Bro contains a programming language designed specifically to be able to represent network-related abstractions (e.g. addresses and ports) and as such offers a great deal of functionality and flexibility in terms of helping you accomplish your network-monitoring goals. The following exercises all explore using Bro’s scripting language.
The string type holds character-string values that are used to represent and manipulate text, so let’s learn to do that since those kinds of tasks are likely to show up later.
Exercise
All the exercises for this part are described within the part1.bro bro script, to which you’ll add your own code. It can be run using Bro at any time to check your progress:
bro part1.bro
There are several container/collection types that are commonly used in Bro for accumulating/storing state information and this tutorial will go over the basic usage of each: table, set, and vector.
Exercise
All exercises are described within part2.bro. Follow the tasks that the comments set out and add your own code to it. Run it using Bro at any time to check/test progress:
bro part2.bro
A record is a collection of values, with each having a name (referred to as the record’s fields), and a type. There’s no restriction on allowed types, which means they can contain other, nested record fields or even function types which are just procedural abstractions most programmers are already familiar with, but will be described in this exercise.
Exercise
All exercises are described within part3.bro. Follow the tasks that the comments set out and add your own code to it. Run it using Bro at any time to check/test progress:
bro part3.bro
Bro provides an event engine as the primary facilitator of network analysis. And the way a Bro programmer (Brogrammer) can tap into the engine is at the scripting-layer through event handlers, so this part of the exercise looks at how to do that.
Exercise
All exercises are described within part4.bro. You’ll also need browse.pcap. Follow the tasks that the comments set out and add your own code to it. Run it using Bro at any time to check/test progress:
bro -r browse.pcap part4.bro
© 2014 The Bro Project.