HTTP_request (``weird'' event)
Events handled by conn_weird
bool
see types, bool
booleans
Booleans to Logical Operators
Bourne shell
Predefined Functions
BPF (Berkeley Packet Filter)
tuning
Tuning BPF
BPF buffers
ensuring they are large
Tuning BPF
break keyword
Statements
break statement
Statements
Bro
checkpointing
Flags
execution aborted
Flags
flags
-f
Flags
-h
Flags
-i
Flags
-p
Flags
-r
Flags
-s
Flags
-w
Flags
-v
Flags
-F
Flags
-O
Flags
-P
Flags
-W
Flags
-P
The dns Module
installing
Building and installing Bro
interactive use
Using Bro interactively
not running as root
Tuning BPF
optimizer
Flags
private caches
Flags | Flags
references
Introduction
running
Running Bro
search path
Run-time environment
shadow
Filtering
source code
The Bro source code
system configuration
Tuning BPF
usage
Flags
version
Flags
watchdog
Flags
web page
The Bro source code
wedging
Flags
Bro bugs/limitations
causing ``weird'' events
The weird Module
.bro suffix
Run-time environment
.bro-dns-cache
The dns Module
bro_done event
General Processing Events
$BRO_ID environment variable
The log Module
bro_init event
Filtering | Filtering | General Processing Events
bro_log_file variable
Uncategorized | The log Module
$BRO_PREFIXES environment variable
Flags | Run-time environment
bro_signal event
General Processing Events
$BROPATH environment variable
Run-time environment
BS
Predefined Functions
buffer overflow tools
login variables
buffer size patch for libpcap
Tuning BPF
buffers
large for BPF
Tuning BPF
buggy implementations
causing ``weird'' events
The weird Module
bugs
$ pattern operator not supported
Embedded Pattern Matching
appalling
Additional handlers for ``weird'' | Additional handlers for ``weird''
causing ``weird'' events
The weird Module
tcpdump
Filtering
building Bro
Building and installing Bro
byte_len function
Predefined Functions
bytes in connection
Connection summaries | Connection functions
caches
Bro's private ones
Flags
CALLIT portmapper call
The portmapper Analyzer
can't open
run-time error
Run-time environment
can_drop_connectivity variable
scan variables
cannot create directory
Predefined Functions
capture_filter global variable
Flags
capture_filter variable
Uncategorized | Filtering to Filtering
\r carriage return escape
String Constants
casting
not provided in Bro
The any type
cat function
Predefined Functions
Central Intelligence Agency
detection
hot variables
cf utility program
no title
character set
ASCII
String Operators
check_hot function
hot functions
check_info record
login functions | login functions | login functions | login functions | login functions
forbidden
login functions
hot
login functions
hot_id
login functions
check_relay_3 variable
mime.bro
check_relay_4 variable
mime.bro
check_scan function
scan functions
check_spoof function
hot functions
checkpointing Bro
Flags
checksum error
ICMP
Events handled by conn_weird
IP
Events handled by net_weird
TCP
Events handled by conn_weird
UDP
Events handled by conn_weird
Christmas packet
Events handled by conn_weird
CIA detection
hot variables
CIDR
Net Type | Predefined Functions | Predefined Functions | Site variables
clean function
Predefined Functions
cleanup event
General Processing Events
client port
triggering a backdoor
login variables
client_cert
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
clock time
Predefined Functions | Predefined Functions
close function
Predefined Functions
code_red_list1 variable
code-red.bro
code_red_list2 variable
code-red.bro
code_red_log variable
code-red.bro
Cold Fusion exploits
http variables
command shell
Predefined Functions
setuid root
login variables
compiling Bro
Building and installing Bro
completed connections
Generic TCP connection events
compound statement
Statements
concatenation of strings
Predefined Functions
conditional expression
Expressions
configuration options
-enable-brov6
The Bro source code
confused login analysis
login analyzer confusion
confused/ authentication annotation
login event handlers | login event handlers
confusion of heuristics
login analyzer confusion
conn analyzer
Generic Connection Analysis
conn_id record
The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record
conn_size function
Connection functions
conn_state function
Connection functions
conn_stats event
The analy Analyzer
conn_tag_info variable
stepping.bro
conn_weird event
Events handled by conn_weird
conn_weird_addl event
Events handled by conn_weird_addl
connection
additional information
The connection record | Connection summaries
addresses
The connection record | The connection record | Connection summaries
analysis
Generic Connection Analysis | The hot Analyzer | The analy Analyzer
attempt
Generic TCP connection events
bytes
The connection record | Connection summaries | Connection functions
completion
Generic TCP connection events | Generic TCP connection events
definitions
Definitions of connections
detecting sensitive
hot functions
duration
The connection record | Connection summaries
establishment
Generic TCP connection events
events
Generic TCP connection events
finished
Generic TCP connection events
flags
Connection summaries
functions
Connection functions | Connection functions
generic analysis
Generic Connection Analysis
half finished
Generic TCP connection events
hosts
Connection summaries
hot
The connection record | Connection functions | login functions | login functions
hot analysis
The hot Analyzer
ICMP
Definitions of connections
ID
Connection functions | Connection functions
initiator
The connection record | The connection record
logging
Connection functions
new
Generic TCP connection events
non-existing
Run-time errors for non-existing
originator
The connection record | The connection record
partial
Generic TCP connection events
partial close
Generic TCP connection events
pending
Generic TCP connection events
ports
The connection record | The connection record
recording
Connection functions
rejected
Generic TCP connection events
reset
Generic TCP connection events
reuse
Events handled by conn_weird
sensitivity
The connection record
sequence numbers
Predefined Functions | Predefined Functions
service
The connection record | Connection summaries | Connection functions | Connection functions
simultaneous open
Events handled by conn_weird
size
The connection record | Connection summaries | Connection functions
start time
The connection record | Connection summaries
state
The connection record | Connection summaries | Connection functions
summaries
Connection summaries
TCP
Definitions of connections
terminating with extreme prejudice
Connection functions
testing for existence
Predefined Functions
UDP
Definitions of connections
connection events
TCP-specific
Generic TCP connection events
connection id is not a known connection
Predefined Functions | Run-time errors for non-existing
connection id is not a known login connection
Predefined Functions | Predefined Functions
connection record
The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record
connection size
undetermined for RST termination
ftp variables
connection states
Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries | Connection summaries
OTH
Connection summaries
REJ
Connection summaries
RSTO
Connection summaries
RSTOS0
Connection summaries
RSTR
Connection summaries
RSTRH
Connection summaries
S0
Connection summaries
S1
Connection summaries
S2
Connection summaries
S3
Connection summaries
SF
Connection summaries
SH
Connection summaries
SHR
Connection summaries
connection summary files
Connection summaries | Connection summaries
red
Connection summaries | Connection summaries
connection_attempt event
Generic TCP connection events
connection_established event
Generic TCP connection events | login event handlers
connection_finished event
Generic TCP connection events
connection_half_finished event
Generic TCP connection events
connection_id
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
connection_originator_SYN_ack (``weird'' event)
Events handled by conn_weird
connection_partial_close event
Generic TCP connection events
connection_pending event
Generic TCP connection events
connection_record function
Predefined Functions
connection_rejected event
Generic TCP connection events
connection_reset event
Generic TCP connection events
connectivity
dropping
scan variables | scan functions
const statement
Statements
const variable declaration
Modifiability
constant expression
Expressions
constant variables
Statements
constants
The analy Analyzer | The analy Analyzer | The analy Analyzer | The analy Analyzer
address
Address Constants
boolean
Boolean Constants
count
Numeric Constants
ENDIAN_BIG
The analy Analyzer
ENDIAN_CONFUSED
The analy Analyzer
ENDIAN_LITTLE
The analy Analyzer
ENDIAN_UNKNOWN
The analy Analyzer
floating-point
Numeric Constants
hostname
Address Constants
integer
Numeric Constants
interval
Temporal Constants to Temporal Constants
net
Net Constants
pattern
Pattern Constants to Pattern Constants
port
Port Constants
record
Record Constants to Record Constants
string
String Constants to String Constants
temporal
Temporal Constants
time
Temporal Constants to Temporal Constants
contains_string function
Predefined Functions
CONTENTS_BOTH direction
Predefined Functions
CONTENTS_NONE direction
Predefined Functions
CONTENTS_ORIG direction
Predefined Functions
CONTENTS_RESP direction
Predefined Functions
control packets (SYN/FIN/RST)
Flags | The tcp analyzer
conversion of non-IPv4 address to net
Predefined Functions
converting an IPv6 address to net
run-time error
Predefined Functions
copy
shallow vs. deep
Record Assignment | Table Assignment
corrupted packets
Events handled by conn_weird | Events handled by net_weird
count
see types, count
count maximum
Predefined Functions
count minimum
Predefined Functions
&create_expire attribute
Table Attributes
creating directories
Predefined Functions
creation_time
The dns_mapping record
dns_mapping field
The dns_mapping record
crud
Generic TCP connection events | The weird Module
current_time function
Predefined Functions
d format
Predefined Functions | Predefined Functions
daemon username
The hot-ids Module | ident variables
daemons
as innocuous user names
ident variables
data
unanalyzed
Events handled by conn_weird
data_after_reset (``weird'' event)
Events handled by conn_weird
data_before_established (``weird'' event)
Events handled by conn_weird
day interval unit
Temporal Constants
debugging
filtering problems
Filtering
decrement expressions
Expressions
deep copy
Record Assignment | Table Assignment
default
filtering
Filtering
&default attribute
Table Attributes
default values
Table Attributes
DEL
Predefined Functions | Predefined Functions
delete character
Predefined Functions
delete keyword
Statements
delete statement
Statements
&delete_func attribute
Refinement
demux module
The demux Module
demux_conn function
The demux Module
demux_dir variable
demux.bro
demuxed_conn variable
demux.bro
denial of service
excessively large fragments
Events handled by flow_weird
Land attack
Events generated by the
detected_stones variable
stepping.bro
detecting scans
The scan Analyzer
detecting sensitive connections
hot functions
determine_service function
Connection functions
/dev/bpf
Tuning BPF
did_PTR_scan_event variable
dns.bro
did_sigconns variable
backdoor.bro
did_ssh_version variable
ssh.bro
did_stone_summary variable
stepping.bro
direct_login_prompts variable
Uncategorized | login variables
directions
Predefined Functions | Predefined Functions | Predefined Functions | Predefined Functions
CONTENTS_BOTH
Predefined Functions
CONTENTS_NONE
Predefined Functions
CONTENTS_ORIG
Predefined Functions
CONTENTS_RESP
Predefined Functions
directories
creating
Predefined Functions
directory names
sensitive
login variables
discarder_check_icmp function
Predefined Functions
discarder_check_ip function
Predefined Functions
discarder_check_tcp function
Predefined Functions
discarder_check_udp function
Predefined Functions
discarder_maxlen variable
Uncategorized
display_pairs variable
stepping.bro
distinct_answered_PTR_requests variable
dns.bro
distinct_backscatter_peers variable
scan.bro
distinct_peers variable
scan.bro
distinct_ports variable
scan.bro
distinct_PTR_requests variable
dns.bro
distinct_rejected_PTR_requests variable
dns.bro
diverse network use
causing ``weird'' events
The weird Module
division
numeric
Arithmetic Operators
temporal
Temporal Division
DMZ
spoof detection
hot variables
DNS
Bro's private cache
The dns Module
forcing access to
Flags
mappings
The dns_mapping record
DNS lookups
non-blocking
The Bro source code
dns module
The dns Module
dns_interesting_changes variable
dns-mapping.bro | dns variables
dns_log variable
dns.bro
dns_mapping record
no title | The dns_mapping record | The dns_mapping record | The dns_mapping record | The dns_mapping record | The dns_mapping record | The dns_mapping record | The dns_mapping record | The dns_mapping record
dns_mapping_altered event
dns event handlers
dns_mapping_lost_name event
dns event handlers
dns_mapping_name_changed event
dns event handlers
dns_mapping_new_name event
dns event handlers
dns_mapping_unverified event
dns event handlers
dns_mapping_valid event
dns event handlers
dns_session_timeout variable
bro.init
dns_sessions variable
dns.bro
done_with_network global variable
Expressions
done_with_network variable
Uncategorized
dotted quads
The hf utility
double
see types, double
double maximum
Predefined Functions
double minimum
Predefined Functions
drop-connectivity shell script
scan functions
drop_address function
scan functions
dropping connectivity
scan variables | scan functions
DUMP portmapper call
The portmapper Analyzer
duration
The connection record
connection field
The connection record
duration of a connection
The connection record | Connection summaries
dynamic defaults
Table Attributes
e format
Predefined Functions
edit function
Predefined Functions
edit_and_check_line function
login functions
edit_and_check_password function
login functions
edit_and_check_user function
login functions
edited_input_trouble variable
login.bro | login variables
editing
Predefined Functions
eggdrop sensitive filename
ftp variables
eggdrop sensitive login input
login variables
eject exploit
login variables
else keyword
Statements
embedded NUL
run-time error
Run-time errors for strings
-enable-brov6 configuration option
The Bro source code
encrypted login sessions
login event handlers
encryption
leading to ``excessive lines''
login event handlers
endian issues
Predefined Functions | The analy Analyzer
ENDIAN_BIG constant
The analy Analyzer
ENDIAN_CONFUSED constant
The analy Analyzer
ENDIAN_LITTLE constant
The analy Analyzer
endian_type statistic
The analy Analyzer
ENDIAN_UNKNOWN constant
The analy Analyzer
endpoint record
The connection record | The connection record | The connection record | The connection record | The connection record | Connection summaries
endpoint_id function
The port-name Module
enum
see types, enum | see types, enum
enumerations
Enumerations to Enumerations
environment
accessing
Predefined Functions
responder
login analyzer confusion
Telnet options
login analyzer confusion
environment variables
$BRO_ID
The log Module
$BRO_PREFIXES
Flags | Run-time environment
$BROPATH
Run-time environment
$USER
login analyzer confusion
ephemeral port
Connection functions
triggering a backdoor
login variables
ephemeral ports
confused with sensitive services
hot variables
equality expression
Expressions
escape sequences
String Constants
established connections
Generic TCP connection events
/etc/inetd.conf
hot variables
/etc/passwd
http variables
/etc/shadow
http variables
evasion
authentication dialog
The login Analyzer | login analyzer confusion
excessively small fragments
Events handled by flow_weird
inconsistent fragment size
Events handled by flow_weird
inconsistent fragments
Events handled by flow_weird
inconsistent RPC retransmission
Events handled by conn_weird
inconsistent TCP retransmission
Additional handlers for ``weird''
inserting NULs
String Constants
length mismatch
Events handled by conn_weird
using tunneling
login event handlers
event
see types, event
event engine
Event handlers
event handler
invocation
Event handlers
event handlers
Event handlers to Event handlers
event handling
weird
Events handled by conn_weird to Additional handlers for ``weird''
event keyword
Statements
event scheduling expression
Expressions
event statement
Statements
event type
Event handlers to Event handlers
events
PTR_scan
dns.bro
PTR_scan
dns.bro
PTR_scan
dns.bro
bro_init
Filtering | Filtering
bro_init
General Processing Events
net_done
General Processing Events
bro_done
General Processing Events
bro_signal
General Processing Events
net_stats_update
General Processing Events
ack_above_hole
General Processing Events
new_connection
Generic TCP connection events
connection_established
Generic TCP connection events
connection_attempt
Generic TCP connection events
partial_connection
Generic TCP connection events
connection_finished
Generic TCP connection events
connection_rejected
Generic TCP connection events
connection_half_finished
Generic TCP connection events
connection_reset
Generic TCP connection events
connection_partial_close
Generic TCP connection events
connection_pending
Generic TCP connection events
udp_request
The udp analyzer
udp_reply
The udp analyzer
account_tried
scan event handlers
dns_mapping_valid
dns event handlers
dns_mapping_unverified
dns event handlers
dns_mapping_new_name
dns event handlers
dns_mapping_lost_name
dns event handlers
dns_mapping_name_changed
dns event handlers
dns_mapping_altered
dns event handlers
finger_request
finger event handlers
finger_reply
finger event handlers
ftp_request
ftp event handlers
ftp_reply
ftp event handlers
http_request
http event handlers
ident_request
ident event handlers
ident_reply
ident event handlers
ident_error
ident event handlers
login_failure
login event handlers
login_success
login event handlers
login_input_line
login event handlers
login_output_line
login event handlers
login_confused
login event handlers
login_confused_text
login event handlers
login_terminal
login event handlers
excessive_line
login event handlers
inconsistent_option
login event handlers
bad_option
login event handlers
bad_option_termination
login event handlers
authentication_accepted
login event handlers
authentication_rejected
login event handlers
authentication_skipped
login event handlers
connection_established
login event handlers
partial_connection
login event handlers
activating_encryption
login event handlers
pm_request_null
portmapper event handlers
pm_request_set
portmapper event handlers
pm_request_unset
portmapper event handlers
pm_request_getport
portmapper event handlers
pm_request_dump
portmapper event handlers
pm_request_callit
portmapper event handlers
pm_attempt_null
portmapper event handlers
pm_attempt_set
portmapper event handlers
pm_attempt_unset
portmapper event handlers
pm_attempt_getport
portmapper event handlers
pm_attempt_dump
portmapper event handlers
pm_attempt_callit
portmapper event handlers
pm_bad_port
portmapper event handlers
conn_stats
The analy Analyzer
signature_match
The signature Module
ssl_conn_attempt
SSL event handlers
ssl_conn_server_reply
SSL event handlers
ssl_certificate_seen
SSL event handlers
ssl_certificate
SSL event handlers
ssl_conn_reused
SSL event handlers
ssl_conn_established
SSL event handlers
ssl_conn_alert
SSL event handlers
ssl_conn_weak
SSL event handlers
conn_weird
Events handled by conn_weird
conn_weird_addl
Events handled by conn_weird_addl
flow_weird
Events handled by flow_weird
net_weird
Events handled by net_weird
rexmit_inconsistency
Additional handlers for ``weird''
ack_above_hole
Additional handlers for ``weird''
exceptional
The weird Module to Additional handlers for ``weird''
finish
General Processing Events | General Processing Events
general Bro processing
General Processing Events
generic TCP connection
Generic TCP connection events
initialization
General Processing Events
scheduling
Expressions
startup
General Processing Events
termination
General Processing Events | General Processing Events
exceptional events
The weird Module to Additional handlers for ``weird''
excess_RPC (``weird'' event)
Events handled by conn_weird
excessive_line event
login event handlers
excessive_ntp_request variable
ntp.bro
excessive_RPC_len (``weird'' event)
Events handled by conn_weird
excessive_typeahead (login confusion state)
login analyzer confusion
excessively long lines
login event handlers
excessively_large_fragment (``weird'' event)
Events handled by flow_weird
excessively_small_fragment (``weird'' event)
Events handled by flow_weird
excluding hosts
Filtering
executables
running
Predefined Functions
exit function
Predefined Functions
expanded_line
login functions
check_info field
login functions
expiration
timer
Expressions | Uncategorized
&expire_func attribute
Table Attributes
explicit typing
Typing
exploit scans
The signature Module
exploit tools
login variables
smashdu.c
login variables
exploits
login variables | login variables | login variables
/bin/eject
login variables
buffer overflow
login variables
eject
login variables
loadmodule
login variables
Unix
login variables
expression statement
Statements
expressions
Expressions to Expressions
parenthesized
Expressions
constant
Expressions
variable
Expressions
increment
Expressions
decrement
Expressions
negation
Expressions
positivation
Expressions
arithmetic
Expressions
logical
Expressions
equality
Expressions
relational
Expressions
conditional
Expressions
assignment
Expressions
function call
Expressions
anonymous function
Expressions
event scheduling
Expressions
index
Expressions
membership
Expressions
pattern matching
Expressions
record field access
Expressions
record constructor
Expressions
record field test
Expressions
extra_repeat_text (login confusion state)
login analyzer confusion
EZsetup username
The hot-ids Module
-F flag
Flags | Flags
f format
Predefined Functions
failure of heuristics
login analyzer confusion
fatal run-time error
non-existing connection
Predefined Functions
fetch utility
login variables
fflush
Predefined Functions
field attributes
Record Assignment
\f formfeed escape
String Constants
file
see types, file
file type
Files to Files
filenames
sensitive
ftp variables | login variables
files
appending
Predefined Functions
opening
Predefined Functions | Predefined Functions
testing if open
Predefined Functions
filtering
default
Filtering
filters
Filtering to Filtering
displaying
Filtering
errors
Filtering
FIN control packet
Flags | The tcp analyzer
FIN_advanced_last_seq (``weird'' event)
Events handled by conn_weird
FIN_after_reset (``weird'' event)
Events handled by conn_weird
FIN_storm (``weird'' event)
Events handled by conn_weird
Finger
analysis
The finger Analyzer
weird events
Events handled by conn_weird
finger analyzer
The finger Analyzer
finger_reply event
finger event handlers
finger_request event
finger event handlers
finish event
General Processing Events | General Processing Events
firewall
reactive
scan variables | scan functions
flag_rejected_service variable
hot.bro | hot variables
flag_successful_inbound_service variable
hot.bro | hot variables
flag_successful_service variable
hot.bro | hot variables
flags
-f
Flags
-h
Flags
-i
Flags
-p
Flags
-r
Flags
-s
Flags
-w
Flags
-v
Flags
-F
Flags
-O
Flags
-P
Flags
-W
Flags
-P
The dns Module
flags of connection
Connection summaries
flex utility
Pattern Constants
flow_weird event
Events handled by flow_weird
flush_all function
Predefined Functions
fmt function
Predefined Functions
for keyword
Statements
for statement
Statements
forbidden check_info record
login functions
forbidden_id_patterns variable
hot-ids.bro | The hot-ids Module
forbidden_ids variable
hot-ids.bro | The hot-ids Module
forbidden_ids_if_no_password variable
hot-ids.bro | The hot-ids Module
forcing access to Bro's private DNS cache
Flags
format
%
Predefined Functions
d
Predefined Functions | Predefined Functions
e
Predefined Functions
f
Predefined Functions
g
Predefined Functions
precision
Predefined Functions
width
Predefined Functions
formatting text
Predefined Functions
.forward
ftp variables
frag module
The frag Module
fragment reassembly
The frag Module
fragment_inconsistency (``weird'' event)
Events handled by flow_weird
fragment_overlap (``weird'' event)
Events handled by flow_weird
fragment_protocol_inconsistency (``weird'' event)
Events handled by flow_weird
fragment_size_inconsistency (``weird'' event)
Events handled by flow_weird
fragment_with_DF (``weird'' event)
Events handled by flow_weird
fragments
excessively large
Events handled by flow_weird
excessively small
Events handled by flow_weird
inconsistent
Events handled by flow_weird
inconsistent protocols
Events handled by flow_weird
inconsistent sizes
Events handled by flow_weird
overlapping
Events handled by flow_weird
TCP vs. UDP
The frag Module
frogs
dissecting
http variables
FTP
analysis
The ftp Analyzer
ephemeral ports confused with sensitive services
hot variables
log file
ftp variables
session information
The ftp_session_info record
weird events
Events handled by conn_weird
ftp analyzer
The ftp Analyzer
ftp session summary file
ftp variables
ftp_data_expected variable
ftp.bro
ftp_data_expected_session variable
ftp.bro
ftp_excessive_filename_len variable
ftp.bro
ftp_excessive_filename_trunc_len variable
ftp.bro
ftp_guest_ids variable
ftp.bro | ftp variables
ftp_hot_cmds variable
ftp.bro
ftp_hot_files variable
ftp.bro | ftp variables
ftp_hot_guest_files variable
ftp.bro | ftp variables
ftp_ignore_invalid_PORT variable
ftp.bro
ftp_ignore_privileged_PASVs variable
ftp.bro
ftp_log variable
ftp.bro
ftp_not_actually_hot_files variable
ftp variables
ftp_port record
Predefined Functions | Predefined Functions
ftp_reply event
ftp event handlers
ftp_request event
ftp event handlers
ftp_session_info record
no title | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record | The ftp_session_info record
ftp_sessions variable
ftp.bro
ftp_sig_disabled variable
backdoor.bro
ftp_skip_hot variable
ftp.bro | ftp variables
full_id_string function
Connection functions
full_input_trouble variable
login.bro
full_output_trouble variable
login.bro
function
see types, function
function call expression
Expressions
function invocation
Expressions
function keyword
Expressions
function type
Functions to Functions
functions
Functions to Functions
active_connection
Predefined Functions
active_file
Predefined Functions
add_interface
Predefined Functions
add_tcpdump_filter
Predefined Functions
log_hook
Predefined Functions
byte_len
Predefined Functions
cat
Predefined Functions
clean
Predefined Functions
close
Predefined Functions
connection_record
Predefined Functions
contains_string
Predefined Functions
current_time
Predefined Functions
discarder_check_icmp
Predefined Functions
discarder_check_ip
Predefined Functions
discarder_check_tcp
Predefined Functions
discarder_check_udp
Predefined Functions
edit
Predefined Functions
exit
Predefined Functions
flush_all
Predefined Functions
fmt
Predefined Functions
get_login_state
Predefined Functions
get_orig_seq
Predefined Functions
get_resp_seq
Predefined Functions
getenv
Predefined Functions
is_tcp_port
Predefined Functions
length
Predefined Functions
log_file_name
Predefined Functions
mask_addr
Predefined Functions
max_count
Predefined Functions
max_double
Predefined Functions
max_interval
Predefined Functions
min_count
Predefined Functions
min_double
Predefined Functions
min_interval
Predefined Functions
mkdir
Predefined Functions
network_time
Predefined Functions
open
Predefined Functions
open_for_append
Predefined Functions
open_log_file
Predefined Functions
parse_ftp_pasv
Predefined Functions
parse_ftp_port
Predefined Functions
reading_live_traffic
Predefined Functions
set_buf
Predefined Functions
set_contents_file
Predefined Functions
set_login_state
Predefined Functions
set_record_packets
Predefined Functions
skip_further_processing
Predefined Functions
sub_bytes
Predefined Functions
system
Predefined Functions
to_lower
Predefined Functions
to_net
Predefined Functions
to_upper
Predefined Functions
conn_size
Connection functions
conn_state
Connection functions
determine_service
Connection functions
full_id_string
Connection functions
id_string
Connection functions
log_hot_conn
Connection functions
record_connection
Connection functions
service_name
Connection functions
terminate_connection
Connection functions
is_local_addr
Site-specific functions
check_spoof
hot functions
check_hot
hot functions
drop_address
scan functions
check_scan
scan functions
endpoint_id
The port-name Module
log_hook
The log Module | The log Module
log_hook
The log Module
demux_conn
The demux Module
is_ftp_data_conn
ftp functions
is_login_conn
login functions
hot_login
login functions
is_hot_id
login functions
is_forbidden_id
login functions
edit_and_check_line
login functions
edit_and_check_user
login functions
edit_and_check_password
login functions
rpc_prog
portmapper functions
pm_check_getport
portmapper functions
pm_activity
portmapper functions
pm_request
portmapper functions
pm_attempt
portmapper functions
has_signature_matched
The signature Module
report_weird
weird functions
report_weird_conn
weird functions
report_weird_orig
weird functions
open
Files
open_for_append
Files
anonymous
Expressions
redefining
Functions
site-specific
Site-specific functions
g format
Predefined Functions
garbage args (RPC status code)
portmapper functions
general Bro processing events
General Processing Events
general scripting
Predefined Functions
generic connection analysis
Generic Connection Analysis
GET HTTP method
http variables
get_login_state function
Predefined Functions
get_orig_seq function
Predefined Functions
get_resp_seq function
Predefined Functions
getenv function
Predefined Functions
GETPORT portmapper call
The portmapper Analyzer
global scope
of enumerations
Enumerations
global variable declaration
Scope
global variables
Scope
interfaces
Live traffic
capture_filter
Flags
restrict_filter
Flags
interfaces
Flags
done_with_network
Expressions
gnutella_sig_disabled variable
backdoor.bro
gtld_servers variable
scan.bro
-h flag
Flags
half-finished connections
Generic TCP connection events
handling signals
General Processing Events
handshake_cipher
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
has_signature_matched function
The signature Module
have_FTP variable
conn.bro
have_skip_remote_sensitive_URIs variable
http-request.bro
have_SMTP variable
conn.bro
have_stats variable
conn.bro
HEAD HTTP method
http variables
headers
truncated
Events handled by net_weird
heartbeat_interval variable
bro.init
help message
Flags
heuristics
attacker-induced confusion
login analyzer confusion
confusion
login analyzer confusion
environment
login analyzer confusion
extracting username information
The login Analyzer | login analyzer confusion
missing login prompt
login analyzer confusion
missing username
login analyzer confusion | login analyzer confusion
multiple login prompts
login analyzer confusion | login analyzer confusion
multiple usernames
login analyzer confusion
type-ahead
login analyzer confusion
VMS
login analyzer confusion | login analyzer confusion | login analyzer confusion
\xhex-digits hexadecimal escape
String Constants
hf utility program
no title
horiz_scan_thresholds variable
rules.bro | The signature Module
horizontal exploit scans
The signature Module
host order (vs. network order)
Predefined Functions
hostname
The dns_mapping record
dns_mapping field
The dns_mapping record
hostnames
Address Constants
mapping addresses to
The hf utility
hosts
excluding
Filtering
in a connection
Connection summaries
hot
The connection record
connection field
The connection record
hot /24 destination networks
hot variables
hot /24 source networks
hot variables
hot analyzer
The hot Analyzer
hot check_info record
login functions
hot connection
analysis
The hot Analyzer
logging
Connection functions
hot connections
login functions | login functions
hot destination addresses
hot variables
hot detection
hot functions
hot source addresses
hot variables
hot usernames
The hot-ids Module
hot-ids module
The hot-ids Module
hot_conns_reported variable
conn.bro
hot_dst_24nets variable
hot.bro | hot variables
hot_dsts variable
hot.bro | hot variables
hot_id check_info record
login functions
hot_ident_exceptions variable
ident.bro | ident variables
hot_ident_ids variable
ident.bro | ident variables
hot_ids variable
hot-ids.bro | The hot-ids Module
hot_login function
login functions
hot_login_ids variable
login.bro | login variables
hot_names variable
finger.bro | finger variables
hot_src_24nets variable
hot.bro | hot variables
hot_srcs variable
hot.bro | hot variables
hot_ssh_orig_ports variable
login variables
hot_telnet_orig_ports variable
login.bro | login variables
hot_terminal_types variable
login.bro | login variables
hr (hours) interval unit
Temporal Constants
HTTP
analysis
The http Analyzer
log file
http variables
weird events
Events handled by conn_weird
http analyzer
The http Analyzer
HTTP methods
http variables | http variables | http variables | http variables
GET
http variables
HEAD
http variables
POST
http variables
HTTP packets
contents not being recorded
Flags
http session summary file
http variables
http_abstract_max_length variable
http-abstract.bro
http_log variable
http.bro
http_proxy_sig_disabled variable
backdoor.bro
http_request event
http event handlers
http_sessions variable
http.bro
http_sig_disabled variable
backdoor.bro
HTTP_unknown_method (``weird'' event)
Events handled by conn_weird
HTTP_version_mismatch (``weird'' event)
Events handled by conn_weird
HUP signal
General Processing Events
-i flag
Flags
ICMP
checksum error
Events handled by conn_weird
connections
Definitions of connections
timeout
Definitions of connections
weird events
Events handled by conn_weird
icmp_flows variable
icmp.bro
id
The connection record | The ftp_session_info record | The ssl_connection_info record
ftp_session_info field
The ftp_session_info record
ssl_connection_info field
The ssl_connection_info record
ID of connection
Connection functions | Connection functions
id_index
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
id_string function
Connection functions
IDENT
analysis
The ident Analyzer
weird events
Events handled by conn_weird_addl
ident analyzer
The ident Analyzer
ident/ authentication annotation
ident event handlers
ident_error event
ident event handlers
ident_reply event
ident event handlers
ident_request event
ident event handlers
ident_request_addendum (``weird'' event)
Events handled by conn_weird_addl
IEUser
useless FTP username
ftp variables
if keyword
