diff --git a/bro-path-dev.in b/bro-path-dev.in index 394462924d..5499f48860 100755 --- a/bro-path-dev.in +++ b/bro-path-dev.in @@ -10,12 +10,12 @@ # BROPATH=`./bro-path-dev` ./src/bro # -broPolicies=${PROJECT_SOURCE_DIR}/policy:${PROJECT_SOURCE_DIR}/policy/sigs:${PROJECT_SOURCE_DIR}/policy/time-machine +broPolicies=${PROJECT_SOURCE_DIR}/policy:${PROJECT_SOURCE_DIR}/policy/frameworks:${PROJECT_SOURCE_DIR}/policy/protocols:${PROJECT_SOURCE_DIR}/policy/detectors:${PROJECT_SOURCE_DIR}/policy/time-machine broGenPolicies=${CMAKE_BINARY_DIR}/src broctlPolicies=${PROJECT_SOURCE_DIR}/aux/broctl/policy:${CMAKE_BINARY_DIR}/aux/broctl/policy/local -installedPolicies=${POLICYDIR}:${POLICYDIR}/sigs:${POLICYDIR}/time-machine:${POLICYDIR}/site +installedPolicies=${POLICYDIR}:${POLICYDIR}/frameworks:${POLICYDIR}/protocols:${POLICYDIR}/detectors:${POLICYDIR}/time-machine:${POLICYDIR}/site echo .:$broPolicies:$broGenPolicies:$broctlPolicies diff --git a/policy/dpd.bro b/policy/frameworks/dpd.bro similarity index 100% rename from policy/dpd.bro rename to policy/frameworks/dpd.bro diff --git a/policy/dpd/base.bro b/policy/frameworks/dpd/base.bro similarity index 100% rename from policy/dpd/base.bro rename to policy/frameworks/dpd/base.bro diff --git a/policy/dpd/dpd.sig b/policy/frameworks/dpd/dpd.sig similarity index 100% rename from policy/dpd/dpd.sig rename to policy/frameworks/dpd/dpd.sig diff --git a/policy/dpd/dyn-disable.bro b/policy/frameworks/dpd/dyn-disable.bro similarity index 100% rename from policy/dpd/dyn-disable.bro rename to policy/frameworks/dpd/dyn-disable.bro diff --git a/policy/dpd/packet-segment-logging.bro b/policy/frameworks/dpd/packet-segment-logging.bro similarity index 100% rename from policy/dpd/packet-segment-logging.bro rename to policy/frameworks/dpd/packet-segment-logging.bro diff --git a/policy/logging-ascii.bro b/policy/frameworks/logging-ascii.bro similarity index 100% rename from policy/logging-ascii.bro rename to policy/frameworks/logging-ascii.bro diff --git a/policy/logging.bro b/policy/frameworks/logging.bro similarity index 100% rename from policy/logging.bro rename to policy/frameworks/logging.bro diff --git a/policy/metrics.bro b/policy/frameworks/metrics.bro similarity index 100% rename from policy/metrics.bro rename to policy/frameworks/metrics.bro diff --git a/policy/metrics/base.bro b/policy/frameworks/metrics/base.bro similarity index 100% rename from policy/metrics/base.bro rename to policy/frameworks/metrics/base.bro diff --git a/policy/metrics/conn-example.bro b/policy/frameworks/metrics/conn-example.bro similarity index 100% rename from policy/metrics/conn-example.bro rename to policy/frameworks/metrics/conn-example.bro diff --git a/policy/metrics/http-example.bro b/policy/frameworks/metrics/http-example.bro similarity index 100% rename from policy/metrics/http-example.bro rename to policy/frameworks/metrics/http-example.bro diff --git a/policy/signatures.bro b/policy/frameworks/signatures.bro similarity index 100% rename from policy/signatures.bro rename to policy/frameworks/signatures.bro diff --git a/policy/signatures/base.bro b/policy/frameworks/signatures/base.bro similarity index 100% rename from policy/signatures/base.bro rename to policy/frameworks/signatures/base.bro diff --git a/policy/signatures/detect-windows-shells.sig b/policy/frameworks/signatures/detect-windows-shells.sig similarity index 100% rename from policy/signatures/detect-windows-shells.sig rename to policy/frameworks/signatures/detect-windows-shells.sig diff --git a/policy/software.bro b/policy/frameworks/software.bro similarity index 100% rename from policy/software.bro rename to policy/frameworks/software.bro diff --git a/policy/software/base.bro b/policy/frameworks/software/base.bro similarity index 100% rename from policy/software/base.bro rename to policy/frameworks/software/base.bro diff --git a/policy/software/vulnerable.bro b/policy/frameworks/software/vulnerable.bro similarity index 100% rename from policy/software/vulnerable.bro rename to policy/frameworks/software/vulnerable.bro diff --git a/policy/conn.bro b/policy/protocols/conn.bro similarity index 100% rename from policy/conn.bro rename to policy/protocols/conn.bro diff --git a/policy/conn/base.bro b/policy/protocols/conn/base.bro similarity index 100% rename from policy/conn/base.bro rename to policy/protocols/conn/base.bro diff --git a/policy/conn/contents.bro b/policy/protocols/conn/contents.bro similarity index 100% rename from policy/conn/contents.bro rename to policy/protocols/conn/contents.bro diff --git a/policy/known-hosts.bro b/policy/protocols/conn/known-hosts.bro similarity index 100% rename from policy/known-hosts.bro rename to policy/protocols/conn/known-hosts.bro diff --git a/policy/known-services.bro b/policy/protocols/conn/known-services.bro similarity index 100% rename from policy/known-services.bro rename to policy/protocols/conn/known-services.bro diff --git a/policy/dns.bro b/policy/protocols/dns.bro similarity index 100% rename from policy/dns.bro rename to policy/protocols/dns.bro diff --git a/policy/dns/auth-addl.bro b/policy/protocols/dns/auth-addl.bro similarity index 100% rename from policy/dns/auth-addl.bro rename to policy/protocols/dns/auth-addl.bro diff --git a/policy/dns/base.bro b/policy/protocols/dns/base.bro similarity index 100% rename from policy/dns/base.bro rename to policy/protocols/dns/base.bro diff --git a/policy/dns/consts.bro b/policy/protocols/dns/consts.bro similarity index 100% rename from policy/dns/consts.bro rename to policy/protocols/dns/consts.bro diff --git a/policy/dns/detect.bro b/policy/protocols/dns/detect.bro similarity index 100% rename from policy/dns/detect.bro rename to policy/protocols/dns/detect.bro diff --git a/policy/dns/passive-replication.bro b/policy/protocols/dns/passive-replication.bro similarity index 100% rename from policy/dns/passive-replication.bro rename to policy/protocols/dns/passive-replication.bro diff --git a/policy/ftp.bro b/policy/protocols/ftp.bro similarity index 100% rename from policy/ftp.bro rename to policy/protocols/ftp.bro diff --git a/policy/ftp/base.bro b/policy/protocols/ftp/base.bro similarity index 100% rename from policy/ftp/base.bro rename to policy/protocols/ftp/base.bro diff --git a/policy/ftp/detect.bro b/policy/protocols/ftp/detect.bro similarity index 100% rename from policy/ftp/detect.bro rename to policy/protocols/ftp/detect.bro diff --git a/policy/ftp/file-extract.bro b/policy/protocols/ftp/file-extract.bro similarity index 100% rename from policy/ftp/file-extract.bro rename to policy/protocols/ftp/file-extract.bro diff --git a/policy/ftp/software.bro b/policy/protocols/ftp/software.bro similarity index 100% rename from policy/ftp/software.bro rename to policy/protocols/ftp/software.bro diff --git a/policy/ftp/utils-commands.bro b/policy/protocols/ftp/utils-commands.bro similarity index 100% rename from policy/ftp/utils-commands.bro rename to policy/protocols/ftp/utils-commands.bro diff --git a/policy/http.bro b/policy/protocols/http.bro similarity index 100% rename from policy/http.bro rename to policy/protocols/http.bro diff --git a/policy/http/base-extended.bro b/policy/protocols/http/base-extended.bro similarity index 100% rename from policy/http/base-extended.bro rename to policy/protocols/http/base-extended.bro diff --git a/policy/http/base.bro b/policy/protocols/http/base.bro similarity index 100% rename from policy/http/base.bro rename to policy/protocols/http/base.bro diff --git a/policy/http/detect-intel.bro b/policy/protocols/http/detect-intel.bro similarity index 100% rename from policy/http/detect-intel.bro rename to policy/protocols/http/detect-intel.bro diff --git a/policy/http/detect-sqli.bro b/policy/protocols/http/detect-sqli.bro similarity index 100% rename from policy/http/detect-sqli.bro rename to policy/protocols/http/detect-sqli.bro diff --git a/policy/http/detect-webapps.bro b/policy/protocols/http/detect-webapps.bro similarity index 100% rename from policy/http/detect-webapps.bro rename to policy/protocols/http/detect-webapps.bro diff --git a/policy/http/detect-webapps.sig b/policy/protocols/http/detect-webapps.sig similarity index 100% rename from policy/http/detect-webapps.sig rename to policy/protocols/http/detect-webapps.sig diff --git a/policy/http/file-extract.bro b/policy/protocols/http/file-extract.bro similarity index 100% rename from policy/http/file-extract.bro rename to policy/protocols/http/file-extract.bro diff --git a/policy/http/file-hash.bro b/policy/protocols/http/file-hash.bro similarity index 100% rename from policy/http/file-hash.bro rename to policy/protocols/http/file-hash.bro diff --git a/policy/http/file-ident.bro b/policy/protocols/http/file-ident.bro similarity index 100% rename from policy/http/file-ident.bro rename to policy/protocols/http/file-ident.bro diff --git a/policy/http/file-ident.sig b/policy/protocols/http/file-ident.sig similarity index 100% rename from policy/http/file-ident.sig rename to policy/protocols/http/file-ident.sig diff --git a/policy/http/headers.bro b/policy/protocols/http/headers.bro similarity index 100% rename from policy/http/headers.bro rename to policy/protocols/http/headers.bro diff --git a/policy/http/software.bro b/policy/protocols/http/software.bro similarity index 100% rename from policy/http/software.bro rename to policy/protocols/http/software.bro diff --git a/policy/http/utils.bro b/policy/protocols/http/utils.bro similarity index 100% rename from policy/http/utils.bro rename to policy/protocols/http/utils.bro diff --git a/policy/http/var-extraction-cookies.bro b/policy/protocols/http/var-extraction-cookies.bro similarity index 100% rename from policy/http/var-extraction-cookies.bro rename to policy/protocols/http/var-extraction-cookies.bro diff --git a/policy/http/var-extraction-uri.bro b/policy/protocols/http/var-extraction-uri.bro similarity index 100% rename from policy/http/var-extraction-uri.bro rename to policy/protocols/http/var-extraction-uri.bro diff --git a/policy/irc.bro b/policy/protocols/irc.bro similarity index 100% rename from policy/irc.bro rename to policy/protocols/irc.bro diff --git a/policy/irc/base.bro b/policy/protocols/irc/base.bro similarity index 100% rename from policy/irc/base.bro rename to policy/protocols/irc/base.bro diff --git a/policy/irc/dcc-send.bro b/policy/protocols/irc/dcc-send.bro similarity index 100% rename from policy/irc/dcc-send.bro rename to policy/protocols/irc/dcc-send.bro diff --git a/policy/mime.bro b/policy/protocols/mime.bro similarity index 100% rename from policy/mime.bro rename to policy/protocols/mime.bro diff --git a/policy/mime/base.bro b/policy/protocols/mime/base.bro similarity index 100% rename from policy/mime/base.bro rename to policy/protocols/mime/base.bro diff --git a/policy/mime/file-extract.bro b/policy/protocols/mime/file-extract.bro similarity index 100% rename from policy/mime/file-extract.bro rename to policy/protocols/mime/file-extract.bro diff --git a/policy/mime/file-hash.bro b/policy/protocols/mime/file-hash.bro