Snort++ dynamic inspector questions

Henry Foster <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CAFUoUDcLuGOd6jxdto0w-81Fawzf8ckKg-pQ9LpE_5oVjq4iBg@mail.gmail.com>
Hi all,

I'm working on writing a dynamic Snort++ inspector to reassemble MPTCP
streams.  I've been doing my best to RTFS, but was hoping someone could
help me with a couple questions. I feel like the answers are probably
pretty obvious, but I've been having trouble figuring them out.

1. Is it possible to craft and submit a pseudopacket for detection from a
dynamic plug-in?
I took a look at the TCP stream source and it looks like
Snort::detect_rebuilt_packet would be a good thing to use, but I'm not sure
how to go about calling it from a dynamic plug-in. I don't suppose there's
an API for submitting rebuilt packets?  Currently, for testing, I'm
overwriting the data pointer of the actual packet (p) that gets passed to the
plug-in, but doing this makes me feel dirty inside.

2. What's the best way to get all the TCP packets to my plugin?
I started with the DPX example and have been building on top of it.
Currently, I'm using IT_NETWORK and PktType::TCP, however, I've noticed
that my plugin's eval() is not getting called with ACKs / non-payload
segments from the tcp receiver -> tcp initiator. I'd like to receive all
the packets as there's some MPTCP control information that's included in
the options field of those ACK packets: I want to keep track of a nonce
that is sent when additional subflows are joining a MPTCP connection (in
the SYN/ACK of the handshake), and mptcp data sequence mappings that are
sent sometimes sent in ACKs.

Disclaimer: Right now, I'm just trying to prototype this out. The actual
plug-in code does very little work; I use Protocol Buffers to ship off the
parts of the header I need to a server written in Python that does the
actual reassembly.

Thanks!

-Henry

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity 
planning reports. http://sdm.link/zohodev2dev

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.