
A Zeek Wireguard protocol analyzer based on Spicy.
该软件包为 Zeek 提供一个基于 Spicy 的 Wireguard 协议分析器。
您必须安装 Spicy 才能使用此软件包。
这是一个遵循 https://www.wireguard.com/protocol/ 的简单实现。
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path conn
#open 2021-11-24-18-10-11
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig local_resp missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
#types time string addr port addr port enum string interval count count string bool bool count string count count count count set[string]
1611583877.627931 CHhAvVGS1DHFjwGM9 188.166.170.114 45965 188.166.170.115 51194 udp spicy_wireguard 35.595192 13516 14924 SF - - 0 Dd 90 16036 82 17220 -
#close 2021-11-24-18-10-11
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path wireguard
#open 2021-11-24-18-10-11
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p established initiations responses
#types time string addr port addr port bool count count
1611583877.627931 CHhAvVGS1DHFjwGM9 188.166.170.114 45965 188.166.170.115 51194 T 1 1
#close 2021-11-24-18-10-11
该软件包还可检测……
Tailscale 是一种对 Wireguard 协议略作修改的 VPN,通过添加 Tailscale 发现消息实现。虽然本仓库中的通用 Wireguard 协议分析器不支持这种变体,但本协议分析器支持。
相关代码段:https://github.com/tailscale/tailscale/blob/main/disco/disco.go#L32
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path conn
#open 2021-11-24-18-11-40
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto service duration orig_bytes resp_bytes conn_state local_orig local_resp missed_bytes history orig_pkts orig_ip_bytes resp_pkts resp_ip_bytes tunnel_parents
#types time string addr port addr port enum string interval count count string bool bool count string count count count count set[string]
1623328901.893092 CHhAvVGS1DHFjwGM9 192.168.88.3 41641 18.196.71.179 41641 udp spicy_tailscale 31.882638 5700 6322 SF - - 0 Dd 51 7128 56 7890 -
#close 2021-11-24-18-11-40