Re: dpd framework and DCE_RPC/NTLM analyzers

Jon Siwek <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAMzgZ0Jgt4L3Yw6atGTwx4YANhBw1cGsE75tOOEyymaBvqHoKQ@mail.gmail.com>
On Thu, Jul 11, 2019 at 1:20 AM Palumbo Mauro <[email protected]> wrote:

>    is there any particular reason why the  DCE_RPC/NTLM protocols are disabled by default in the DPD framework? (both protocols are in DPD::ignore_violations).

Being in DPD::ignore_violations doesn't exactly mean "DPD is disabled
for those analyzers".  It's more like "if an analyzer has previously
issued a protocol confirmation signal, but later issues a protocol
violation signal, then disable that analyzer except if it's in
DPD::ignore_violations".  So it's actually used to prevent the
disabling of analyzers.

However, I don't know the origins of DPD::ignore_violations, why it
works that way, or why the DCE_RPC/NTLM protocols are in that set.

- Jon
_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.