similarity index 100% rename from policy/mime/file-hash.bro rename to policy/protocols/mime/file-hash.bro diff --git a/policy/mime/file-ident.bro b/policy/protocols/mime/file-ident.bro similarity index 100% rename from policy/mime/file-ident.bro rename to policy/protocols/mime/file-ident.bro diff --git a/policy/smtp.bro b/policy/protocols/smtp.bro similarity index 100% rename from policy/smtp.bro rename to policy/protocols/smtp.bro diff --git a/policy/smtp/base-extended.bro b/policy/protocols/smtp/base-extended.bro similarity index 100% rename from policy/smtp/base-extended.bro rename to policy/protocols/smtp/base-extended.bro diff --git a/policy/smtp/base.bro b/policy/protocols/smtp/base.bro similarity index 100% rename from policy/smtp/base.bro rename to policy/protocols/smtp/base.bro diff --git a/policy/smtp/detect.bro b/policy/protocols/smtp/detect.bro similarity index 100% rename from policy/smtp/detect.bro rename to policy/protocols/smtp/detect.bro diff --git a/policy/smtp/software.bro b/policy/protocols/smtp/software.bro similarity index 100% rename from policy/smtp/software.bro rename to policy/protocols/smtp/software.bro diff --git a/policy/smtp/utils.bro b/policy/protocols/smtp/utils.bro similarity index 100% rename from policy/smtp/utils.bro rename to policy/protocols/smtp/utils.bro diff --git a/policy/smtp/webmail-ident.bro b/policy/protocols/smtp/webmail-ident.bro similarity index 100% rename from policy/smtp/webmail-ident.bro rename to policy/protocols/smtp/webmail-ident.bro diff --git a/policy/ssh.bro b/policy/protocols/ssh.bro similarity index 100% rename from policy/ssh.bro rename to policy/protocols/ssh.bro diff --git a/policy/ssh/base.bro b/policy/protocols/ssh/base.bro similarity index 100% rename from policy/ssh/base.bro rename to policy/protocols/ssh/base.bro diff --git a/policy/ssh/software.bro b/policy/protocols/ssh/software.bro similarity index 100% rename from policy/ssh/software.bro rename to policy/protocols/ssh/software.bro diff --git a/policy/ssl-ciphers.bro b/policy/protocols/ssl-ciphers.bro similarity index 100% rename from policy/ssl-ciphers.bro rename to policy/protocols/ssl-ciphers.bro diff --git a/policy/ssl-errors.bro b/policy/protocols/ssl-errors.bro similarity index 100% rename from policy/ssl-errors.bro rename to policy/protocols/ssl-errors.bro diff --git a/policy/ssl.bro b/policy/protocols/ssl.bro similarity index 100% rename from policy/ssl.bro rename to policy/protocols/ssl.bro diff --git a/policy/server-ports.bro b/policy/server-ports.bro deleted file mode 100644 index 5645b6c716..0000000000 --- a/policy/server-ports.bro +++ /dev/null @@ -1,70 +0,0 @@ -# $Id: server-ports.bro,v 1.1.2.1 2006/05/31 23:19:07 sommer Exp $ -# -# Automatically-loaded script which sets defaults for likely server ports. - -redef likely_server_ports += { - - ### TCP - - 21/tcp, - 22/tcp, - 23/tcp, - 25/tcp, - 587/tcp, - 513/tcp, - 79/tcp, - 113/tcp, - 80/tcp, - 8080/tcp, - 8000/tcp, - 8888/tcp, - 3128/tcp, - 53/tcp, - 111/tcp, - 139/tcp, - 6346/tcp, - 8436/tcp, - 135/tcp, - 445/tcp, - 110/tcp, - 6666/tcp, - 6667/tcp, - - # SSL-relatd ports/tcp, - 443/tcp, - 563/tcp, - 585/tcp, - 614/tcp, - 636/tcp, - 989/tcp, - 990/tcp, - 992/tcp, - 993/tcp, - 994/tcp, - 995/tcp, - 8443/tcp, - - # Not analyzed (yet), but give a hint which side the server is. - 143/tcp, # IMAP - 497/tcp, # Dantz - 515/tcp, # LPD - 524/tcp, # Netware core protocol - 631/tcp, # IPP - 1521/tcp, # Oracle SQL - 2049/tcp, # NFS - 5730/tcp, # Calendar - 6000/tcp, # X11 - 6001/tcp, # X11 - 16384/tcp, # Connected Backup - - ### UDP - - 53/udp, - 111/udp, - 123/udp, - 137/udp, - 138/udp, - 161/udp, - 427/udp, # srvloc - 2049/udp, # NFS -};