zeek/testing/btest/Baseline/scripts.policy.frameworks.intel.seen.certs/intel-all.log
Johanna Amann 3bce313b12 Switch file UID hashing from md5 to highwayhash.
This commit switches UID hashing from md5 to a highway hash. It also
moves the salt value out of the file plugin - and makes it
installation-specific instead - it is moved to the global namespace.

There now are digest hash functions to make "static"
installation-specific hashes that are stable over workers available to
everyone; hashes can be 64, 128 or 256 bits in size.

Due to the fact that we switch the file hashing algorithm, all file
hashes change.

The underlyigng algorithm that is used for hashing is highwayhash-128,
which is significantly faster than md5.
2020-04-30 10:20:09 -07:00

25 lines
2.2 KiB
Text

#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path intel
#open 2020-04-30-00-48-03
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p seen.indicator seen.indicator_type seen.where seen.node matched sources fuid file_mime_type file_desc
#types time string addr port addr port string enum enum string set[enum] set[string] string string string
1416942644.593119 CHhAvVGS1DHFjwGM9 192.168.4.149 49422 23.92.19.75 443 www.pantz.org Intel::DOMAIN X509::IN_CERT zeek Intel::DOMAIN source1 FMSZyB2PMaf4sHLjE1 application/x-x509-user-cert 23.92.19.75:443/tcp
#close 2020-04-30-00-48-04
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path intel
#open 2020-04-30-00-48-04
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p seen.indicator seen.indicator_type seen.where seen.node matched sources fuid file_mime_type file_desc
#types time string addr port addr port string enum enum string set[enum] set[string] string string string
1170717505.735416 CHhAvVGS1DHFjwGM9 192.150.187.164 58868 194.127.84.106 443 2c322ae2b7fe91391345e070b63668978bb1c9da Intel::CERT_HASH X509::IN_CERT zeek Intel::CERT_HASH source1 FaPs2M3vQdQYOJSlia application/x-x509-user-cert 194.127.84.106:443/tcp
1170717505.934612 CHhAvVGS1DHFjwGM9 192.150.187.164 58868 194.127.84.106 443 www.dresdner-privat.de Intel::DOMAIN X509::IN_CERT zeek Intel::DOMAIN source1 FaPs2M3vQdQYOJSlia - -
1170717508.883051 ClEkJM2Vm5giqnMf4h 192.150.187.164 58869 194.127.84.106 443 2c322ae2b7fe91391345e070b63668978bb1c9da Intel::CERT_HASH X509::IN_CERT zeek Intel::CERT_HASH source1 Fchqui4jmz6K3XZzq2 application/x-x509-user-cert 194.127.84.106:443/tcp
1170717509.082241 ClEkJM2Vm5giqnMf4h 192.150.187.164 58869 194.127.84.106 443 www.dresdner-privat.de Intel::DOMAIN X509::IN_CERT zeek Intel::DOMAIN source1 Fchqui4jmz6K3XZzq2 - -
1170717511.909717 C4J4Th3PJpwUYZZ6gc 192.150.187.164 58870 194.127.84.106 443 2c322ae2b7fe91391345e070b63668978bb1c9da Intel::CERT_HASH X509::IN_CERT zeek Intel::CERT_HASH source1 F9t9Mo3PvEHEdcasbc application/x-x509-user-cert 194.127.84.106:443/tcp
1170717512.108799 C4J4Th3PJpwUYZZ6gc 192.150.187.164 58870 194.127.84.106 443 www.dresdner-privat.de Intel::DOMAIN X509::IN_CERT zeek Intel::DOMAIN source1 F9t9Mo3PvEHEdcasbc - -
#close 2020-04-30-00-48-05