|
|||||||||||
|
announcing Bro
From: Vern Paxson <vern(at)icir.org>
Date: Mon Nov 18 2002 - 01:37:15 EST
Bro runs the events produced by the event engine through a user-specified "policy script" written in a high-level, customized language geared towards network analysis in general and security analysis in particular. The policy scripts can maintain and update global state information, write arbitrary information to disk files, generate new events, call functions (either user-defined or predefined), generate alerts that produce syslog messages, or invoke arbitrary shell commands. Bro is now publicly available in source code form under a BSD-like license, with a (modest) home page at: http://www.icir.org/vern/bro.html You can get the "stable" 0.7 release from: ftp://ftp.ee.lbl.gov/bro-pub-0.7-stable.tar.gz or the "current" release (with considerably more features, including a signature engine that can read Snort rules, but unfortunately is not yet documented) from: ftp://ftp.ee.lbl.gov/bro-pub-0.8-current.tar.gz Fairly, but not fully, complete documentation is available from: http://www.icir.org/vern/bro-manual/index.html There's a Bro mailing list, too, bro@lbl.gov. To get on it, send a message to majordomo@listserv.lbl.gov with "subscribe bro" in the *body*. Vern Vern Paxson ICSI Center for Internet Research (ICIR) and Lawrence Berkeley National Laboratory vern@icir.org, vern@ee.lbl.gov Received on Mon Nov 18 02:15:19 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||