Re: duplicated intel logs DNS::IN_REQUEST

Justin Azoff <[email protected]> Fri, 4 Oct 2019 13:19:08 -0400
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAPfnCugzEbPtLqsLgQartOcvi6Z2OTVSgNerTyMs0KMNW7wuQQ@mail.gmail.com>
On Fri, Oct 4, 2019 at 4:08 AM Palumbo Mauro <[email protected]>
wrote:

> Hi Justin,
>
>    I am in fact seeing 2,2 or 2,0 as orig_pkts and resp_pkts. And I
> confirmed this with tcpdump. So I believe it is an issue with the network
> we are tapping as I see these duplicated packets only for dns.
>

Possibly, but you may have duplicates everywhere.  The tcp reassembler can
use the sequence numbers to avoid analyzing the same traffic twice, but UDP
doesn't have anything like that.  DNS is just the place you tend to notice
the duplicate traffic the most.


-- 
Justin

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek