Re: duplicated intel logs DNS::IN_REQUEST
Justin Azoff <[email protected]> Fri, 4 Oct 2019 13:19:08 -0400
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAPfnCugzEbPtLqsLgQartOcvi6Z2OTVSgNerTyMs0KMNW7wuQQ@mail.gmail.com> |
On Fri, Oct 4, 2019 at 4:08 AM Palumbo Mauro <[email protected]> wrote: > Hi Justin, > > I am in fact seeing 2,2 or 2,0 as orig_pkts and resp_pkts. And I > confirmed this with tcpdump. So I believe it is an issue with the network > we are tapping as I see these duplicated packets only for dns. > Possibly, but you may have duplicates everywhere. The tcp reassembler can use the sequence numbers to avoid analyzing the same traffic twice, but UDP doesn't have anything like that. DNS is just the place you tend to notice the duplicate traffic the most. -- Justin _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek