mirror of
https://github.com/zeek/zeek.git
synced 2025-10-10 02:28:21 +00:00

* 'ntp-rewrite' of https://github.com/mauropalumbo75/zeek: (25 commits) update tests baseline Apply requested changes: - file dpd.sig and TODO comments for signature protocol detection removed - missing doc field filled in events.bif - rename OpCode and ReqCode fields into op_code and req_code respectively - removed unnecessary child method in NTP.h/.cc - main.zeek and ntp-protocol.pac reformatted minor changes in the documentation fix some initializations fix wrong assignment of control key_id/crypto_checksum code clean up add extension fields parsing add extended mac field with 20 byte digest (+4 byte key id) update tests and add a new one for key_id and mac fix auth field (key_id and mac) in standard and control msg remove old NTP record in init-bare.zeek fix key_id and digest (WIP) fix wrong Assign with reference_id add tests for ntp protocol (finished) add tests for ntp protocol (WIP) fix problem with time vals add ntp records to init-bare.zeek update ntp analyzer to val_mgr extend and refact script-side of NTP analyzer extend and refactor several fields ...
41 lines
6.8 KiB
Text
41 lines
6.8 KiB
Text
#separator \x09
|
|
#set_separator ,
|
|
#empty_field (empty)
|
|
#unset_field -
|
|
#path ntp
|
|
#open 2019-06-16-00-50-01
|
|
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p version mode stratum poll precision root_delay root_disp ref_id ref_time org_time rec_time xmt_time num_exts
|
|
#types time string addr port addr port count count count interval interval interval interval string time time time time count
|
|
1559246614.027454 CHhAvVGS1DHFjwGM9 192.168.43.118 123 80.211.52.109 123 4 3 2 64.000000 0.000000 0.046280 0.024170 85.199.214.99 1559246556.073681 1559246548.048352 1559246548.076756 1559246614.027421 0
|
|
1559246614.074475 CHhAvVGS1DHFjwGM9 192.168.43.118 123 80.211.52.109 123 4 4 4 64.000000 0.000000 0.048843 0.071350 105.237.207.28 1559245852.721794 1559246614.027421 1559246614.048376 1559246614.048407 0
|
|
1559246617.027486 ClEkJM2Vm5giqnMf4h 192.168.43.118 123 212.45.144.88 123 4 3 2 64.000000 0.000000 0.046280 0.024216 85.199.214.99 1559246556.073681 1559246550.040662 1559246550.063198 1559246617.027452 0
|
|
1559246617.063504 ClEkJM2Vm5giqnMf4h 192.168.43.118 123 212.45.144.88 123 4 4 2 64.000000 0.000000 0.003799 0.032959 193.204.114.233 1559245541.537424 1559246617.027452 1559246617.040799 1559246617.040813 0
|
|
1559246619.027413 C4J4Th3PJpwUYZZ6gc 192.168.43.118 123 31.14.131.188 123 4 3 2 64.000000 0.000000 0.046280 0.024246 85.199.214.99 1559246556.073681 1559246553.074199 1559246553.094855 1559246619.027384 0
|
|
1559246619.074513 C4J4Th3PJpwUYZZ6gc 192.168.43.118 123 31.14.131.188 123 4 4 2 64.000000 0.000000 0.040375 0.001266 195.113.144.238 1559246560.207644 1559246619.027384 1559246619.054018 1559246619.054053 0
|
|
1559246620.027437 CtPZjS20MLrsMUOJi2 192.168.43.118 123 188.213.165.209 123 4 3 2 64.000000 0.000000 0.046280 0.024261 85.199.214.99 1559246556.073681 1559246551.034239 1559246551.058223 1559246620.027408 0
|
|
1559246620.027466 CUM0KZ3MLUfNB0cl11 192.168.43.118 123 185.19.184.35 123 4 3 2 64.000000 0.000000 0.046280 0.024261 85.199.214.99 1559246556.073681 1559246553.067084 1559246553.088704 1559246620.027461 0
|
|
1559246620.027480 CmES5u32sYpV7JYN 192.168.43.118 123 212.45.144.3 123 4 3 2 64.000000 0.000000 0.046280 0.024261 85.199.214.99 1559246556.073681 1559246554.041266 1559246554.063055 1559246620.027475 0
|
|
1559246620.059693 CUM0KZ3MLUfNB0cl11 192.168.43.118 123 185.19.184.35 123 4 4 2 64.000000 0.000008 0.003235 0.000275 193.204.114.233 1559246481.481997 1559246620.027461 1559246620.040139 1559246620.040206 0
|
|
1559246620.065302 CtPZjS20MLrsMUOJi2 192.168.43.118 123 188.213.165.209 123 4 4 2 64.000000 0.000000 0.013397 0.053787 193.204.114.233 1559244627.070973 1559246620.027408 1559246620.043959 1559246620.043985 0
|
|
1559246620.065335 CmES5u32sYpV7JYN 192.168.43.118 123 212.45.144.3 123 4 4 2 64.000000 0.000001 0.003510 0.036545 193.204.114.232 1559245278.442390 1559246620.027475 1559246620.048058 1559246620.048074 0
|
|
1559246621.027458 CP5puj4I8PtEU4qzYg 192.168.43.118 123 31.14.133.122 123 4 3 2 64.000000 0.000000 0.046280 0.024277 85.199.214.99 1559246556.073681 1559246553.072776 1559246553.094814 1559246621.027421 0
|
|
1559246621.095645 CP5puj4I8PtEU4qzYg 192.168.43.118 123 31.14.133.122 123 4 4 2 64.000000 0.000000 0.010910 0.033463 193.204.114.233 1559245577.265702 1559246621.027421 1559246621.073143 1559246621.073172 0
|
|
1559246622.027418 C37jN32gN3y3AZzyf6 192.168.43.118 123 85.199.214.99 123 4 3 2 64.000000 0.000000 0.046280 0.024292 85.199.214.99 1559246556.073681 1559246556.043833 1559246556.073681 1559246622.027384 0
|
|
1559246622.027454 C3eiCBGOLw3VtHfOj 192.168.43.118 123 94.177.187.22 123 4 3 2 64.000000 0.000000 0.046280 0.024292 85.199.214.99 1559246556.073681 1559246553.078959 1559246553.100708 1559246622.027446 0
|
|
1559246622.027471 CwjjYJ2WqgTbAqiHl6 192.168.43.118 123 147.135.207.214 123 4 3 2 64.000000 0.000000 0.046280 0.024292 85.199.214.99 1559246556.073681 1559246553.085177 1559246553.102587 1559246622.027464 0
|
|
1559246622.027484 C0LAHyvtKSQHyJxIl 192.168.43.118 123 212.45.144.206 123 4 3 2 64.000000 0.000000 0.046280 0.024292 85.199.214.99 1559246556.073681 1559246554.041367 1559246554.069181 1559246622.027478 0
|
|
1559246622.092519 C3eiCBGOLw3VtHfOj 192.168.43.118 123 94.177.187.22 123 4 4 2 64.000000 0.000000 0.013733 0.041672 193.204.114.233 1559245709.302032 1559246622.027446 1559246622.071899 1559246622.071924 0
|
|
1559246622.092556 C0LAHyvtKSQHyJxIl 192.168.43.118 123 212.45.144.206 123 4 4 2 64.000000 0.000002 0.003510 0.038559 193.204.114.232 1559245178.020777 1559246622.027478 1559246622.068521 1559246622.068560 0
|
|
1559246622.100109 C37jN32gN3y3AZzyf6 192.168.43.118 123 85.199.214.99 123 4 4 1 16.000000 0.000000 0.000000 0.000000 GPS\x00 1559246622.000000 1559246622.027384 1559246622.073734 1559246622.073740 0
|
|
1559246622.100152 CwjjYJ2WqgTbAqiHl6 192.168.43.118 123 147.135.207.214 123 4 4 2 64.000000 0.000008 0.042236 0.037430 212.7.1.132 1559245356.576177 1559246622.027464 1559246622.086267 1559246622.086348 0
|
|
1559246623.027502 CFLRIC3zaTU1loLGxh 192.168.43.118 123 93.41.196.243 123 4 3 2 64.000000 0.000000 0.046280 0.024307 85.199.214.99 1559246556.073681 1559246556.032041 1559246556.054612 1559246623.027478 0
|
|
1559246623.027531 C9rXSW3KSpTYvPrlI1 192.168.43.118 123 80.211.171.177 123 4 3 2 64.000000 0.000000 0.046280 0.024307 85.199.214.99 1559246556.073681 1559246555.051459 1559246555.077253 1559246623.027521 0
|
|
1559246623.062844 CFLRIC3zaTU1loLGxh 192.168.43.118 123 93.41.196.243 123 4 4 2 64.000000 0.000000 0.025391 0.011642 193.204.114.233 1559246412.455332 1559246623.027478 1559246623.041209 1559246623.041220 0
|
|
1559246623.070217 C9rXSW3KSpTYvPrlI1 192.168.43.118 123 80.211.171.177 123 4 4 4 64.000000 0.000000 0.036835 0.046951 73.98.4.223 1559245789.870424 1559246623.027521 1559246623.048360 1559246623.048416 0
|
|
1559246626.027461 Ck51lg1bScffFj34Ri 192.168.43.118 123 147.135.207.213 123 4 3 2 64.000000 0.000000 0.046280 0.024353 85.199.214.99 1559246556.073681 1559246557.078120 1559246557.097844 1559246626.027432 0
|
|
1559246626.027518 C9mvWx3ezztgzcexV7 192.168.43.118 123 80.211.155.206 123 4 3 2 64.000000 0.000000 0.046280 0.024353 85.199.214.99 1559246556.073681 1559246558.043947 1559246558.067904 1559246626.027514 0
|
|
1559246626.065984 C9mvWx3ezztgzcexV7 192.168.43.118 123 80.211.155.206 123 4 4 2 64.000000 0.000000 0.013535 0.025497 193.204.114.232 1559246283.180069 1559246626.027514 1559246626.044105 1559246626.044139 0
|
|
1559246626.075079 Ck51lg1bScffFj34Ri 192.168.43.118 123 147.135.207.213 123 4 4 2 64.000000 0.000008 0.042236 0.037491 212.7.1.132 1559245356.576177 1559246626.027432 1559246626.058084 1559246626.058151 0
|
|
1559246627.027502 CNnMIj2QSd84NKf7U3 192.168.43.118 123 80.211.88.132 123 3 3 2 64.000000 0.000000 0.046280 0.024368 85.199.214.99 1559246556.073681 1559246560.040576 1559246560.064668 1559246627.027459 0
|
|
1559246627.073485 CNnMIj2QSd84NKf7U3 192.168.43.118 123 80.211.88.132 123 3 4 3 64.000000 0.000001 0.011765 0.001526 185.19.184.35 1559245638.390748 1559246627.027459 1559246627.050401 1559246627.050438 0
|
|
#close 2019-06-16-00-50-01
|