Statements
if statement
Statements
ignore_checksums variable
bro.init
implicit typing
Typing
in operator
Embedded Pattern Matching | Expressions | Expressions
in-order delivery
The analy Analyzer
"!in negation of in operator
Embedded Pattern Matching
inactivity_timeout variable
bro.init
inappropriate_FIN (``weird'' event)
Events handled by conn_weird
inbound services
fatal
hot variables
forbidden
hot variables
include_HTTP_abstract variable
http.bro
incompletely_captured_fragment (``weird'' event)
Events handled by flow_weird
inconsistent acknowledgment
Additional handlers for ``weird''
inconsistent retransmission
Events handled by conn_weird | Additional handlers for ``weird''
inconsistent_option event
login event handlers
increment expressions
Expressions
index
of a table
Tables
index expression
Expressions
inetd.conf
hot variables
inferring types
Typing
information associated with a connection
The connection record | Connection summaries
ingreslock popular backdoor
hot variables
initialization event
General Processing Events
initialization of variables
Initialization
input
analysis
The login Analyzer
editing
login variables
input_trouble variable
login.bro | login variables
input_wait_for_output variable
login.bro
installing Bro
Installing Bro
int
see types, int
INT signal
General Processing Events
integers
network vs. host order
Predefined Functions
interconn_conns variable
interconn.bro
interconn_default_pkt_size variable
interconn.bro
interconn_demux_disabled variable
interconn.bro
interconn_ignore_standard_ports variable
interconn.bro
interconn_log variable
interconn.bro
interconn_max_interarrival variable
interconn.bro
interconn_max_keystroke_pkt_size variable
interconn.bro
interconn_min_7bit_ascii_ratio variable
interconn.bro
interconn_min_alpha variable
interconn.bro
interconn_min_bytes variable
interconn.bro
interconn_min_duration variable
interconn.bro
interconn_min_gamma variable
interconn.bro
interconn_min_interarrival variable
interconn.bro
interconn_min_normal_line_ratio variable
interconn.bro
interconn_min_num_lines variable
interconn.bro
interconn_min_num_pkts variable
interconn.bro
interconn_min_ssh_pkts_ratio variable
interconn.bro
interconn_ssh_len_disabled variable
interconn.bro
interconn_standard_ports variable
interconn.bro
interconn_stat_backoff variable
interconn.bro
interconn_stat_period variable
interconn.bro
interfaces global variable
Live traffic | Flags
interfaces variable
Uncategorized
internal networks
spoof detection
hot variables
internal variables
WATCHDOG_INTERVAL
Flags
ATTEMPT_INTERVAL
Generic TCP connection events
PARTIAL_CLOSE_INTERVAL
Generic TCP connection events
internally_truncated_header (``weird'' event)
Events handled by net_weird
Internet Relay Chat (IRC)
attacker subpopulation
login variables
interval
see types, interval
interval maximum
Predefined Functions
interval minimum
Predefined Functions
interval units
usec
Temporal Constants
sec
Temporal Constants
min
Temporal Constants
hr
Temporal Constants
day
Temporal Constants
invocation
function
Expressions
invoking event handlers
Event handlers
IP
checksum error
Events handled by net_weird
fragments
Events handled by flow_weird
identification field
The analy Analyzer
weird events
Events handled by net_weird
IPv4/IPv6 address constants
Address Constants
IPv6 and lack of CIDR prefixes
Net Type
IPv6 support
Address Type
IRC
login variables
is not a TCP connection
Predefined Functions | Predefined Functions
is_forbidden_id function
login functions
is_ftp_data_conn function
ftp functions
is_hot_id function
login functions
is_local_addr function
Site-specific functions
is_login_conn function
login functions
is_tcp_port function
Predefined Functions
isascii
Predefined Functions | Predefined Functions
islower
Predefined Functions
isupper
Predefined Functions
kazaa_sig_disabled variable
backdoor.bro
keystrokes
analysis
The login Analyzer
editing
login variables
keywords
print
Statements
log
Statements
event
Statements
if
Statements
else
Statements
for
Statements
next
Statements
break
Statements
return
Statements
add
Statements
delete
Statements
function
Expressions
schedule
Expressions
kiddies
script
hot variables
Land attack
hot functions | Events generated by the
Land_attack (``weird'' event)
Events generated by the
large BPF buffers
Tuning BPF
last_stat variable
conn.bro
last_stat_time variable
conn.bro
( operator
Expressions | Expressions
length
of strings
Predefined Functions
of table or set
Predefined Functions
length function
Predefined Functions
length mismatch
UDP
Events handled by conn_weird
length() requires a table/set argument
Predefined Functions
length() takes exactly one argument
Predefined Functions
lex utility
Pattern Constants
libpcap buffer size patch
Tuning BPF
libpcap library
Tuning BPF
libraries
libpcap
Tuning BPF
libpcap
Tuning BPF
line editing
Predefined Functions
Linux
compiling Bro under
The Bro source code
super exploit
login variables
little endian
Predefined Functions | The analy Analyzer
live traffic
Statements | Predefined Functions
load
shedding
Predefined Functions
loadmodule exploit
login variables
local addresses
Site variables | Site variables | Site variables | Site-specific functions
spoofing
hot variables | hot variables | hot functions
local statement
Statements
local variable declaration
Scope
local variables
Statements | Scope
local_16_nets variable
site.bro | Site variables
local_24_nets variable
site.bro | Site variables
local_code_red_response_pgm variable
code-red.bro
local_mail_addr variable
smtp.bro
local_nets variable
site.bro | Site variables
log file
Uncategorized | Predefined Functions | The log Module
altering
login variables
connection summary (red)
Connection functions
FTP
ftp variables
HTTP
http variables
signatures
The signature Module
SSL
SSL variables
weird events
The weird Module
log keyword
Statements
log module
The log Module
log statement
Statements
log_file_name function
Predefined Functions
log_hook function
The log Module | The log Module | The log Module
log_hook predefined function
Predefined Functions
log_hot_conn function
Connection functions
log_HTTP_data variable
http.bro
log_if_not_denied
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
log_if_not_unavail
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
log_it
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
LOG_NOTICE syslog level
Statements
logging
connection
Connection functions
control of
Predefined Functions
logical expression
Expressions
logical negation
Logical Operators
login analysis
confusion
login analyzer confusion
login analyzer
The login Analyzer
login confusion states
login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion | login analyzer confusion
excessive_typeahead
login analyzer confusion
extra_repeat_text
login analyzer confusion
multiple_login_prompts
login analyzer confusion
multiple_USERs
login analyzer confusion
no_login_prompt
login analyzer confusion
no_username
login analyzer confusion
no_username2
login analyzer confusion
non_empty_multi_login
login analyzer confusion
possible_login_ploy
login analyzer confusion
repeat_without_username
login analyzer confusion
responder_environment
login analyzer confusion
username_with_embedded_repeat
login analyzer confusion
login prompts
missing
login analyzer confusion
repeated
login analyzer confusion | login analyzer confusion
login session
The login Analyzer
state
Predefined Functions | Predefined Functions
login_confused event
login event handlers
login_confused_text event
login event handlers
login_failure event
login event handlers
login_failure_msgs variable
login.bro | login variables
login_input_line event
login event handlers
login_non_failure_msgs variable
login.bro | login variables
login_output_line event
login event handlers
login_prompts variable
login.bro | login variables
login_sessions variable
login.bro
LOGIN_STATE_AUTHENTICATE state of login connection
Predefined Functions
LOGIN_STATE_CONFUSED state of login connection
Predefined Functions
LOGIN_STATE_LOGGED_IN state of login connection
Predefined Functions
LOGIN_STATE_SKIP state of login connection
Predefined Functions
login_success event
login event handlers
login_success_msgs variable
login.bro | login variables
login_terminal event
login event handlers
login_timeouts variable
login.bro | login variables
ls utility
login variables
lynx utility
login variables
magic terminal types
login variables
maintain_http_sessions variable
http.bro
management
of state
Table Attributes
mask_addr function
Predefined Functions
masking
Predefined Functions | Predefined Functions
max_count function
Predefined Functions
max_double function
Predefined Functions
max_finger_request_len variable
finger.bro
max_interval function
Predefined Functions
max_request_length variable
finger variables
max_timer_expires variable
Uncategorized
maximum
Predefined Functions
Maximum Segment Lifetime (MSL)
Events handled by conn_weird
maximums
Predefined Functions | Predefined Functions | Predefined Functions
count
Predefined Functions
double
Predefined Functions
interval
Predefined Functions
membership expression
Expressions
memory management
Table Attributes
message
connection id is not a known connection
Predefined Functions
not exactly one edit character
Predefined Functions
precision specified for non-floating point format
Predefined Functions
ridiculous field width or precision
Predefined Functions
bad format
Predefined Functions
bad type for Date format
Predefined Functions
bad type for integer format
Predefined Functions
bad type for floating-point format
Predefined Functions
wrong number of fmt arguments
Predefined Functions
too many arguments for format
Predefined Functions
too few arguments for format
Predefined Functions
connection id is not a known login connection
Predefined Functions
is not a TCP connection
Predefined Functions
is not a TCP connection
Predefined Functions
length() takes exactly one argument
Predefined Functions
length() requires a table/set argument
Predefined Functions
bad second argument to mask_addr()
Predefined Functions
cannot create directory
Predefined Functions
connection id is not a known login connection
Predefined Functions
conversion of non-IPv4 address to net
Predefined Functions
connection id is not a known connection
Run-time errors for non-existing
string without NUL terminator
Run-time errors for strings
string with embedded NUL
Run-time errors for strings
mime_log variable
mime.bro
mime_sessions variable
mime.bro
min (minutes) interval unit
Temporal Constants
min_count function
Predefined Functions
min_double function
Predefined Functions
min_interval function
Predefined Functions
minimum
Predefined Functions
minimums
Predefined Functions | Predefined Functions | Predefined Functions
count
Predefined Functions
double
Predefined Functions
interval
Predefined Functions
mismatch (RPC status code)
portmapper functions
missing login prompts
login analyzer confusion
missing username
login analyzer confusion | login analyzer confusion
mkdir failure
run-time error
Predefined Functions
mkdir function
Predefined Functions
modifiability of variables
Modifiability
modules
port-name
The port-name Module
mt
The mt Module
log
The log Module
active
The active Module
demux
The demux Module
dns
The dns Module
frag
The frag Module
hot-ids
The hot-ids Module
weird
The weird Module
dns
event handlers
dns event handlers to dns event handlers
variables
dns variables to dns variables
MSL (Maximum Segment Lifetime)
Events handled by conn_weird
mt module
The mt Module
multi-dimensional table
Declaring Tables
multiple login prompts
login analyzer confusion | login analyzer confusion
multiple usernames
login analyzer confusion
multiple_HTTP_request_elements (``weird'' event)
Events handled by conn_weird
multiple_login_prompts (login confusion state)
login analyzer confusion
multiple_RPCs (``weird'' event)
Events handled by conn_weird
multiple_USERs (login confusion state)
login analyzer confusion
multiplication
numeric
Arithmetic Operators
temporal
Temporal Multiplication
name
of log file
Predefined Functions
names
case-sensitive
Defining records
Napster
tunneled over Telnet or Rlogin
login event handlers
napster_sig_disabled variable
backdoor.bro
negation
logical
Logical Operators
temporal
Temporal Negation
negation expression
Expressions
neighbor addresses
Site variables | Site variables | Site variables
neighbor_16_nets variable
site.bro | Site variables
neighbor_24_nets variable
Site variables
neighbor_nets variable
site.bro | Site variables
net
see types, net
constants
Net Constants
operators
Net Operators
net type
Net Type to Net Operators
net_done event
General Processing Events
net_stats
see types, net_stats
net_stats record
General Processing Events | General Processing Events
net_stats_update event
General Processing Events
net_weird event
Events handled by net_weird
network cleanup event
General Processing Events
Network File System (NFS)
portmapper variables
network interfaces
Live traffic | Flags | Uncategorized
network order (vs. host order)
Predefined Functions
network prefixes
Net Type | Predefined Functions | Site variables | Site variables
network statistics
General Processing Events
Network Virtual Terminal (NVT)
login event handlers
network_time function
Predefined Functions
networks
hot destinations
hot variables
hot sources
hot variables
never_shut_down variable
scan variables
new connection
Generic TCP connection events
new_connection event
Generic TCP connection events
\n newline escape
String Constants
next keyword
Statements
next statement
Statements
NFS (Network File System)
portmapper variables
NFS traffic
high volume fragments
The frag Module
NFS_services variable
portmapper.bro | portmapper variables
NFS_world_servers variable
portmapper.bro | portmapper variables
no such connection
run-time error
Run-time errors for non-existing
no_login_prompt (login confusion state)
login analyzer confusion
no_username (login confusion state)
login analyzer confusion
no_username2 (login confusion state)
login analyzer confusion
non-blocking DNS lookups
The Bro source code
non-existing connection
fatal run-time error
Predefined Functions
non_analyzed_lifetime variable
bro.init
non_ASCII_hosts variable
login.bro | login variables
non_backdoor_prompts variable
login.bro | login variables
non_empty_multi_login (login confusion state)
login analyzer confusion
<none> username
login analyzer confusion
not a login connection
run-time error
Predefined Functions | Predefined Functions
not a TCP connection
run-time error
Predefined Functions | Predefined Functions
not exactly one edit character
Predefined Functions
"!in negation of in operator
Embedded Pattern Matching
! ``not'' operator
Logical Operators
NT
not supported
Supported platforms
ntp_session_timeout variable
bro.init
NUL
Predefined Functions
NUL_in_line (``weird'' event)
Events handled by conn_weird
NULL portmapper call
The portmapper Analyzer
null statement
Statements
NULs
Events handled by conn_weird
allowed in strings
String Constants | Run-time errors for non-existing
disallowed in certain function calls
Run-time errors for non-existing
terminating string constants
String Constants
termination
Run-time errors for non-existing
terminator missing
run-time error
Run-time errors for strings
num_accounts_tried variable
scan.bro
num_backscatter_peers variable
scan.bro
num_distinct_peers variable
scan.bro
num_distinct_ports variable
scan.bro
num_dns_sessions variable
dns.bro
num_in_order statistic
The analy Analyzer
num_OO statistic
The analy Analyzer
num_pkts statistic
The analy Analyzer
num_repl statistic
The analy Analyzer
num_requests
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
num_rxmit statistic
The analy Analyzer
num_rxmit_bytes statistic
The analy Analyzer
num_scan_triples variable
scan.bro
number of elements
in table or set
Predefined Functions
numeric types
count
Bro Types
int
Bro Types
double
Bro Types
nuucp username
The hot-ids Module | ident variables
NVT (Network Virtual Terminal)
login event handlers
NVT options
authentication
login event handlers | login event handlers
bad
login event handlers
bad termination
login event handlers
encryption
login event handlers
inconsistent
login event handlers
-O flag
Flags
\octal-digits octal escape
String Constants
off-line analysis
Traffic traces | Flags | Predefined Functions | Connection functions
ok (RPC status code)
portmapper functions
okay_to_lookup_sensitive_hosts variable
dns.bro
omit_rewrite_place_holder variable
bro.init
on-line analysis
Live traffic | Flags | Uncategorized | Predefined Functions | Connection functions
open function
Files | Predefined Functions
open_for_append function
Files | Predefined Functions
open_log_file function
Predefined Functions
opening a file
Predefined Functions | Predefined Functions
operator
&& ``and''
Logical Operators | Expressions
( parenthesis
Expressions | Expressions
! ``not''
Logical Operators
"|"| ``or''
Logical Operators | Expressions
) parenthesis
Expressions | Expressions
operators
+=
Filtering
+
Arithmetic Operators
-
Arithmetic Operators
*
Arithmetic Operators
/
Arithmetic Operators
+
Arithmetic Operators
-
Arithmetic Operators
-
Temporal Negation
+
Temporal Addition
-
Temporal Subtraction
*
Temporal Multiplication
/
Temporal Division
$
Accessing Fields Using ``$''
++
Expressions
-
Expressions
!
