Field "state" from Argus (ra)
Mauricio Reis <[email protected]> Thu, 10 May 2018 12:38:41 -0300
| Newsgroups | gmane.network.argus |
|---|---|
| Message-ID | <CAHCPJrJAF0A8cd-oNXyJV7Ky-SkMu8TY-EK3GGF_0vowX8ofsQ@mail.gmail.com> |
> I'm working on the binetflow extension files available on the CTU-13 site ( > link > <https://mcfp.weebly.com/the-ctu-13-dataset-a-labeled-dataset-with-botnet-normal-and-background-traffic.html>), > which was generated by Argus with the "ra" option according to what I was > able to verify (see link <http://dx.doi.org/10.1016/j.cose.2014.05.011>). > > I'd like to understand the values of the "state" field. The documentation > I accessed (link <http://qosient.com/argus/man/man1/ra.1.pdf>) describes > only some of the values I found (for example: ECO, ECR, IRQ, IRR, MAS, MHR, > MRQ, MSR, NNA, NNS, NRA, NRS, PAR, PTB, RED, RTA, RTS, SRC, TSR, TST, TXD, > URCUT, URF, URFIL, URH, URHPRO, URHTOS, URHU, URISO, URN, URNPRO, URNTOS, > URNU, URP, URPRE, URS). But I could not understand the meaning of values > like: FRPA, FSRAEC, RPA, SRA, etc - and combinations like: A_FRA, > FSRPAEC_FSRPA, RPA_SA, SPAC_FSRPA. > > Would you help me? > > Att., > Mauricio Reis >