mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 10:08:20 +00:00

I've worked on this a bit more: - Added tcp_max_old_segments to init-bare.bro. - Removed the existing call to Overlap() as that now led to duplicate events. - Fixed the code checking for overlaps, as it didn't catch all the cases. BIT-1314 #merged GitHub #31 merged * topic/yunzheng/bit-1314: BIT-1314: Added QI test for rexmit_inconsistency BIT-1314: Add detection for Quantum Insert attacks
12 lines
497 B
Text
12 lines
497 B
Text
# @TEST-EXEC: bro -b -r $TRACES/tcp/qi_internet_SYNACK_curl_jsonip.pcap %INPUT
|
|
# @TEST-EXEC: btest-diff .stdout
|
|
|
|
# Quantum Insert like attack, overlapping TCP packet with different content
|
|
redef tcp_max_old_segments = 10;
|
|
event rexmit_inconsistency(c: connection, t1: string, t2: string)
|
|
{
|
|
print "----- rexmit_inconsistency -----";
|
|
print fmt("%.6f c: %s", network_time(), c$id);
|
|
print fmt("%.6f t1: %s", network_time(), t1);
|
|
print fmt("%.6f t2: %s", network_time(), t2);
|
|
}
|