mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00
Add basic LLC, SNAP, and Novell 802.3 packet analyzers
This commit is contained in:
parent
31afe082ac
commit
7e88a2b3fb
30 changed files with 527 additions and 171 deletions
|
@ -20,6 +20,9 @@
|
|||
@load base/packet-protocols/udp
|
||||
@load base/packet-protocols/tcp
|
||||
@load base/packet-protocols/icmp
|
||||
@load base/packet-protocols/llc
|
||||
@load base/packet-protocols/novell_802_3
|
||||
@load base/packet-protocols/snap
|
||||
|
||||
@load base/packet-protocols/gre
|
||||
@load base/packet-protocols/iptunnel
|
||||
|
|
1
scripts/base/packet-protocols/llc/__load__.zeek
Normal file
1
scripts/base/packet-protocols/llc/__load__.zeek
Normal file
|
@ -0,0 +1 @@
|
|||
@load ./main
|
1
scripts/base/packet-protocols/llc/main.zeek
Normal file
1
scripts/base/packet-protocols/llc/main.zeek
Normal file
|
@ -0,0 +1 @@
|
|||
module PacketAnalyzer::LLC;
|
1
scripts/base/packet-protocols/novell_802_3/__load__.zeek
Normal file
1
scripts/base/packet-protocols/novell_802_3/__load__.zeek
Normal file
|
@ -0,0 +1 @@
|
|||
@load ./main
|
6
scripts/base/packet-protocols/novell_802_3/main.zeek
Normal file
6
scripts/base/packet-protocols/novell_802_3/main.zeek
Normal file
|
@ -0,0 +1,6 @@
|
|||
module PacketAnalyzer::NOVELL_802_3;
|
||||
|
||||
export {
|
||||
# The Novell 802.3 protocol should expect an IPX analyzer here. Since
|
||||
# one doesn't exist yet, the default analyzer is left undefined.
|
||||
}
|
1
scripts/base/packet-protocols/snap/__load__.zeek
Normal file
1
scripts/base/packet-protocols/snap/__load__.zeek
Normal file
|
@ -0,0 +1 @@
|
|||
@load ./main
|
9
scripts/base/packet-protocols/snap/main.zeek
Normal file
9
scripts/base/packet-protocols/snap/main.zeek
Normal file
|
@ -0,0 +1,9 @@
|
|||
module PacketAnalyzer::SNAP;
|
||||
|
||||
event zeek_init() &priority=20
|
||||
{
|
||||
PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_SNAP, 0x0800, PacketAnalyzer::ANALYZER_IP);
|
||||
PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_SNAP, 0x86DD, PacketAnalyzer::ANALYZER_IP);
|
||||
PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_SNAP, 0x0806, PacketAnalyzer::ANALYZER_ARP);
|
||||
PacketAnalyzer::register_packet_analyzer(PacketAnalyzer::ANALYZER_SNAP, 0x8035, PacketAnalyzer::ANALYZER_ARP);
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue