zeek/scripts/base/protocols
Johanna Amann bea3075c1f TLS analyzer: change logic to track TLS 1.3 connection establishment
This commit changes the logic that is used to tracks connection
establishment - and moves it from scriptland into the core.

TLS 1.3 connection establishment is much more finnicky for us than the
establishment of earlier versions - since we cannot rely on the CCS
message anymore (which is meaningless and not sent in a lot of cases).

With this commit, the ssl_encrypted_data message gets raised for
encrypted TLS 1.3 handshake messages - which is much more correct than
the behavior before that just interpreted them as plaintext messages.

I will refine this a bit more - at the moment the connection established
event happens a bit too early - earlier than TLS 1.3 connections
actually can be estasblished.

Part of GH-1323
2020-12-14 19:51:05 +00:00
..
conn Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
dce-rpc Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
dhcp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
dnp3 Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
dns Support for additional DNS RR Type: LOC[29], SSHFP[44], NSEC3PARAM[51], custom BIND9 signaling[65534] 2020-11-11 13:35:51 -07:00
ftp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
http Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
imap Merge remote-tracking branch 'origin/topic/seth/zeek_init' 2019-04-19 11:24:29 -07:00
irc Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
krb Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
modbus Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
mqtt Disable MQTT by default 2019-08-05 17:04:39 -07:00
mysql Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
ntlm Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
ntp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
pop3 Rename all scripts to have ".zeek" file extension 2019-04-11 21:12:40 -05:00
radius Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
rdp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
rfb Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
sip Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
smb Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
smtp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
snmp Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
socks Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
ssh Merge remote-tracking branch 'origin/topic/jsiwek/gh-1264-ssh-host-key-fingerprints' into master 2020-11-16 11:22:37 -08:00
ssl TLS analyzer: change logic to track TLS 1.3 connection establishment 2020-12-14 19:51:05 +00:00
syslog Support for log filter policy hooks 2020-09-30 12:32:45 -07:00
tunnels Rename all scripts to have ".zeek" file extension 2019-04-11 21:12:40 -05:00
xmpp Merge remote-tracking branch 'origin/topic/seth/zeek_init' 2019-04-19 11:24:29 -07:00