Expressions
-
Expressions
+
Expressions
+
Expressions
-
Expressions
*
Expressions
/
Expressions
?
Expressions
:
Expressions
=
Expressions
(
Expressions
)
Expressions
[
Expressions
]
Expressions
in
Expressions
!in
Expressions
in
Expressions
!in
Expressions
[
Expressions
]
Expressions
address
Address Operators
arithmetic
Arithmetic Operators to Arithmetic Operators
associativity
Arithmetic Operators
operand conversion
Arithmetic Operators
precedence
Arithmetic Operators
comparison
Comparison Operators to Comparison Operators
associativity
Comparison Operators
operand conversion
Comparison Operators
precedence
Comparison Operators
logical
Logical Operators to Logical Operators
associativity
Logical Operators
precedence
Logical Operators
net
Net Operators
pattern
Pattern Operators
ports
Port Operators
string
String Operators
temporal
Temporal Operators
optimizer for policy script interpreter
Flags
optimizing your system for Bro
Tuning BPF
options
Telnet
The login Analyzer
"|"| ``or'' operator
Logical Operators | Expressions
orig
The connection record
orig_h
The connection record
conn_id field
The connection record
orig_p
The connection record
conn_id field
The connection record
originator_RPC_reply (``weird'' event)
Events handled by conn_weird
OTH connection state
Connection summaries
out-of-order delivery
The analy Analyzer
OutOfBox username
The hot-ids Module
output_trouble variable
login.bro | login variables
-P flag
Flags | Flags | The dns Module
packet filter
access
Tuning BPF
permissions
Tuning BPF
packets
control (SYN/FIN/RST)
Flags | The tcp analyzer
corrupted
Events handled by conn_weird | Events handled by net_weird
drops
General Processing Events | Additional handlers for ``weird''
recording
Predefined Functions
replication
The analy Analyzer
storms
Events handled by conn_weird
time
Predefined Functions
()
Expressions | Expressions
parenthesized expression
Expressions
parse_ftp_pasv function
Predefined Functions
parse_ftp_port function
Predefined Functions
partial connections
Generic TCP connection events
PARTIAL_CLOSE_INTERVAL internal variable
Generic TCP connection events
partial_connection event
Generic TCP connection events | login event handlers
partial_connection_ok variable
bro.init
partial_finger_request (``weird'' event)
Events handled by conn_weird
partial_ftp_request (``weird'' event)
Events handled by conn_weird
partial_ident_request (``weird'' event)
Events handled by conn_weird
partial_portmapper_request (``weird'' event)
Events handled by conn_weird
partial_RPC (``weird'' event)
Events handled by conn_weird
partially closed connections
Generic TCP connection events
passwd
http variables
passwords
guessing
The scan Analyzer
inadvertently exposed
The login Analyzer
sniffing
The login Analyzer
PATH_UTMP sensitive pattern
login variables
pattern
see types, pattern
pattern matching
Patterns
embedded
Embedded Pattern Matching
exact
Exact Pattern Matching
pattern matching expression
Expressions
patterns
Patterns to Embedded Pattern Matching
pending connections
Generic TCP connection events
pending_data_when_closed (``weird'' event)
Events handled by conn_weird
performance
analysis tradeoffs
Activating an Analyzer
filtering
Filtering
pm_activity function
portmapper functions
pm_attempt function
portmapper functions
pm_attempt portmapper attempt
portmapper event handlers
pm_attempt_callit event
portmapper event handlers
pm_attempt_dump event
portmapper event handlers
pm_attempt_getport event
portmapper event handlers
pm_attempt_null event
portmapper event handlers
pm_attempt_set event
portmapper event handlers
pm_attempt_unset event
portmapper event handlers
pm_bad_port event
portmapper event handlers
pm_callit_request portmapper call
portmapper event handlers
pm_check_getport function
portmapper functions
pm_mapping portmapper mapping record
portmapper event handlers
pm_port_request portmapper request
portmapper event handlers
pm_request function
portmapper functions
pm_request_callit event
portmapper event handlers
pm_request_dump event
portmapper event handlers
pm_request_getport event
portmapper event handlers
pm_request_null event
portmapper event handlers
pm_request_set event
portmapper event handlers
pm_request_unset event
portmapper event handlers
policy/ policy directory
Run-time environment
policy directories
Run-time environment
policy script interpreter
optimizer
Flags
policy/local/ policy directory
Run-time environment
polymorphic functions
need for
Predefined Functions | Predefined Functions | Events handled by conn_weird_addl
popular backdoors
hot variables
ingreslock
hot variables
port
see types, port
ephemeral
Connection functions
port scanning
The scan Analyzer
port type
Port Type to Port Operators
port-name module
The port-name Module
port_names variable
port-names.bro | The connection record | Connection functions | The port-name Module
portmapper analyzer
The portmapper Analyzer
portmapper attempts
portmapper event handlers
pm_attempt
portmapper event handlers
portmapper calls
portmapper event handlers
CALLIT
The portmapper Analyzer
DUMP
The portmapper Analyzer
GETPORT
The portmapper Analyzer
NULL
The portmapper Analyzer
pm_callit_request
portmapper event handlers
SET
The portmapper Analyzer
UNSET
The portmapper Analyzer
portmapper mapping records
portmapper event handlers
pm_mapping
portmapper event handlers
portmapper requests
portmapper event handlers
pm_port_request
portmapper event handlers
ports
constants
Port Constants
operators
Port Operators
TCP
Port Type
TCP vs. UDP
Predefined Functions
UDP
Port Type
positivation expression
Expressions
possible future changes
timer type
Expressions
breaking string constants across multiple lines
String Constants
constants for absolute times
Temporal Constants
use of any type for bypassing strong typing
The any type
possible packet drop messages
Additional handlers for ``weird''
ack above a hole
Additional handlers for ``weird''
possible_login_ploy (login confusion state)
login analyzer confusion
possible_port_scan_thresh variable
scan.bro | scan variables
possible_scan_sources variable
scan.bro
possible_split_routing (``weird'' event)
Events handled by conn_weird
POST HTTP method
http variables
precision
of formatted strings
Predefined Functions
precision specified for non-floating point format
Predefined Functions
predefined functions
Predefined Functions to Functions for manipulating time
active_connection
Predefined Functions
active_file
Predefined Functions
add_interface
Predefined Functions
add_tcpdump_filter
Predefined Functions
log_hook
Predefined Functions
byte_len
Predefined Functions
cat
Predefined Functions
clean
Predefined Functions
close
Predefined Functions
connection_record
Predefined Functions
contains_string
Predefined Functions
current_time
Predefined Functions
discarder_check_icmp
Predefined Functions
discarder_check_ip
Predefined Functions
discarder_check_tcp
Predefined Functions
discarder_check_udp
Predefined Functions
edit
Predefined Functions
exit
Predefined Functions
flush_all
Predefined Functions
fmt
Predefined Functions
get_login_state
Predefined Functions
get_orig_seq
Predefined Functions
get_resp_seq
Predefined Functions
getenv
Predefined Functions
is_tcp_port
Predefined Functions
length
Predefined Functions
log_file_name
Predefined Functions
mask_addr
Predefined Functions
max_count
Predefined Functions
max_double
Predefined Functions
max_interval
Predefined Functions
min_count
Predefined Functions
min_double
Predefined Functions
min_interval
Predefined Functions
mkdir
Predefined Functions
network_time
Predefined Functions
open
Predefined Functions
open_for_append
Predefined Functions
open_log_file
Predefined Functions
parse_ftp_pasv
Predefined Functions
parse_ftp_port
Predefined Functions
reading_live_traffic
Predefined Functions
set_buf
Predefined Functions
set_contents_file
Predefined Functions
set_login_state
Predefined Functions
set_record_packets
Predefined Functions
skip_further_processing
Predefined Functions
sub_bytes
Predefined Functions
system
Predefined Functions
to_lower
Predefined Functions
to_net
Predefined Functions
to_upper
Predefined Functions
predefined variables
Predefined Variables to Uncategorized
active_conn
active.bro
alert_action_filters
alert.bro
alert_file
alert.bro
anon_log
anon.bro
preserved_subnet
anon.bro
preserved_net
anon.bro
backdoor_log
backdoor.bro
backdoor_min_num_lines
backdoor.bro
backdoor_min_normal_line_ratio
backdoor.bro
backdoor_min_bytes
backdoor.bro
backdoor_min_7bit_ascii_ratio
backdoor.bro
backdoor_demux_disabled
backdoor.bro
backdoor_demux_skip_tags
backdoor.bro
backdoor_ignore_src_addrs
backdoor.bro
backdoor_ignore_dst_addrs
backdoor.bro
backdoor_ignore_ports
backdoor.bro
backdoor_standard_ports
backdoor.bro
backdoor_stat_period
backdoor.bro
backdoor_stat_backoff
backdoor.bro
backdoor_annotate_standard_ports
backdoor.bro
ssh_sig_disabled
backdoor.bro
telnet_sig_disabled
backdoor.bro
telnet_sig_3byte_disabled
backdoor.bro
rlogin_sig_disabled
backdoor.bro
rlogin_sig_1byte_disabled
backdoor.bro
root_backdoor_sig_disabled
backdoor.bro
ftp_sig_disabled
backdoor.bro
napster_sig_disabled
backdoor.bro
gnutella_sig_disabled
backdoor.bro
kazaa_sig_disabled
backdoor.bro
http_sig_disabled
backdoor.bro
http_proxy_sig_disabled
backdoor.bro
did_sigconns
backdoor.bro
rlogin_conns
backdoor.bro
root_backdoor_sig_conns
backdoor.bro
ssh_len_conns
backdoor.bro
ssh_min_num_pkts
backdoor.bro
ssh_min_ssh_pkts_ratio
backdoor.bro
telnet_sig_conns
backdoor.bro
telnet_sig_3byte_conns
backdoor.bro
ignore_checksums
bro.init
partial_connection_ok
bro.init
tcp_SYN_ack_ok
bro.init
tcp_match_undelivered
bro.init
tcp_SYN_timeout
bro.init
tcp_session_timer
bro.init
tcp_connection_linger
bro.init
tcp_attempt_delayv
bro.init
tcp_close_delay
bro.init
tcp_reset_delay
bro.init
tcp_partial_close_delay
bro.init
non_analyzed_lifetime
bro.init
inactivity_timeout
bro.init
tcp_storm_thresh
bro.init
tcp_storm_interarrival_thresh
bro.init
tcp_reassembler_ports_orig
bro.init
tcp_reassembler_ports_resp
bro.init
table_expire_interval
bro.init
dns_session_timeout
bro.init
ntp_session_timeout
bro.init
rpc_timeout
bro.init
watchdog_interval
bro.init
heartbeat_interval
bro.init
anonymize_ip_addr
bro.init
omit_rewrite_place_holder
bro.init
rewriting_http_trace
bro.init
rewriting_smtp_trace
bro.init
code_red_log
code-red.bro
code_red_list1
code-red.bro
code_red_list2
code-red.bro
local_code_red_response_pgm
code-red.bro
remote_code_red_response_pgm
code-red.bro
have_FTP
conn.bro
have_SMTP
conn.bro
have_stats
conn.bro
hot_conns_reported
conn.bro
last_stat
conn.bro
last_stat_time
conn.bro
RPC_server_map
conn.bro
demux_dir
demux.bro
demuxed_conn
demux.bro
actually_rejected_PTR_anno
dns.bro
sensitive_lookup_hosts
dns.bro
okay_to_lookup_sensitive_hosts
dns.bro
dns_log
dns.bro
dns_sessions
dns.bro
num_dns_sessions
dns.bro
distinct_PTR_requests
dns.bro
distinct_rejected_PTR_requests
dns.bro
distinct_answered_PTR_requests
dns.bro
report_rejected_PTR_thresh
dns.bro
report_rejected_PTR_factor
dns.bro
allow_PTR_scans
dns.bro
did_PTR_scan_event
dns.bro
dns_interesting_changes
dns-mapping.bro
hot_names
finger.bro
max_finger_request_len
finger.bro
rewrite_finger_trace
finger.bro
ftp_log
ftp.bro
ftp_sessions
ftp.bro
ftp_guest_ids
ftp.bro
ftp_skip_hot
ftp.bro
ftp_hot_files
ftp.bro
ftp_hot_guest_files
ftp.bro
ftp_hot_cmds
ftp.bro
skip_unexpected
ftp.bro
skip_unexpected_net
ftp.bro
ftp_data_expected
ftp.bro
ftp_data_expected_session
ftp.bro
ftp_excessive_filename_len
ftp.bro
ftp_excessive_filename_trunc_len
ftp.bro
ftp_ignore_invalid_PORT
ftp.bro
ftp_ignore_privileged_PASVs
ftp.bro
same_local_net_is_spoof
hot.bro
allow_spoof_services
hot.bro
allow_pairs
hot.bro
allow_16_net_pairs
hot.bro
hot_srcs
hot.bro
hot_dsts
hot.bro
hot_src_24nets
hot.bro
hot_dst_24nets
hot.bro
allow_services
hot.bro
allow_services_to
hot.bro
allow_service_pairs
hot.bro
flag_successful_service
hot.bro
flag_successful_inbound_service
hot.bro
terminate_successful_inbound_service
hot.bro
flag_rejected_service
hot.bro
forbidden_ids
hot-ids.bro
forbidden_ids_if_no_password
hot-ids.bro
forbidden_id_patterns
hot-ids.bro
always_hot_ids
hot-ids.bro
hot_ids
hot-ids.bro
http_log
http.bro
http_sessions
http.bro
include_HTTP_abstract
http.bro
log_HTTP_data
http.bro
maintain_http_sessions
http.bro
process_HTTP_replies
http.bro
process_HTTP_data
http.bro
http_abstract_max_length
http-abstract.bro
skip_remote_sensitive_URIs
http-request.bro
have_skip_remote_sensitive_URIs
http-request.bro
sensitive_URIs
http-request.bro
worm_URIs
http-request.bro
sensitive_post_URIs
http-request.bro
icmp_flows
icmp.bro
hot_ident_ids
ident.bro
hot_ident_exceptions
ident.bro
public_ident_user_ids
ident.bro
public_ident_systems
ident.bro
rewrite_ident_trace
ident.bro
interconn_conns
interconn.bro
interconn_log
interconn.bro
interconn_min_interarrival
interconn.bro
interconn_max_interarrival
interconn.bro
interconn_max_keystroke_pkt_size
interconn.bro
interconn_default_pkt_size
interconn.bro
interconn_stat_period
interconn.bro
interconn_stat_backoff
interconn.bro
