zeek/scripts/policy/frameworks
Johanna Amann 8ce746cc25 Merge remote-tracking branch 'origin/topic/vladg/bit-1641'
* origin/topic/vladg/bit-1641:
  Logic fix for ssh/main.bro when the auth status is indeterminate, and fix a test. Addresses BIT-1641.
  Clean up the logic for ssh_auth_failed. Addresses BIT-1641
  Update baselines for adding a field to ssh.log as part of BIT-1641
  Script-land changes for BIT-1641.
  Change SSH.cc to use ssh_auth_attempted instead of ssh_auth_failed. Addresses BIT-1641.
  Revert "Fixing duplicate SSH authentication failure events."
  Create new SSH events ssh_auth_attempt and ssh_auth_result. Add auth_attempts to SSH::Info. Address BIT-1641.

I extended the tests a bit and did some small cleanups. I also moved the
SSH events back to the global namespace for backwards compatibility and
for consistency (the way it was at the moment, some of them were global
some SSH::).

Furthermore, I fixed the ssh_auth_result result event, it was only
raised in the success case. ssh_auth_result is now also checked in the
testcases. I also have a suspicion that the intel integration never
really worked before.

BIT-1641 #merged
2016-10-18 21:57:27 -04:00
..
communication Enable Bro to communicate with peers over non-global IPv6 addresses. 2012-05-17 12:59:20 -05:00
control Fixing control frameworks net_stats and peer_status commands. 2016-05-17 16:11:22 -07:00
dpd Fix typos and formatting in the policy/frameworks docs 2013-10-21 01:23:08 -05:00
files Merge remote-tracking branch 'origin/fastpath' 2016-05-03 11:36:52 -07:00
intel Merge remote-tracking branch 'origin/topic/vladg/bit-1641' 2016-10-18 21:57:27 -04:00
packet-filter Fix typos and formatting in the policy/frameworks docs 2013-10-21 01:23:08 -05:00
signatures Hopefully the last major script reorganization. 2011-08-05 23:09:53 -04:00
software Update windows-version-detection.bro 2015-12-04 09:46:14 -05:00