zeek/scripts/base/frameworks
Jon Siwek 9edbf3e53c Add GPRS Tunnelling Protocol (GTPv1) decapsulation.
This currently supports automatic decapsulation of GTP-U packets on
UDP port 2152.

The GTPv1 headers for such tunnels can be inspected by handling the
"gtpv1_g_pdu_packet" event, which has a parameter of type "gtpv1_hdr".

Analyzer and test cases are derived from submissions by Carsten Langer.

Addresses #690.
2012-10-19 14:02:35 -05:00
..
cluster Merge remote-tracking branch 'origin/topic/jsiwek/ipv6-comm' 2012-05-24 17:01:34 -07:00
communication Merge remote-tracking branch 'vlad/info_record_fixes' 2012-07-13 16:20:49 -07:00
control Enable Bro to communicate with peers over non-global IPv6 addresses. 2012-05-17 12:59:20 -05:00
dpd Fixed some problems with the SOCKS analyzer and tests. 2012-06-20 22:57:46 -04:00
input Merge remote-tracking branch 'origin/topic/bernhard/input-end-of-data' 2012-10-12 09:48:58 -07:00
intel This completes framework documentation package 4. 2012-01-06 16:36:22 -05:00
logging Merge remote-tracking branch 'origin/topic/matthias/libcurl-fix' 2012-10-02 12:07:26 -07:00
metrics Fixing a warning from the documentation generation. 2012-01-06 16:50:20 -05:00
notice Fix a problem with non-manager cluster nodes applying Notice::policy. 2012-10-04 16:45:56 -05:00
packet-filter Checkpoint after pass. 2012-02-15 13:07:08 -08:00
reporter Merge remote-tracking branch 'origin/topic/seth/reporter-to-stderr' 2012-08-10 12:29:07 -07:00
signatures Add more signature framework documentation. 2011-12-14 12:50:54 -06:00
software One more very minor change I forgot to commit. 2012-02-03 16:27:51 -05:00
tunnels Add GPRS Tunnelling Protocol (GTPv1) decapsulation. 2012-10-19 14:02:35 -05:00