interconn_min_num_pkts
interconn.bro
interconn_min_duration
interconn.bro
interconn_ssh_len_disabled
interconn.bro
interconn_min_ssh_pkts_ratio
interconn.bro
interconn_min_bytes
interconn.bro
interconn_min_7bit_ascii_ratio
interconn.bro
interconn_min_num_lines
interconn.bro
interconn_min_normal_line_ratio
interconn.bro
interconn_min_alpha
interconn.bro
interconn_min_gamma
interconn.bro
interconn_standard_ports
interconn.bro
interconn_ignore_standard_ports
interconn.bro
interconn_demux_disabled
interconn.bro
input_trouble
login.bro
edited_input_trouble
login.bro
full_input_trouble
login.bro
input_wait_for_output
login.bro
output_trouble
login.bro
full_output_trouble
login.bro
backdoor_prompts
login.bro
non_backdoor_prompts
login.bro
hot_terminal_types
login.bro
hot_telnet_orig_ports
login.bro
skip_authentication
login.bro
login_prompts
login.bro
login_failure_msgs
login.bro
login_non_failure_msgs
login.bro
login_success_msgs
login.bro
login_timeouts
login.bro
router_prompts
login.bro
non_ASCII_hosts
login.bro
skip_logins_to
login.bro
always_hot_login_ids
login.bro
hot_login_ids
login.bro
rlogin_id_okay_if_no_password_exposed
login.bro
login_sessions
login.bro
mime_log
mime.bro
mime_sessions
mime.bro
check_relay_3
mime.bro
check_relay_4
mime.bro
excessive_ntp_request
ntp.bro
allow_excessive_ntp_requests
ntp.bro
port_names
port-names.bro
rpc_programs
portmapper.bro
NFS_services
portmapper.bro
RPC_okay
portmapper.bro
RPC_okay_nets
portmapper.bro
RPC_okay_services
portmapper.bro
NFS_world_servers
portmapper.bro
any_RPC_okay
portmapper.bro
RPC_dump_okay
portmapper.bro
RPC_do_not_complain
portmapper.bro
suppress_pm_log
portmapper.bro
rule_actions
rules.bro
rule_file
rules.bro
horiz_scan_thresholds
rules.bro
vert_scan_thresholds
rules.bro
suppress_scan_checks
scan.bro
report_peer_scan
scan.bro
report_outbound_peer_scan
scan.bro
num_distinct_peers
scan.bro
distinct_peers
scan.bro
num_distinct_ports
scan.bro
distinct_ports
scan.bro
report_port_scan
scan.bro
possible_port_scan_thresh
scan.bro
possible_scan_sources
scan.bro
num_scan_triples
scan.bro
scan_triples
scan.bro
accounts_tried
scan.bro
num_accounts_tried
scan.bro
report_accounts_tried
scan.bro
report_remote_accounts_tried
scan.bro
skip_accounts_tried
scan.bro
addl_web
scan.bro
skip_services
scan.bro
skip_outbound_services
scan.bro
skip_scan_sources
scan.bro
skip_scan_nets_16
scan.bro
skip_scan_nets_24
scan.bro
backscatter_ports
scan.bro
num_backscatter_peers
scan.bro
distinct_backscatter_peers
scan.bro
report_backscatter
scan.bro
root_servers
scan.bro
gtld_servers
scan.bro
local_nets
site.bro
local_16_nets
site.bro
local_24_nets
site.bro
neighbor_nets
site.bro
neighbor_16_nets
site.bro
local_mail_addr
smtp.bro
smtp_log
smtp.bro
smtp_sessions
smtp.bro
process_smtp_relay
smtp.bro
smtp_legal_cmds
smtp.bro
smtp_hot_cmds
smtp.bro
smtp_sensitive_cmds
smtp.bro
relay_log
smtp-relay.bro
smtp_relay_table
smtp-relay.bro
smtp_session_by_recipient
smtp-relay.bro
smtp_session_by_message_id
smtp-relay.bro
smtp_session_by_content_hash
smtp-relay.bro
software_file
software.bro
software_table
software.bro
software_ident_by_major
software.bro
ssh_log
ssh.bro
did_ssh_version
ssh.bro
step_log
stepping.bro
display_pairs
stepping.bro
tag_to_conn_map
stepping.bro
conn_tag_info
stepping.bro
detected_stones
stepping.bro
did_stone_summary
stepping.bro
stp_delta
stepping.bro
stp_idle_min
stepping.bro
stp_ratio_thresh
stepping.bro
stp_scale
stepping.bro
stp_common_host_thresh
stepping.bro
stp_random_pair_thresh
stepping.bro
stp_demux_disabled
stepping.bro
skip_clear_ssh_reports
stepping.bro
tftp_alert_count
tftp.bro
udp_req_count
udp.bro
udp_rep_count
udp.bro
udp_did_summary
udp.bro
weird_log
weird.bro
weird_action
weird.bro
weird_action_filters
weird.bro
weird_ignore_host
weird.bro
weird_do_not_ignore_repeats
weird.bro
worm_log
worm.bro
worm_list
worm.bro
worm_type_list
worm.bro
bro_log_file
Uncategorized
capture_filter
Uncategorized
direct_login_prompts
Uncategorized
discarder_maxlen
Uncategorized
done_with_network
Uncategorized
interfaces
Uncategorized
max_timer_expires
Uncategorized
restrict_filter
Uncategorized
prefixes
Flags | Run-time environment
network
Net Type | Predefined Functions | Site variables | Site variables
premature_connection_reuse (``weird'' event)
Events handled by conn_weird
preserved_net variable
anon.bro
preserved_subnet variable
anon.bro
priming Bro's private DNS cache
Flags
print keyword
Statements
print statement
Statements
print-filter analyzer
Filtering | Filtering | Filtering
printf
Predefined Functions
process_HTTP_data variable
http.bro
process_HTTP_replies variable
http.bro
process_smtp_relay variable
smtp.bro
processing
avoiding
Predefined Functions
prog unavail (RPC status code)
portmapper functions
programs
hf
no title
cf
no title
PTR_scan event
dns.bro | dns.bro | dns.bro
public_ident_systems variable
ident.bro
public_ident_user_ids variable
ident.bro
-r flag
Flags
reactive firewall
scan variables | scan functions
&read_expire attribute
Table Attributes
reading tcpdump files
Flags
reading_live_traffic function
Predefined Functions
record
see types, record
ftp_port
Predefined Functions
ftp_port
Predefined Functions
connection
The connection record
record constructor expression
Expressions
record field access expression
Expressions
record field test expression
Expressions
record_connection function
Connection functions
recorded traffic
Predefined Functions
recording connections
Connection functions
recording packets
Predefined Functions
records
Records to Record Assignment | Predefined Functions | Predefined Functions | General Processing Events | General Processing Events | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | The connection record | Connection summaries | no title | The dns_mapping record | The dns_mapping record | no title | The ftp_session_info record | login functions | no title | The x509 record | no title | The ssl_connection_info record | Context conditions | Context conditions
assignment
Record Assignment to Record Assignment
check_info
login functions
conn_id
The connection record | The connection record | The connection record
connection
The connection record | The connection record | The connection record | The connection record | The connection record
dns_mapping
no title | The dns_mapping record | The dns_mapping record
endpoint
The connection record | The connection record | The connection record | Connection summaries
field attributes
Record Assignment
fields
Records
accessing
Accessing Fields Using ``$''
legal names
Defining records
ftp_port
Predefined Functions | Predefined Functions
ftp_session_info
no title | The ftp_session_info record
net_stats
General Processing Events | General Processing Events
signature_state
Context conditions | Context conditions
ssl_connection_info
no title | The ssl_connection_info record
x509
no title | The x509 record
red connection summary file
Connection summaries | Connection summaries
&redef attribute
Refinement
redefining functions
Functions
redefining variables
Refinement
refinement
Refinement
REJ connection state
Connection summaries
rejected connections
Generic TCP connection events
relational expression
Expressions
relationals
address
Address Type
net
Net Operators
numeric
Comparison Operators
string
String Operators
temporal
Temporal Relationals
relative time
Temporal Types
relay_log variable
smtp-relay.bro
remote procedure call (RPC)
The portmapper Analyzer
remote_code_red_response_pgm variable
code-red.bro
repeat text
login analyzer confusion | login analyzer confusion
repeat text (VMS)
login analyzer confusion
repeat_without_username (login confusion state)
login analyzer confusion
repeated_SYN_reply_wo_ack (``weird'' event)
Events handled by conn_weird
repeated_SYN_with_ack (``weird'' event)
Events handled by conn_weird
replication of packets
The analy Analyzer
report_accounts_tried variable
scan.bro | scan variables
report_backscatter variable
scan.bro
report_outbound_peer_scan variable
scan.bro | scan variables
report_peer_scan variable
scan.bro | scan variables
report_port_scan variable
scan.bro
report_rejected_PTR_factor variable
dns.bro
report_rejected_PTR_thresh variable
dns.bro
report_remote_accounts_tried variable
scan.bro | scan variables
report_weird function
weird functions
report_weird_conn function
weird functions
report_weird_orig function
weird functions
req_addr
The dns_mapping record
dns_mapping field
The dns_mapping record
req_host
The dns_mapping record
dns_mapping field
The dns_mapping record
request
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
request_t
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
reserved multicast addresss
portmapper variables
sun-rpc.mcast.net
portmapper variables
reset connections
Generic TCP connection events
resp
The connection record
resp_h
The connection record
conn_id field
The connection record
resp_p
The connection record
conn_id field
The connection record
responder_environment (login confusion state)
login analyzer confusion
responder_RPC_call (``weird'' event)
Events handled by conn_weird
restrict_filter global variable
Flags
restrict_filter variable
Uncategorized | Filtering to Filtering
restricting traffic
Filtering
retransmission
inconsistent
Events handled by conn_weird | Additional handlers for ``weird''
return keyword
Statements
return statement
Statements
rewrite_finger_trace variable
finger.bro
rewrite_ident_trace variable
ident.bro
rewriting_http_trace variable
bro.init
rewriting_smtp_trace variable
bro.init
rewt username
The hot-ids Module | login variables
rexmit_inconsistency event
Additional handlers for ``weird''
.rhosts
ftp variables | The login Analyzer | login analyzer confusion | login variables | login event handlers
ridiculous field width or precision
Predefined Functions
) operator
Expressions | Expressions
RLIMIT_NOFILE a
Files
Rlogin
session state
Predefined Functions | Predefined Functions
sessions
The login Analyzer
weird events
Events handled by conn_weird
rlogin_conns variable
backdoor.bro
rlogin_id_okay_if_no_password_exposed variable
login.bro | login variables
rlogin_sig_1byte_disabled variable
backdoor.bro
rlogin_sig_disabled variable
backdoor.bro
rlogin_text_after_rejected (``weird'' event)
Events handled by conn_weird
root
backdoors
login variables
Bro not running as
Tuning BPF
setuid
login variables
root_backdoor_sig_conns variable
backdoor.bro
root_backdoor_sig_disabled variable
backdoor.bro
root_servers variable
scan.bro
router_prompts variable
login.bro | login variables
routing
split
Events handled by conn_weird
RPC (Remote Procedure Call)
The portmapper Analyzer
reserved multicast address
portmapper variables
weird events
Events handled by conn_weird
RPC status codes
portmapper functions | portmapper functions | portmapper functions | portmapper functions | portmapper functions | portmapper functions | portmapper functions | portmapper functions
auth error
portmapper functions
garbage args
portmapper functions
mismatch
portmapper functions
ok
portmapper functions
prog unavail
portmapper functions
system err
portmapper functions
timeout
portmapper functions
unknown
portmapper functions
RPC_do_not_complain variable
portmapper.bro
RPC_dump_okay variable
portmapper.bro | portmapper variables
RPC_okay variable
portmapper.bro | portmapper variables
RPC_okay_nets variable
portmapper.bro | portmapper variables
RPC_okay_services variable
portmapper.bro | portmapper variables
rpc_prog function
portmapper functions
rpc_programs variable
portmapper.bro | portmapper variables
RPC_rexmit_inconsistency (``weird'' event)
Events handled by conn_weird
RPC_server_map variable
conn.bro
rpc_timeout variable
bro.init
RST control packet
Flags | The tcp analyzer
RST termination
causing undetermined connection size
ftp variables
RST_storm (``weird'' event)
Events handled by conn_weird
RST_with_data (``weird'' event)
Events handled by conn_weird
RSTO connection state
Connection summaries
RSTOS0 connection state
Connection summaries
RSTR connection state
Connection summaries
RSTRH connection state
Connection summaries
rule_actions variable
rules.bro
rule_file variable
rules.bro
run-time error
bad address mask
Predefined Functions
bad fmt date argument
Predefined Functions
bad fmt editing character
Predefined Functions
bad fmt field width
Predefined Functions
bad fmt floating-point argument
Predefined Functions
bad fmt format specifier
Predefined Functions
bad fmt integer argument
Predefined Functions
bad fmt precision
Predefined Functions
bad length argument (not a table or set)
Predefined Functions
can't open
Run-time environment
converting an IPv6 address to net
Predefined Functions
embedded NUL
Run-time errors for strings
mkdir failure
Predefined Functions
no such connection
Run-time errors for non-existing
non-existing connection
Predefined Functions
not a login connection
Predefined Functions | Predefined Functions
not a TCP connection
Predefined Functions | Predefined Functions
NULs
terminator missing
Run-time errors for strings
watchdog timer expired
Flags
