Re: dpd framework and DCE_RPC/NTLM analyzers
Jon Siwek <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAMzgZ0Jgt4L3Yw6atGTwx4YANhBw1cGsE75tOOEyymaBvqHoKQ@mail.gmail.com> |
On Thu, Jul 11, 2019 at 1:20 AM Palumbo Mauro <[email protected]> wrote: > is there any particular reason why the DCE_RPC/NTLM protocols are disabled by default in the DPD framework? (both protocols are in DPD::ignore_violations). Being in DPD::ignore_violations doesn't exactly mean "DPD is disabled for those analyzers". It's more like "if an analyzer has previously issued a protocol confirmation signal, but later issues a protocol violation signal, then disable that analyzer except if it's in DPD::ignore_violations". So it's actually used to prevent the disabling of analyzers. However, I don't know the origins of DPD::ignore_violations, why it works that way, or why the DCE_RPC/NTLM protocols are in that set. - Jon _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek