Zeek-Parser-Bacnet
English is here
æ¦è¦
Zeek-Parser-Bacnetã¨ã¯Bacnetãè§£æã§ããZeekãã©ã°ã¤ã³ã§ãã
ã¤ã³ã¹ãã¼ã«
ããã±ã¼ã¸ããã¼ã¸ã£ã¼ã«ããã¤ã³ã¹ãã¼ã«
ãã®ãã©ã°ã¤ã³ã¯Zeek Package Mangerç¨ã®ããã±ã¼ã¸ã¨ãã¦æä¾ããã¦ãã¾ãã
以ä¸ã®ã³ãã³ããå®è¡ãããã¨ã§ãæ¬ãã©ã°ã¤ã³ã¯å©ç¨å¯è½ã«ãªãã¾ãã
zkg refresh
zkg install icsnpp-bacnet
zkg install zeek-parser-Bacnet
ããã¥ã¢ã«ã¤ã³ã¹ãã¼ã«
æ¬ãã©ã°ã¤ã³ãå©ç¨ããåã«ãZeekãã¤ã³ã¹ãã¼ã«ããã¦ãããã¨ã確èªãã¾ãã
# Zeekã®ãã§ãã¯
~$ zeek -version
zeek version 5.0.0
# æ¬ããã¥ã¢ã«ã§ã¯Zeekã®ãã¹ã以ä¸ã§ãããã¨ãåæã¨ãã¦ãã¾ãã
~$ which zeek
/usr/local/zeek/bin/zeek
æ¬ãªãã¸ããªããã¼ã«ã«ç°å¢ã« git clone
ãã¾ãã
~$ git clone https://github.com/nttcom/zeek-parser-Bacnet.git
ä½¿ãæ¹
ããã±ã¼ã¸ããã¼ã¸ã£ã¼ã«ããã¤ã³ã¹ãã¼ã«ã®å ´å
以ä¸ã®ããã«æ¬ãã©ã°ã¤ã³ã使ããã¨ã§ bacnet.log
ãçæããã¾ãã
zeek -Cr /usr/local/zeek/var/lib/zkg/clones/package/zeek-parser-Bacnet/testing/Traces/test.pcap zeek-parser-Bacnet
ããã¥ã¢ã«ã¤ã³ã¹ãã¼ã«ã®å ´å
Zeekãã¡ã¤ã«ã以ä¸ã®ãã¹ã«ã³ãã¼ãã¾ãã
~$ cd ~/zeek-parser-Bacnet/scripts/
~$ cp bacnet_ip.zeek /usr/local/zeek/share/zeek/site/icsnpp-bacnet/main.zeek
~$ cp consts_bacnet_ip.zeek /usr/local/zeek/lib/zeek/plugins/packages/icsnpp-bacnet/scripts/consts.zeek
Zeekãã©ã°ã¤ã³ãã¤ã³ãã¼ããã¾ãã
~$ tail /usr/local/zeek/share/zeek/site/local.zeek
...çç¥...
@load icsnpp-bacnet
æ¬ãã©ã°ã¤ã³ã使ããã¨ã§ bacnet.log
ãçæããã¾ãã
~$ cd ~/zeek-parser-Bacnet/testing/Traces
~$ zeek -Cr test.pcap /usr/local/zeek/share/zeek/site/icsnpp-bacnet/main.zeek
ãã°ã®ã¿ã¤ãã¨èª¬æ
æ¬ãã©ã°ã¤ã³ã¯bacbetã®å
¨ã¦ã®é¢æ°ãç£è¦ãã¦bacnet.log
ã¨ãã¦åºåãã¾ãã
ãã£ã¼ã«ã | ã¿ã¤ã | 説æ |
---|---|---|
ts | time | æåã«éä¿¡ããæã®ã¿ã¤ã ã¹ã¿ã³ã |
uid | string | ã¦ãã¼ã¯ID |
id.orig_h | addr | éä¿¡å IPã¢ãã¬ã¹ |
id.orig_p | port | éä¿¡å ãã¼ãçªå· |
id.resp_h | addr | å®å IPã¢ãã¬ã¹ |
id.resp_p | port | å®å ãã¼ãçªå· |
proto | enum | ãã©ã³ã¹ãã¼ã層ãããã³ã« |
pdu_service | string | PDUãµã¼ãã¹ã®åå |
pdu_type | string | PDUã¿ã¤ã |
obj_type | string | ãªãã¸ã§ã¯ãã¿ã¤ã |
number | int | ãã±ããåºç¾åæ° |
ts_end | time | æå¾ã«éä¿¡ããæã®ã¿ã¤ã ã¹ã¿ã³ã |
bacnet.log
ã®ä¾ã¯ä»¥ä¸ã®ã¨ããã§ãã
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path bacnet
#open 2023-08-22-02-33-43
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto pdu_service pdu_type obj_type number ts_end
#types time string addr port addr port enum string string string int time
83079.679847 Cifz3n4zRoW5N4c3Fg 10.0.20.24 47808 10.0.30.35 47808 udp atomic_write_file ConfirmedRequest file 4 83136.235718
83076.790637 Czf30y4FoJ43aMrB47 10.0.20.22 47808 10.0.30.27 47808 udp who_is UnconfirmedRequest (empty) 8 83138.226848
83076.042712 C6QrIv2oRwgQMqYYc5 10.0.20.23 47808 10.0.30.31 47808 udp who_has UnconfirmedRequest (empty) 12 83147.742865
#close 2023-08-22-02-33-43
é¢é£ã½ããã¦ã§ã¢
æ¬ãã©ã°ã¤ã³ã¯OsecTã§å©ç¨ããã¦ãã¾ãã