wrong number of fmt arguments
Predefined Functions
wrong number of length arguments
Predefined Functions
running Bro
Running Bro
running outside scripts or executables
Predefined Functions
-s flag
Flags
S0 connection state
Connection summaries
S1 connection state
Connection summaries
S2 connection state
Connection summaries
S3 connection state
Connection summaries
same_local_net_is_spoof variable
hot.bro | hot variables
save file
control over what's recorded
Predefined Functions
reading
Flags
writing
Flags
scalars
Declaring Tables
scan analyzer
The scan Analyzer
scan detection
The scan Analyzer to scan event handlers
scan_triples variable
scan.bro
scanning
address
The scan Analyzer
port
The scan Analyzer
shutting down
scan variables | scan functions
stealth
Generic TCP connection events | hot functions | scan functions | Events handled by conn_weird | Events handled by conn_weird
scans
exploit
The signature Module
schedule keyword
Expressions
scheduling events
Expressions
scoping of variables
Scope
script kiddies
hot variables
scripting
general
Predefined Functions
scripts
running
Predefined Functions
standard
Analyzers and Events to The interconn Analyzer
search path
Run-time environment
searching for strings
Patterns
sec (seconds) interval unit
Temporal Constants
semi-colon statement termination
Statements
sensitive /24 destination networks
hot variables
sensitive /24 source networks
hot variables
sensitive destination addresses
hot variables
sensitive filenames
ftp variables | login variables
eggdrop
ftp variables
sensitive information
inadvertently exposed
The login Analyzer
sensitive login inputs
login variables
eggdrop
login variables
sensitive patterns
login variables
PATH_UTMP
login variables
sensitive POST URIs
http variables
wwwroot
http variables
sensitive services
confused with ephemeral ports
hot variables
sensitive source addresses
hot variables
sensitive usernames
The hot-ids Module
sensitive_lookup_hosts variable
dns.bro
sensitive_post_URIs variable
http-request.bro | http variables
sensitive_URIs variable
http-request.bro | http variables
sensitivity associated with a connection
The connection record
sequence numbers
connection originator
Predefined Functions
connection responder
Predefined Functions
server_cert
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
service
The connection record
connection field
The connection record
service associated with a connection
The connection record | Connection summaries | Connection functions | Connection functions
service_name function
Connection functions
services
allowable
hot variables
allowed to a particular host
hot variables
allowed to particular host pairs
hot variables
fatal if inbound
hot variables
forbidden
hot variables
forbidden if attempted
hot variables
forbidden if inbound
hot variables
set
see types, set
SET portmapper call
The portmapper Analyzer
set size
Predefined Functions
set type
Sets to Sets
set_buf function
Predefined Functions
set_contents_file function
Predefined Functions
set_login_state function
Predefined Functions
set_record_packets function
Predefined Functions
setrlimit system calls
Files
setuid root
login variables
SF connection state
Connection summaries
sgiweb username
The hot-ids Module
sh
Predefined Functions
SH connection state
Connection summaries
shadow
http variables
shadowing
Filtering
shallow copy
Record Assignment | Table Assignment
shedding load
Predefined Functions
shell escape
Predefined Functions
shell scripts
drop-connectivity
scan functions
short-circuit && ``and'' operator
Logical Operators | Expressions
short-circuit "|"| ``or'' operator
Logical Operators | Expressions
SHR connection state
Connection summaries
shut_down_all_scans variable
scan variables
shut_down_scans variable
scan variables
shut_down_thresh variable
scan variables
shutting down scans
scan variables | scan functions
sig_actions variable
The signature Module
SIG_FILE action
The signature Module
SIG_IGNORE action
The signature Module
SIG_LOG action
The signature Module
SIG_QUIET action
The signature Module
SIGHUP
General Processing Events
SIGINT
General Processing Events
signal handling
General Processing Events
signature analysis
The signature Module
signature analyzer
The signature Module
signature_match event
The signature Module
signature_state record
Context conditions | Context conditions
signatures
log file
The signature Module
SIGTERM
General Processing Events
simultaneous open
Events handled by conn_weird
simultaneous_open (``weird'' event)
Events handled by conn_weird
site addresses
Site-specific functions
site analyzer
Site-specific information
site-specific
functions
Site-specific functions to Site-specific functions
information
Site-specific information
variables
Site variables to Site variables
size
The connection record
endpoint field
The connection record
of table or set
Predefined Functions
size of connection
Connection summaries | Connection functions
skip_accounts_tried variable
scan.bro | scan variables
skip_authentication variable
login.bro | login variables
skip_clear_ssh_reports variable
stepping.bro
skip_further_processing function
Predefined Functions
skip_logins_to variable
login.bro | login variables
skip_outbound_services variable
scan.bro | scan variables
skip_remote_sensitive_URIs variable
http-request.bro
skip_scan_nets_16 variable
scan.bro
skip_scan_nets_24 variable
scan.bro | scan variables
skip_scan_sources variable
scan.bro | scan variables
skip_services variable
scan.bro
skip_unexpected variable
ftp.bro | ftp variables
skip_unexpected_net variable
ftp.bro | ftp variables
(skipped) authentication annotation
login event handlers
smashdu.c exploit tool
login variables
smtp_hot_cmds variable
smtp.bro
smtp_legal_cmds variable
smtp.bro
smtp_log variable
smtp.bro
smtp_relay_table variable
smtp-relay.bro
smtp_sensitive_cmds variable
smtp.bro
smtp_session_by_content_hash variable
smtp-relay.bro
smtp_session_by_message_id variable
smtp-relay.bro
smtp_session_by_recipient variable
smtp-relay.bro
smtp_sessions variable
smtp.bro
smurf attacks
login variables
sniffer logs
login variables
sniffing
The login Analyzer
software_file variable
software.bro
software_ident_by_major variable
software.bro
software_table variable
software.bro
source code
for Bro
The Bro source code
split routing
Events handled by conn_weird
spontaneous_FIN (``weird'' event)
Events handled by conn_weird
spontaneous_RST (``weird'' event)
Events handled by conn_weird
spoofing
allowable services
hot variables
detection
hot variables | hot functions
spook detection
hot variables
sprintf
Predefined Functions
ssh_len_conns variable
backdoor.bro
ssh_log variable
ssh.bro
ssh_min_num_pkts variable
backdoor.bro
ssh_min_ssh_pkts_ratio variable
backdoor.bro
ssh_sig_disabled variable
backdoor.bro
SSL
analysis
The SSL Analyzer
connection information
The ssl_connection_info record
log file
SSL variables
x509
The x509 record
SSL analyzer
The SSL Analyzer
SSL session summary file
SSL variables
ssl_analyze_certificates variable
SSL variables
ssl_certificate event
SSL event handlers
ssl_certificate_seen event
SSL event handlers
ssl_compare_cipherspecs variable
SSL variables
ssl_conn_alert event
SSL event handlers
ssl_conn_attempt event
SSL event handlers
ssl_conn_established event
SSL event handlers
ssl_conn_reused event
SSL event handlers
ssl_conn_server_reply event
SSL event handlers
ssl_conn_weak event
SSL event handlers
ssl_connection_info record
no title | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record | The ssl_connection_info record
ssl_max_cipherspec_size variable
SSL variables
ssl_store_cert_path variable
SSL variables
ssl_store_certificates variable
SSL variables
ssl_store_key_material variable
SSL variables
ssl_verify_certificates variable
SSL variables
standard scripts
Analyzers and Events to The interconn Analyzer
start time of a connection
The connection record | Connection summaries
start_time
The connection record
connection field
The connection record
startup
event
General Processing Events
transients
Events handled by conn_weird
state
The connection record
endpoint field
The connection record
of a Telnet/Rlogin session
Predefined Functions | Predefined Functions
state management
Table Attributes
state of connection
Connection summaries | Connection functions
state of login connections
Predefined Functions | Predefined Functions | Predefined Functions | Predefined Functions
LOGIN_STATE_AUTHENTICATE
Predefined Functions
LOGIN_STATE_CONFUSED
Predefined Functions
LOGIN_STATE_LOGGED_IN
Predefined Functions
LOGIN_STATE_SKIP
Predefined Functions
statements
Statements to Statements
expression
Statements
print
Statements
log
Statements
event
Statements
if
Statements
for
Statements
next
Statements
break
Statements
return
Statements
add
Statements
delete
Statements
compound
Statements
null
Statements
local
Statements
const
Statements
multi-line
Statements
semi-colon termination
Statements
static typing
Bro Types
statistical analysis
The analy Analyzer
statistics
The analy Analyzer | The analy Analyzer | The analy Analyzer | The analy Analyzer | The analy Analyzer | The analy Analyzer | The analy Analyzer
endian_type
The analy Analyzer
num_in_order
The analy Analyzer
num_OO
The analy Analyzer
num_pkts
The analy Analyzer
num_repl
The analy Analyzer
num_rxmit
The analy Analyzer
num_rxmit_bytes
The analy Analyzer
stderr
Uncategorized | Predefined Functions | The log Module
stdout
Statements | Predefined Functions
stealth scans
Generic TCP connection events | hot functions | scan functions | Events handled by conn_weird | Events handled by conn_weird
step_log variable
stepping.bro
storms
Events handled by conn_weird
stp_common_host_thresh variable
stepping.bro
stp_delta variable
stepping.bro
stp_demux_disabled variable
stepping.bro
stp_idle_min variable
stepping.bro
stp_random_pair_thresh variable
stepping.bro
stp_ratio_thresh variable
stepping.bro
stp_scale variable
stepping.bro
strftime
Predefined Functions
string
see types, string
extraction
Predefined Functions
formatting
Predefined Functions
string constants
NUL terminated
String Constants
string with embedded NUL
Run-time errors for strings
string without NUL terminator
Run-time errors for strings
"<string-with-NUL>" error value
Run-time errors for strings
strings
Strings to String Operators
cleaned up
Predefined Functions
concatenation
Predefined Functions
length
Predefined Functions
termination with NULs
Run-time errors for non-existing
strlen
Predefined Functions
strstr
Predefined Functions
sub-tables
lack of
Accessing Tables
sub_bytes function
Predefined Functions
subnets
Net Type | Predefined Functions | Predefined Functions | Site variables | Site variables
substrings
Predefined Functions
subtraction
numeric
Arithmetic Operators
temporal
Temporal Subtraction
sun-rpc.mcast.net reserved multicast address
portmapper variables
suppress_pm_log variable
portmapper.bro | portmapper variables
suppress_scan_checks variable
scan.bro
SYN control packet
Flags | The tcp analyzer
SYN_after_close (``weird'' event)
Events handled by conn_weird
SYN_after_partial (``weird'' event)
Events handled by conn_weird
SYN_after_reset (``weird'' event)
Events handled by conn_weird
SYN_inside_connection (``weird'' event)
Events handled by conn_weird
SYN_seq_jump (``weird'' event)
Events handled by conn_weird
SYN_with_data (``weird'' event)
Events handled by conn_weird
syslog
Statements
syslog levels
Statements
LOG_NOTICE
Statements
system callss
Files
setrlimit
Files
system configuration
Tuning BPF
system err (RPC status code)
portmapper functions
system function
Predefined Functions
T/TCP
Events handled by conn_weird
\t tab escape
String Constants
table
see types, table
table size
Predefined Functions
table_expire_interval variable
bro.init
tables
Tables to Deleting Table Elements
clearing entries
Table Assignment
tag_to_conn_map variable
stepping.bro
TCP
analysis
The tcp analyzer
checksum error
Events handled by conn_weird
Christmas packet
Events handled by conn_weird
connections
Definitions of connections
corrupted header
Events handled by net_weird
events
Generic TCP connection events
fragments
The frag Module
transaction
Events handled by conn_weird
weird events
Events handled by conn_weird
tcp analyzer
no title
TCP control packets (SYN/FIN/RST)
Flags | The tcp analyzer
TCP vs. UDP ports
Predefined Functions
TCP Wrappers
reset vs. rejected connections
Generic TCP connection events
TCP-specific connection events
Generic TCP connection events
tcp_attempt_delayv variable
bro.init
TCP_christmas (``weird'' event)
Events handled by conn_weird
tcp_close_delay variable
bro.init
tcp_connection_linger variable
bro.init
tcp_match_undelivered variable
bro.init
tcp_partial_close_delay variable
bro.init
tcp_reassembler_ports_orig variable
bro.init
tcp_reassembler_ports_resp variable
bro.init
tcp_reset_delay variable
bro.init
tcp_session_timer variable
bro.init
tcp_storm_interarrival_thresh variable
bro.init
tcp_storm_thresh variable
bro.init
tcp_SYN_ack_ok variable
bro.init
tcp_SYN_timeout variable
bro.init
tcpdump
Tuning BPF | Running Bro on network | Flags | Flags | Flags | Flags | Filtering | Filtering | Filtering
bugs
Filtering
filters
Flags | Filtering
merging save files
Flags
reading save files
Running Bro on network | Flags
running concurrently with Bro
Tuning BPF
shadow
Filtering
turning off optimization
Filtering
writing save files
Flags
Telnet
options
The login Analyzer
authentication
login event handlers | login event handlers
bad
login event handlers
bad termination
login event handlers
encryption
login event handlers
environment
login analyzer confusion
inconsistent
login event handlers
session state
Predefined Functions | Predefined Functions
sessions
The login Analyzer
telnet_sig_3byte_conns variable
backdoor.bro
telnet_sig_3byte_disabled variable
backdoor.bro
telnet_sig_conns variable
backdoor.bro
telnet_sig_disabled variable
backdoor.bro
temporal
addition
Temporal Addition
constants
Temporal Constants
division
Temporal Division
multiplication
Temporal Multiplication
negation
Temporal Negation
relationals
Temporal Relationals
subtraction
Temporal Subtraction
types
Temporal Types
TERM signal
General Processing Events
terminal type backdoors
login variables
VT666
login variables
terminate_connection function
Connection functions
terminate_successful_inbound_service variable
hot.bro | hot variables
terminating connections forcibly
Connection functions
termination event
General Processing Events | General Processing Events
text
formatting
Predefined Functions
TFreak
login variables
tftp_alert_count variable
tftp.bro
time
see types, time | Temporal Types to Temporal Relationals
clock
Predefined Functions | Predefined Functions
packet
Predefined Functions
timeout (RPC status code)
portmapper functions
timer expiration
Expressions | Uncategorized
timers
Expressions
timestamps
mapping to readable form
The cf utility
to_lower function
Predefined Functions
to_net function
Predefined Functions
to_upper function
Predefined Functions
tolower
Predefined Functions
too few arguments for format
Predefined Functions
too many arguments for format
Predefined Functions
toupper
Predefined Functions
trace file
control over what's recorded
Predefined Functions
reading
Flags
writing
Flags
traffic
live vs. recorded
Statements | Predefined Functions
restricting
Filtering
transaction TCP
Events handled by conn_weird
transients
startup
Events handled by conn_weird
trojaning
login variables
truncated headers
Events handled by net_weird
truncated_header (``weird'' event)
Events handled by net_weird
truncated_IP (``weird'' event)
Events handled by net_weird
tunneling
login event handlers
type casting
not provided in Bro
The any type
type inference
Typing
type-ahead
maximum allowed
login analyzer confusion
types
bool
Bro Types
numeric
Bro Types
count
Bro Types
int
Bro Types
double
Bro Types
enumeration
Bro Types
enum
Bro Types
string
Bro Types
pattern
Bro Types
temporal
Bro Types
time
Bro Types
interval
Bro Types
port
Bro Types
addr
Bro Types
net
Bro Types
record
Bro Types
table
Bro Types
set
Bro Types
file
Bro Types
function
Bro Types
event
Bro Types
bool
Logical Operators
count
Numeric Types
int
Numeric Types
double
Numeric Types
numeric
Numeric Types
numeric
to Comparison Operators
enum
Enumerations
string
Strings
pattern
Patterns
time
Temporal Types
interval
Temporal Types
conversion
Type Conversions to Type Conversions
automatic
Type Conversions
numeric
bool not numeric
Mixing Numeric Types
intermixing
Mixing Numeric Types
overview
Bro Types
types, need fors
The connection record
union
The connection record
typing
static
Bro Types
typing of variables
Typing
UDP
analysis
The udp analyzer
checksum error
Events handled by conn_weird
``connections''
Definitions of connections
fragments
The frag Module
length mismatch
Events handled by conn_weird
timeout
Definitions of connections
weird events
Events handled by conn_weird
udp analyzer
no title
UDP_datagram_length_mismatch (``weird'' event)
Events handled by conn_weird
udp_did_summary variable
udp.bro
udp_rep_count variable
udp.bro
udp_reply event
The udp analyzer
udp_req_count variable
udp.bro
udp_request event
The udp analyzer
unanalyzed data
Events handled by conn_weird
undirectional analysis
Events handled by conn_weird
union type
need for
Predefined Functions
union types, need for
The connection record
Unix analysis
The login Analyzer
Unix support
Supported platforms
Unix timestamps
The cf utility
unknown (RPC status code)
portmapper functions
unpaired_RPC_response (``weird'' event)
Events handled by conn_weird
UNSET portmapper call
The portmapper Analyzer
unsolicited_SYN_response (``weird'' event)
Events handled by conn_weird
unusual events
The weird Module to Additional handlers for ``weird''
prevalence in actual network traffic
The weird Module
usage message
Flags
usec (microseconds) interval unit
Temporal Constants
user
The ftp_session_info record
ftp_session_info field
The ftp_session_info record
$USER environment variable
login analyzer confusion
user keystrokes
analysis
The login Analyzer
editing
login variables
\tt Username: (VMS login prompt)
login analyzer confusion
username_with_embedded_repeat (login confusion state)
login analyzer confusion
usernames
The hot-ids Module | The hot-ids Module | The hot-ids Module | The hot-ids Module | The hot-ids Module | The hot-ids Module | The hot-ids Module | The hot-ids Module | ident variables | ident variables | ident variables | login variables
4Dgifts
The hot-ids Module
daemon
The hot-ids Module | ident variables
extracting
The login Analyzer | login analyzer confusion
EZsetup
The hot-ids Module
missing
login analyzer confusion | login analyzer confusion
<none>
login analyzer confusion
nuucp
The hot-ids Module | ident variables
OutOfBox
The hot-ids Module
repeated
login analyzer confusion
rewt
The hot-ids Module | login variables
sensitive
The hot-ids Module
sgiweb
The hot-ids Module
uucp
The hot-ids Module | ident variables
/usr/local/lib/bro/ policy directory
Run-time environment
utilities
fetch
login variables
flex
Pattern Constants
lex
Pattern Constants
ls
login variables
lynx
login variables
utility programs
hf
no title
cf
no title
uucp username
The hot-ids Module | ident variables
-v flag
Flags
valid
The dns_mapping record
dns_mapping field
The dns_mapping record
values
overview
Overview
vantage point
Events handled by conn_weird
variable declarations
Scope | Scope | Modifiability
const
Modifiability
global
Scope
local
Scope
variable expression
Expressions
variables
active_conn
active.bro
alert_action_filters
alert.bro
alert_file
alert.bro
anon_log
anon.bro
preserved_subnet
anon.bro
preserved_net
anon.bro
backdoor_log
backdoor.bro
backdoor_min_num_lines
backdoor.bro
backdoor_min_normal_line_ratio
backdoor.bro
backdoor_min_bytes
backdoor.bro
backdoor_min_7bit_ascii_ratio
backdoor.bro
backdoor_demux_disabled
backdoor.bro
backdoor_demux_skip_tags
backdoor.bro
backdoor_ignore_src_addrs
backdoor.bro
backdoor_ignore_dst_addrs
backdoor.bro
backdoor_ignore_ports
backdoor.bro
backdoor_standard_ports
backdoor.bro
backdoor_stat_period
backdoor.bro
backdoor_stat_backoff
backdoor.bro
backdoor_annotate_standard_ports
backdoor.bro
ssh_sig_disabled
backdoor.bro
telnet_sig_disabled
backdoor.bro
telnet_sig_3byte_disabled
backdoor.bro
rlogin_sig_disabled
backdoor.bro
rlogin_sig_1byte_disabled
backdoor.bro
root_backdoor_sig_disabled
backdoor.bro
ftp_sig_disabled
backdoor.bro
napster_sig_disabled
backdoor.bro
gnutella_sig_disabled
backdoor.bro
kazaa_sig_disabled
backdoor.bro
http_sig_disabled
backdoor.bro
http_proxy_sig_disabled
backdoor.bro
did_sigconns
backdoor.bro
rlogin_conns
backdoor.bro
root_backdoor_sig_conns
backdoor.bro
ssh_len_conns
backdoor.bro
ssh_min_num_pkts
backdoor.bro
ssh_min_ssh_pkts_ratio
backdoor.bro
telnet_sig_conns
backdoor.bro
telnet_sig_3byte_conns
backdoor.bro
ignore_checksums
bro.init
partial_connection_ok
bro.init
tcp_SYN_ack_ok
bro.init
tcp_match_undelivered
bro.init
tcp_SYN_timeout
bro.init
tcp_session_timer
bro.init
tcp_connection_linger
bro.init
tcp_attempt_delayv
bro.init
tcp_close_delay
bro.init
tcp_reset_delay
bro.init
tcp_partial_close_delay
bro.init
non_analyzed_lifetime
bro.init
inactivity_timeout
bro.init
tcp_storm_thresh
bro.init
tcp_storm_interarrival_thresh
bro.init
tcp_reassembler_ports_orig
bro.init
tcp_reassembler_ports_resp
bro.init
table_expire_interval
bro.init
dns_session_timeout
bro.init
ntp_session_timeout
bro.init
rpc_timeout
bro.init
watchdog_interval
bro.init
heartbeat_interval
bro.init
anonymize_ip_addr
bro.init
omit_rewrite_place_holder
bro.init
rewriting_http_trace
bro.init
rewriting_smtp_trace
bro.init
code_red_log
code-red.bro
code_red_list1
code-red.bro
code_red_list2
code-red.bro
local_code_red_response_pgm
code-red.bro
remote_code_red_response_pgm
code-red.bro
have_FTP
conn.bro
have_SMTP
conn.bro
have_stats
conn.bro
hot_conns_reported
conn.bro
last_stat
conn.bro
last_stat_time
conn.bro
RPC_server_map
conn.bro
demux_dir
demux.bro
demuxed_conn
demux.bro
actually_rejected_PTR_anno
dns.bro
sensitive_lookup_hosts
dns.bro
okay_to_lookup_sensitive_hosts
dns.bro
dns_log
dns.bro
dns_sessions
dns.bro
num_dns_sessions
dns.bro
distinct_PTR_requests
dns.bro
distinct_rejected_PTR_requests
dns.bro
distinct_answered_PTR_requests
dns.bro
report_rejected_PTR_thresh
dns.bro
report_rejected_PTR_factor
dns.bro
allow_PTR_scans
dns.bro
did_PTR_scan_event
dns.bro
dns_interesting_changes
dns-mapping.bro
hot_names
finger.bro
max_finger_request_len
finger.bro
rewrite_finger_trace
finger.bro
ftp_log
ftp.bro
ftp_sessions
ftp.bro
ftp_guest_ids
ftp.bro
ftp_skip_hot
ftp.bro
ftp_hot_files
ftp.bro
ftp_hot_guest_files
ftp.bro
ftp_hot_cmds
ftp.bro
skip_unexpected
ftp.bro
skip_unexpected_net
ftp.bro
ftp_data_expected
ftp.bro
ftp_data_expected_session
ftp.bro
ftp_excessive_filename_len
ftp.bro
ftp_excessive_filename_trunc_len
ftp.bro
ftp_ignore_invalid_PORT
ftp.bro
ftp_ignore_privileged_PASVs
ftp.bro
same_local_net_is_spoof
hot.bro
allow_spoof_services
hot.bro
allow_pairs
hot.bro
allow_16_net_pairs
hot.bro
hot_srcs
hot.bro
hot_dsts
hot.bro
hot_src_24nets
hot.bro
hot_dst_24nets
hot.bro
allow_services
hot.bro
allow_services_to
hot.bro
allow_service_pairs
hot.bro
flag_successful_service
hot.bro
flag_successful_inbound_service
hot.bro
terminate_successful_inbound_service
hot.bro
flag_rejected_service
hot.bro
forbidden_ids
hot-ids.bro
forbidden_ids_if_no_password
hot-ids.bro
forbidden_id_patterns
hot-ids.bro
always_hot_ids
hot-ids.bro
hot_ids
hot-ids.bro
http_log
http.bro
http_sessions
http.bro
include_HTTP_abstract
http.bro
log_HTTP_data
http.bro
maintain_http_sessions
http.bro
process_HTTP_replies
http.bro
process_HTTP_data
http.bro
http_abstract_max_length
http-abstract.bro
skip_remote_sensitive_URIs
http-request.bro
have_skip_remote_sensitive_URIs
http-request.bro
sensitive_URIs
http-request.bro
worm_URIs
http-request.bro
sensitive_post_URIs
http-request.bro
icmp_flows
icmp.bro
hot_ident_ids
ident.bro
hot_ident_exceptions
ident.bro
public_ident_user_ids
ident.bro
public_ident_systems
ident.bro
rewrite_ident_trace
ident.bro
interconn_conns
interconn.bro
interconn_log
interconn.bro
interconn_min_interarrival
interconn.bro
interconn_max_interarrival
interconn.bro
interconn_max_keystroke_pkt_size
interconn.bro
interconn_default_pkt_size
interconn.bro
interconn_stat_period
interconn.bro
interconn_stat_backoff
interconn.bro
interconn_min_num_pkts
interconn.bro
interconn_min_duration
interconn.bro
interconn_ssh_len_disabled
interconn.bro
interconn_min_ssh_pkts_ratio
interconn.bro
interconn_min_bytes
interconn.bro
interconn_min_7bit_ascii_ratio
interconn.bro
interconn_min_num_lines
interconn.bro
interconn_min_normal_line_ratio
interconn.bro
interconn_min_alpha
interconn.bro
interconn_min_gamma
interconn.bro
interconn_standard_ports
interconn.bro
interconn_ignore_standard_ports
interconn.bro
interconn_demux_disabled
interconn.bro
input_trouble
login.bro
edited_input_trouble
login.bro
full_input_trouble
login.bro
input_wait_for_output
login.bro
output_trouble
login.bro
full_output_trouble
login.bro
backdoor_prompts
login.bro
non_backdoor_prompts
login.bro
hot_terminal_types
login.bro
hot_telnet_orig_ports
login.bro
skip_authentication
login.bro
login_prompts
login.bro
login_failure_msgs
login.bro
login_non_failure_msgs
login.bro
login_success_msgs
login.bro
login_timeouts
login.bro
router_prompts
login.bro
non_ASCII_hosts
login.bro
skip_logins_to
login.bro
always_hot_login_ids
login.bro
hot_login_ids
login.bro
rlogin_id_okay_if_no_password_exposed
login.bro
login_sessions
login.bro
mime_log
mime.bro
mime_sessions
mime.bro
check_relay_3
mime.bro
check_relay_4
mime.bro
excessive_ntp_request
ntp.bro
allow_excessive_ntp_requests
ntp.bro
port_names
port-names.bro
rpc_programs
portmapper.bro
NFS_services
portmapper.bro
RPC_okay
portmapper.bro
RPC_okay_nets
portmapper.bro
RPC_okay_services
portmapper.bro
NFS_world_servers
portmapper.bro
any_RPC_okay
portmapper.bro
RPC_dump_okay
portmapper.bro
RPC_do_not_complain
portmapper.bro
suppress_pm_log
portmapper.bro
rule_actions
rules.bro
rule_file
rules.bro
