zeek/scripts/base/protocols/sip/dpd.sig
2015-03-19 19:57:05 -04:00

17 lines
387 B
Standard ML

signature dpd_sip_udp_req {
ip-proto == udp
payload /.* SIP\/[0-9]\.[0-9]\x0d\x0a/
enable "sip"
}
signature dpd_sip_udp_resp {
ip-proto == udp
payload /^( SIP\/[0-9]\.[0-9]\x0d\x0a|SIP\/[0-9]\.[0-9] [0-9][0-9][0-9] )/
enable "sip"
}
signature dpd_sip_tcp {
ip-proto == tcp
payload /^( SIP\/[0-9]\.[0-9]\x0d\x0a|SIP\/[0-9]\.[0-9] [0-9][0-9][0-9] )/
enable "sip_tcp"
}