Field "state" from Argus (ra)

Mauricio Reis <[email protected]> Thu, 10 May 2018 12:38:41 -0300
Newsgroups gmane.network.argus
Message-ID <CAHCPJrJAF0A8cd-oNXyJV7Ky-SkMu8TY-EK3GGF_0vowX8ofsQ@mail.gmail.com>
> I'm working on the binetflow extension files available on the CTU-13 site (
> link
> <https://mcfp.weebly.com/the-ctu-13-dataset-a-labeled-dataset-with-botnet-normal-and-background-traffic.html>),
> which was generated by Argus with the "ra" option according to what I was
> able to verify (see link <http://dx.doi.org/10.1016/j.cose.2014.05.011>).
>
> I'd like to understand the values of the "state" field. The documentation
> I accessed (link <http://qosient.com/argus/man/man1/ra.1.pdf>) describes
> only some of the values I found (for example: ECO, ECR, IRQ, IRR, MAS, MHR,
> MRQ, MSR, NNA, NNS, NRA, NRS, PAR, PTB, RED, RTA, RTS, SRC, TSR, TST, TXD,
> URCUT, URF, URFIL, URH, URHPRO, URHTOS, URHU, URISO, URN, URNPRO, URNTOS,
> URNU, URP, URPRE, URS). But I could not understand the meaning of values
> like: FRPA, FSRAEC, RPA, SRA, etc - and combinations like: A_FRA,
> FSRPAEC_FSRPA, RPA_SA, SPAC_FSRPA.
>
> Would you help me?
>
> Att.,
> Mauricio Reis
>