Zeek-Parser-DHCPv4-COM
English is here
æ¦è¦
Zeek-Parser-DHCPv4-COMã¨ã¯Zeekãªãªã¸ãã«ã®DHCPv4(Dynamic Host Configuration Protocol for IPv4)ãã©ã°ã¤ã³ãåèã«ãã¦ä½æãããã©ã°ã¤ã³ã§ãã
ã¤ã³ã¹ãã¼ã«
ããã±ã¼ã¸ããã¼ã¸ã£ã¼ã«ããã¤ã³ã¹ãã¼ã«
ãã®ãã©ã°ã¤ã³ã¯Zeek Package Mangerç¨ã®ããã±ã¼ã¸ã¨ãã¦æä¾ããã¦ãã¾ãã
以ä¸ã®ã³ãã³ããå®è¡ãããã¨ã§ãæ¬ãã©ã°ã¤ã³ã¯å©ç¨å¯è½ã«ãªãã¾ãã
zkg refresh
zkg install zeek-parser-DHCPv4-COM
ããã¥ã¢ã«ã¤ã³ã¹ãã¼ã«
æ¬ãã©ã°ã¤ã³ãå©ç¨ããåã«ãZeek, Spicyãã¤ã³ã¹ãã¼ã«ããã¦ãããã¨ã確èªãã¾ãã
# Zeekã®ãã§ãã¯
~$ zeek -version
zeek version 5.0.0
# Spicyã®ãã§ãã¯
~$ spicyz -version
1.3.16
~$ spicyc -version
spicyc v1.5.0 (d0bc6053)
# æ¬ããã¥ã¢ã«ã§ã¯Zeekã®ãã¹ã以ä¸ã§ãããã¨ãåæã¨ãã¦ãã¾ãã
~$ which zeek
/usr/local/zeek/bin/zeek
æ¬ãªãã¸ããªããã¼ã«ã«ç°å¢ã« git clone
ãã¾ãã
~$ git clone https://github.com/nttcom/zeek-parser-DHCPv4-COM.git
ä½¿ãæ¹
ããã±ã¼ã¸ããã¼ã¸ã£ã¼ã«ããã¤ã³ã¹ãã¼ã«ã®å ´å
以ä¸ã®ããã«æ¬ãã©ã°ã¤ã³ã使ããã¨ã§ mydhcp.log
ãçæããã¾ãã
zeek -Cr /usr/local/zeek/var/lib/zkg/clones/package/zeek-parser-DHCPv4-COM/testing/Traces/test.pcap zeek-parser-DHCPv4-COM
ããã¥ã¢ã«ã¤ã³ã¹ãã¼ã«ã®å ´å
ã½ã¼ã¹ã³ã¼ããã³ã³ãã¤ã«ãã¦ããªãã¸ã§ã¯ããã¡ã¤ã«ã以ä¸ã®ãã¹ã«ã³ãã¼ãã¾ãã
~$ cd ~/zeek-parser-DHCPv4-COM/analyzer
~$ spicyz -o mydhcp.hlto mydhcp.spicy zeek_mydhcp.spicy mydhcp.evt
# mydhcp.hltoãçæããã¾ã
~$ cp mydhcp.hlto /usr/local/zeek/lib/zeek-spicy/modules/
åæ§ã«Zeekãã¡ã¤ã«ã以ä¸ã®ãã¹ã«ã³ãã¼ãã¾ãã
~$ cd ~/zeek-parser-DHCPv4-COM/scripts/
~$ cp main.zeek /usr/local/zeek/share/zeek/site/MYDHCP.zeek
æå¾ã«Zeekãã©ã°ã¤ã³ãã¤ã³ãã¼ããã¾ãã
~$ tail /usr/local/zeek/share/zeek/site/local.zeek
...çç¥...
@load MYDHCP
æ¬ãã©ã°ã¤ã³ã使ããã¨ã§ mydhcp.log
ãçæããã¾ãã
~$ cd ~/zeek-parser-DHCPv4-COM/testing/Traces
~$ zeek -Cr test.pcap /usr/local/zeek/share/zeek/site/MYDHCP.zeek
ãã°ã®ã¿ã¤ãã¨èª¬æ
æ¬ãã©ã°ã¤ã³ã¯dhcpv4ã®å
¨ã¦ã®é¢æ°ãç£è¦ãã¦mydhcp.log
ã¨ãã¦åºåãã¾ãã
ãã£ã¼ã«ã | ã¿ã¤ã | 説æ |
---|---|---|
ts | time | éä¿¡ããæã®ã¿ã¤ã ã¹ã¿ã³ã |
SrcIP | addr | éä¿¡å IPã¢ãã¬ã¹ |
SrcMAC | string | éä¿¡å MACã¢ãã¬ã¹ |
Hostname | string | ãã¹ãã®åå |
ParameterList | vector[count] | DHCPã¯ã©ã¤ã¢ã³ãã¨DHCPãµã¼ãéã§ããåããããã¡ãã»ã¼ã¸å ã®è¨å®æ å ± |
ClassId | string | ããã¤ã¹ã®ã¿ã¤ãããã¼ã¸ã§ã³æ å ± |
mydhcp.log
ã®ä¾ã¯ä»¥ä¸ã®ã¨ããã§ãã
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path mydhcp
#open 2023-09-13-05-55-51
#fields ts SrcIP SrcMAC Hostname ParameterList ClassId
#types time addr string string vector[count] string
1539480862.362578 0.0.0.0 32:05:33:83:b1:e7 DESKTOP-QVGI2E4 1,3,6,15,31,33,43,44,46,47,119,121,249,252 MSFT 5.0
1539567778.980630 192.168.0.28 32:05:33:83:b1:e7 DESKTOP-QVGI2E4 1,3,6,15,31,33,43,44,46,47,119,121,249,252 MSFT 5.0
#close 2023-09-13-05-55-55
é¢é£ã½ããã¦ã§ã¢
æ¬ãã©ã°ã¤ã³ã¯OsecTã§å©ç¨ããã¦ãã¾ãã
é¢é£ãªãã¸ããª
- spicy-dhcp - Zeekãªãªã¸ãã«ã®Spicyã«åºã¥ããDHCPv4(Dynamic Host Configuration Protocol for IPv4)ãã©ã°ã¤ã³ã§ãã
ãã°ã®å·®å(DHCPv4-COMã¨Zeekãªãªã¸ãã«)
ãã£ã¼ã«ã | DHCPv4-COM | Zeekãªãªã¸ãã« | 説æ |
---|---|---|---|
ts | ⯠| ⯠| éä¿¡ããæã®ã¿ã¤ã ã¹ã¿ã³ã |
SrcIP | ⯠| ⯠(client_addr) | éä¿¡å IPã¢ãã¬ã¹ |
SrcMAC | ⯠| ⯠(mac) | éä¿¡å MACã¢ãã¬ã¹ |
Hostname | ⯠| ⯠(host_name) | ãã¹ãã®åå |
ParameterList | ⯠| x | DHCPã¯ã©ã¤ã¢ã³ãã¨DHCPãµã¼ãéã§ããåããããã¡ãã»ã¼ã¸å ã®è¨å®æ å ± |
ClassId | ⯠| x | ããã¤ã¹ã®ã¿ã¤ãããã¼ã¸ã§ã³æ å ± |
uids | x | ⯠| éä¿¡ã«ä»ãããã䏿ã®èå¥å |
server_addr | x | ⯠| DHCPãµã¼ãã®IPã¢ãã¬ã¹ |
client_fqdn | x | ⯠| DHCPã¯ã©ã¤ã¢ã³ãã®å®å ¨ä¿®é£¾ãã¡ã¤ã³å |
domain | x | ⯠| DHCPã¯ã©ã¤ã¢ã³ããæå±ãããã¡ã¤ã³å |
requested_addr | x | ⯠| DHCPã¯ã©ã¤ã¢ã³ããè¦æ±ããIPã¢ãã¬ã¹ |
assigned_addr | x | ⯠| DHCPãµã¼ãã«ãã£ã¦ã¯ã©ã¤ã¢ã³ãã«å²ãå½ã¦ãããIPã¢ãã¬ã¹ |
lease_time | x | ⯠| DHCPã¯ã©ã¤ã¢ã³ãã«å²ãå½ã¦ãããIPã¢ãã¬ã¹ã®ãªã¼ã¹æé |
client_message | x | ⯠| DHCPã¯ã©ã¤ã¢ã³ãã®ã¡ãã»ã¼ã¸ |
server_message | x | ⯠| DHCPãµã¼ãã®ã¡ãã»ã¼ã¸ |
msg_types | x | ⯠| ã¡ãã»ã¼ã¸ã®ã¿ã¤ã |
duration | x | ⯠| éä¿¡ã®ç¶ç¶æé |