It seems there is something strange going on with the combination of bro_http.site field, numeric characters and the grep transform. Does anyone have any pointers that can straighten me out?
Thanks,
Kurt
Kurt,
I can confirm this does not work with numeric characters.
Have you tried using srcip or dstip instead?
Thanks,
Wes
Hi Wes,
Thanks for checking into this.
Working with srcip and dstip won't work. I believe Bro extracts those from the layer 3 IP header and they will always be dotted decimal octet style IP addresses (assuming IPv4, not 6). The bro_http.site field is taken from the Host: field of the http headers. 99ish% of the time this field is DNS hostname such as www.google.com. When it isn't a DNS hostname, but instead an IP address, it is interesting and potentially worth investigating. Users rarely browse by IP address. But, a low budget attacker who can't afford to register DNS domains may hard code IP addresses in malware for an HTTP reverse connection.
If I can't do this with Bro/ELSA, I'll try to figure out another way to perform this query. But the geek in me is curious as to why this doesn't work. The http header "host" field/bro_http.site field is string data. Why does parsing with the grep transform behave strangely when it's all dotted decimal? That's still ASCII string data... Hmm...
Thanks,
Kurt
Hi Doug,
Thanks for this. It was indeed the issue. I feel a bit silly for not considering truncated results being fed to grep as the root cause. Thanks for the help.
Kurt
> > To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
> > To post to this group, send email to security-onion@googlegroups.com.
> > Visit this group at https://groups.google.com/group/security-onion.
> > For more options, visit https://groups.google.com/d/optout.
>
>
>
> --
> Doug Burks
Hi Doug,
Thanks for this. It was indeed the issue. I feel a bit silly for not considering truncated results being fed to grep as the root cause. Thanks for the help.
Kurt
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onion+unsubscribe@googlegroups.com.
To post to this group, send email to security-onion@googlegroups.com.