horiz_scan_thresholds
rules.bro
vert_scan_thresholds
rules.bro
suppress_scan_checks
scan.bro
report_peer_scan
scan.bro
report_outbound_peer_scan
scan.bro
num_distinct_peers
scan.bro
distinct_peers
scan.bro
num_distinct_ports
scan.bro
distinct_ports
scan.bro
report_port_scan
scan.bro
possible_port_scan_thresh
scan.bro
possible_scan_sources
scan.bro
num_scan_triples
scan.bro
scan_triples
scan.bro
accounts_tried
scan.bro
num_accounts_tried
scan.bro
report_accounts_tried
scan.bro
report_remote_accounts_tried
scan.bro
skip_accounts_tried
scan.bro
addl_web
scan.bro
skip_services
scan.bro
skip_outbound_services
scan.bro
skip_scan_sources
scan.bro
skip_scan_nets_16
scan.bro
skip_scan_nets_24
scan.bro
backscatter_ports
scan.bro
num_backscatter_peers
scan.bro
distinct_backscatter_peers
scan.bro
report_backscatter
scan.bro
root_servers
scan.bro
gtld_servers
scan.bro
local_nets
site.bro
local_16_nets
site.bro
local_24_nets
site.bro
neighbor_nets
site.bro
neighbor_16_nets
site.bro
local_mail_addr
smtp.bro
smtp_log
smtp.bro
smtp_sessions
smtp.bro
process_smtp_relay
smtp.bro
smtp_legal_cmds
smtp.bro
smtp_hot_cmds
smtp.bro
smtp_sensitive_cmds
smtp.bro
relay_log
smtp-relay.bro
smtp_relay_table
smtp-relay.bro
smtp_session_by_recipient
smtp-relay.bro
smtp_session_by_message_id
smtp-relay.bro
smtp_session_by_content_hash
smtp-relay.bro
software_file
software.bro
software_table
software.bro
software_ident_by_major
software.bro
ssh_log
ssh.bro
did_ssh_version
ssh.bro
step_log
stepping.bro
display_pairs
stepping.bro
tag_to_conn_map
stepping.bro
conn_tag_info
stepping.bro
detected_stones
stepping.bro
did_stone_summary
stepping.bro
stp_delta
stepping.bro
stp_idle_min
stepping.bro
stp_ratio_thresh
stepping.bro
stp_scale
stepping.bro
stp_common_host_thresh
stepping.bro
stp_random_pair_thresh
stepping.bro
stp_demux_disabled
stepping.bro
skip_clear_ssh_reports
stepping.bro
tftp_alert_count
tftp.bro
udp_req_count
udp.bro
udp_rep_count
udp.bro
udp_did_summary
udp.bro
weird_log
weird.bro
weird_action
weird.bro
weird_action_filters
weird.bro
weird_ignore_host
weird.bro
weird_do_not_ignore_repeats
weird.bro
worm_log
worm.bro
worm_list
worm.bro
worm_type_list
worm.bro
bro_log_file
Uncategorized
capture_filter
Uncategorized
direct_login_prompts
Uncategorized
discarder_maxlen
Uncategorized
done_with_network
Uncategorized
interfaces
Uncategorized
max_timer_expires
Uncategorized
restrict_filter
Uncategorized
capture_filter
Filtering
restrict_filter
Filtering
restrict_filter
to Filtering
capture_filter
to Filtering
port_names
The connection record
port_names
Connection functions
local_nets
Site variables
local_16_nets
Site variables
local_24_nets
Site variables
neighbor_nets
Site variables
neighbor_16_nets
Site variables
neighbor_24_nets
Site variables
same_local_net_is_spoof
hot variables
allow_spoof_services
hot variables
allow_pairs
hot variables
allow_16_net_pairs
hot variables
hot_srcs
hot variables
hot_dsts
hot variables
hot_src_24nets
hot variables
hot_dst_24nets
hot variables
allow_services
hot variables
allow_services_to
hot variables
allow_services_pairs
hot variables
flag_successful_service
hot variables
flag_successful_inbound_service
hot variables
terminate_successful_inbound_service
hot variables
flag_rejected_service
hot variables
report_peer_scan
scan variables
report_outbound_peer_scan
scan variables
possible_port_scan_thresh
scan variables
report_accounts_tried
scan variables
report_remote_accounts_tried
scan variables
skip_accounts_tried
scan variables
skip_outbound_services
scan variables
addl_web
scan variables
skip_scan_sources
scan variables
skip_scan_nets_24
scan variables
can_drop_connectivity
scan variables
shut_down_scans
scan variables
shut_down_all_scans
scan variables
shut_down_thresh
scan variables
never_shut_down
scan variables
port_names
The port-name Module
bro_log_file
The log Module
active_conn
The active Module
dns_interesting_changes
dns variables
hot_names
finger variables
max_request_length
finger variables
forbidden_ids
The hot-ids Module
forbidden_ids_if_no_password
The hot-ids Module
forbidden_id_patterns
The hot-ids Module
always_hot_ids
The hot-ids Module
hot_ids
The hot-ids Module
ftp_guest_ids
ftp variables
ftp_skip_hot
ftp variables
ftp_hot_files
ftp variables
ftp_not_actually_hot_files
ftp variables
ftp_hot_guest_files
ftp variables
skip_unexpected
ftp variables
skip_unexpected_net
ftp variables
sensitive_URIs
http variables
sensitive_post_URIs
http variables
hot_ident_ids
ident variables
hot_ident_exceptions
ident variables
input_trouble
login variables
edited_input_trouble
login variables
output_trouble
login variables
backdoor_prompts
login variables
non_backdoor_prompts
login variables
hot_terminal_types
login variables
hot_telnet_orig_ports
login variables
hot_ssh_orig_ports
login variables
skip_authentication
login variables
direct_login_prompts
login variables
login_prompts
login variables
login_failure_msgs
login variables
login_non_failure_msgs
login variables
router_prompts
login variables
login_success_msgs
login variables
login_timeouts
login variables
non_ASCII_hosts
login variables
skip_logins_to
login variables
always_hot_login_ids
login variables
hot_login_ids
login variables
rlogin_id_okay_if_no_password_exposed
login variables
rpc_programs
portmapper variables
NFS_services
portmapper variables
RPC_okay
portmapper variables
RPC_okay_nets
portmapper variables
RPC_okay_services
portmapper variables
NFS_world_servers
portmapper variables
RPC_dump_okay
portmapper variables
any_RPC_okay
portmapper variables
suppress_pm_log
portmapper variables
sig_actions
The signature Module
horiz_scan_thresholds
The signature Module
vert_scan_thresholds
The signature Module
ssl_compare_cipherspecs
SSL variables
ssl_analyze_certificates
SSL variables
ssl_store_certificates
SSL variables
ssl_store_cert_path
SSL variables
ssl_verify_certificates
SSL variables
x509_trusted_cert_path
SSL variables
ssl_max_cipherspec_size
SSL variables
ssl_store_key_material
SSL variables
weird_action
weird variables
weird_action_filters
weird variables
weird_ignore_host
weird variables
weird_do_not_ignore_repeats
weird variables
attributes
Attributes
constant
Statements
initialization
Initialization
local
Statements
modifiability
Modifiability
overview
Overview
redefining
Refinement
refinement
Refinement
scope
Statements
scoping
Scope
typing
Typing
version
The ssl_connection_info record
ssl_connection_info field
The ssl_connection_info record
version message
Flags
vert_scan_thresholds variable
rules.bro | The signature Module
vertical exploit scans
The signature Module
VMS input editing
login analyzer confusion | login analyzer confusion | login analyzer confusion
VMS login prompts
login analyzer confusion
\tt Username:
login analyzer confusion
VT666 terminal type backdoor
login variables
-W flag
Flags | Flags
walld
portmapper variables | portmapper variables | portmapper event handlers | portmapper event handlers
watchdog
Flags
watchdog timer expired
run-time error
Flags
WATCHDOG_INTERVAL internal variable
Flags
watchdog_interval variable
bro.init
``weird'' event
Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird | Events handled by conn_weird_addl | Events handled by conn_weird_addl | Events handled by conn_weird_addl | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by flow_weird | Events handled by net_weird | Events handled by net_weird | Events handled by net_weird | Events handled by net_weird | Events handled by net_weird | Events generated by the | Events generated by the
active_connection_reuse
Events handled by conn_weird
bad_HTTP_reply
Events handled by conn_weird
bad_HTTP_version
Events handled by conn_weird
bad_ICMP_checksum
Events handled by conn_weird
bad_ident_reply
Events handled by conn_weird_addl
bad_ident_request
Events handled by conn_weird_addl
bad_IP_checksum
Events handled by net_weird
bad_pm_port
Events generated by the
bad_rlogin_prolog
Events handled by conn_weird
bad_RPC
Events handled by conn_weird
bad_RPC_program
Events handled by conn_weird
bad_SYN_ack
Events handled by conn_weird
bad_TCP_checksum
Events handled by conn_weird
bad_TCP_header_len
Events handled by net_weird
bad_UDP_checksum
Events handled by conn_weird
baroque_SYN
Events handled by conn_weird
blank_in_HTTP_request
Events handled by conn_weird
connection_originator_SYN_ack
Events handled by conn_weird
data_after_reset
Events handled by conn_weird
data_before_established
Events handled by conn_weird
excess_RPC
Events handled by conn_weird
excessive_RPC_len
Events handled by conn_weird
excessively_large_fragment
Events handled by flow_weird
excessively_small_fragment
Events handled by flow_weird
FIN_advanced_last_seq
Events handled by conn_weird
FIN_after_reset
Events handled by conn_weird
FIN_storm
Events handled by conn_weird
fragment_inconsistency
Events handled by flow_weird
fragment_overlap
Events handled by flow_weird
fragment_protocol_inconsistency
Events handled by flow_weird
fragment_size_inconsistency
Events handled by flow_weird
fragment_with_DF
Events handled by flow_weird
HTTP_unknown_method
Events handled by conn_weird
HTTP_version_mismatch
Events handled by conn_weird
ident_request_addendum
Events handled by conn_weird_addl
inappropriate_FIN
Events handled by conn_weird
incompletely_captured_fragment
Events handled by flow_weird
internally_truncated_header
Events handled by net_weird
Land_attack
Events generated by the
multiple_HTTP_request_elements
Events handled by conn_weird
multiple_RPCs
Events handled by conn_weird
NUL_in_line
Events handled by conn_weird
originator_RPC_reply
Events handled by conn_weird
partial_finger_request
Events handled by conn_weird
partial_ftp_request
Events handled by conn_weird
partial_ident_request
Events handled by conn_weird
partial_portmapper_request
Events handled by conn_weird
partial_RPC
Events handled by conn_weird
pending_data_when_closed
Events handled by conn_weird
possible_split_routing
Events handled by conn_weird
premature_connection_reuse
Events handled by conn_weird
repeated_SYN_reply_wo_ack
Events handled by conn_weird
repeated_SYN_with_ack
Events handled by conn_weird
responder_RPC_call
Events handled by conn_weird
rlogin_text_after_rejected
Events handled by conn_weird
RPC_rexmit_inconsistency
Events handled by conn_weird
RST_storm
Events handled by conn_weird
RST_with_data
Events handled by conn_weird
simultaneous_open
Events handled by conn_weird
spontaneous_FIN
Events handled by conn_weird
spontaneous_RST
Events handled by conn_weird
SYN_after_close
Events handled by conn_weird
SYN_after_partial
Events handled by conn_weird
SYN_after_reset
Events handled by conn_weird
SYN_inside_connection
Events handled by conn_weird
SYN_seq_jump
Events handled by conn_weird
SYN_with_data
Events handled by conn_weird
TCP_christmas
Events handled by conn_weird
truncated_header
Events handled by net_weird
truncated_IP
Events handled by net_weird
UDP_datagram_length_mismatch
Events handled by conn_weird
unpaired_RPC_response
Events handled by conn_weird
unsolicited_SYN_response
Events handled by conn_weird
weird event summary file
The weird Module
weird events
The weird Module to Additional handlers for ``weird''
actions
Actions for ``weird'' events
additional handlers
Additional handlers for ``weird''
generated by standard scripts
Events generated by the
handled by conn_weird
Events handled by conn_weird
handled by conn_weird_addl
Events handled by conn_weird_addl
handled by flow_weird
Events handled by flow_weird
handled by net_weird
Events handled by net_weird
prevalence in actual network traffic
The weird Module
weird module
The weird Module
weird_action variable
weird.bro | weird variables
weird_action_filters variable
weird.bro | weird variables
weird_do_not_ignore_repeats variable
weird.bro | weird variables
WEIRD_FILE action
Actions for ``weird'' events
WEIRD_IGNORE action
Actions for ``weird'' events
weird_ignore_host variable
weird.bro | weird variables
weird_log variable
weird.bro
WEIRD_LOG_ALWAYS action
Actions for ``weird'' events
WEIRD_LOG_ONCE action
Actions for ``weird'' events
WEIRD_LOG_PER_CONN action
Actions for ``weird'' events
WEIRD_LOG_PER_ORIG action
Actions for ``weird'' events
WEIRD_UNSPECIFIED action
Actions for ``weird'' events
whitespace
in statements
Statements
width
of formatted strings
Predefined Functions
Windows
not supported
Supported platforms
worm_list variable
worm.bro
worm_log variable
worm.bro
worm_type_list variable
worm.bro
worm_URIs variable
http-request.bro
write file
control over what's recorded
Predefined Functions
&write_expire attribute
Table Attributes
writing tcpdump files
Flags
wrong number of fmt arguments
Predefined Functions
wrong number of fmt arguments
run-time error
Predefined Functions
wrong number of length arguments
run-time error
Predefined Functions
www.anticode.com
login variables
wwwroot sensitive POST URI
http variables
x509 record
no title | The x509 record
x509_trusted_cert_path variable
SSL variables
yield
of a table
Tables
ypserv
portmapper variables



Vern Paxson 2004-03-21