mirror of
https://github.com/zeek/zeek.git
synced 2025-10-13 20:18:20 +00:00
Initial implementation of Lower-Level analyzers
This commit is contained in:
parent
f744d4c070
commit
b2e6c9ac9a
146 changed files with 3967 additions and 613 deletions
1
scripts/base/llprotocols/linux_sll/__load__.zeek
Normal file
1
scripts/base/llprotocols/linux_sll/__load__.zeek
Normal file
|
@ -0,0 +1 @@
|
|||
@load ./main
|
12
scripts/base/llprotocols/linux_sll/main.zeek
Normal file
12
scripts/base/llprotocols/linux_sll/main.zeek
Normal file
|
@ -0,0 +1,12 @@
|
|||
module LL_LINUX_SLL;
|
||||
|
||||
const DLT_LINUX_SLL : count = 113;
|
||||
|
||||
redef LLAnalyzer::config_map += {
|
||||
LLAnalyzer::ConfigEntry($identifier=DLT_LINUX_SLL, $analyzer=LLAnalyzer::LLANALYZER_LINUXSLL),
|
||||
LLAnalyzer::ConfigEntry($parent=LLAnalyzer::LLANALYZER_LINUXSLL, $identifier=0x0800, $analyzer=LLAnalyzer::LLANALYZER_IPV4),
|
||||
LLAnalyzer::ConfigEntry($parent=LLAnalyzer::LLANALYZER_LINUXSLL, $identifier=0x86DD, $analyzer=LLAnalyzer::LLANALYZER_IPV6),
|
||||
LLAnalyzer::ConfigEntry($parent=LLAnalyzer::LLANALYZER_LINUXSLL, $identifier=0x0806, $analyzer=LLAnalyzer::LLANALYZER_ARP),
|
||||
# RARP
|
||||
LLAnalyzer::ConfigEntry($parent=LLAnalyzer::LLANALYZER_LINUXSLL, $identifier=0x8035, $analyzer=LLAnalyzer::LLANALYZER_ARP)
|
||||
};
|
Loading…
Add table
Add a link
Reference in a new issue