Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

integrate Zeek IEC104 parser #557

Closed
mmguero opened this issue Sep 4, 2024 · 2 comments
Closed

integrate Zeek IEC104 parser #557

mmguero opened this issue Sep 4, 2024 · 2 comments
Labels
enhancement New feature or request ics Relating to ICS (Industrial Control Systems) devices zeek Relating to Malcolm's use of Zeek
Milestone

Comments

@mmguero
Copy link
Collaborator

mmguero commented Sep 4, 2024

cert-lv/zeek-iec104 takes the initial work done by @georgemakrakis and expands on it. I think this would be a great protocol parser to integrate into Malcolm.

see:

@mmguero mmguero added enhancement New feature or request ics Relating to ICS (Industrial Control Systems) devices zeek Relating to Malcolm's use of Zeek labels Sep 4, 2024
@mmguero mmguero added this to Malcolm Sep 4, 2024
@mmguero mmguero moved this to In Progress in Malcolm Sep 11, 2024
@mmguero mmguero added this to the v24.09.0 milestone Sep 11, 2024
@mmguero mmguero self-assigned this Sep 11, 2024
mmguero added a commit to mmguero-dev/Malcolm that referenced this issue Sep 11, 2024
@mmguero mmguero modified the milestones: v24.09.0, z.staging Sep 11, 2024
@mmguero mmguero removed the status in Malcolm Sep 11, 2024
@mmguero mmguero removed their assignment Sep 11, 2024
@mmguero mmguero moved this to Todo (develop) in Malcolm Sep 11, 2024
mmguero added a commit to mmguero-dev/Malcolm that referenced this issue Sep 11, 2024
…bled yet)" (decided to wait until the next release)

This reverts commit ba4a7e9.
@mmguero
Copy link
Collaborator Author

mmguero commented Sep 11, 2024

There are a few issues I'd like to resolve in the plugin before getting this in:

  • can we make it signature based rather than port based?
  • I don't like the way it overrides JSON vs. TSV, is there a reason we can't just let Zeek handle it globally like all the other plugins?
  • this isn't as huge a deal, but the tests directory is kind of weird

@mmguero mmguero modified the milestones: z.staging, v24.10.0 Sep 19, 2024
@mmguero mmguero modified the milestones: v24.10.0, v24.10.1, z.staging Oct 7, 2024
@mmguero
Copy link
Collaborator Author

mmguero commented Nov 4, 2024

Kamino closed and cloned this issue to cisagov/Malcolm

@mmguero mmguero closed this as completed Nov 4, 2024
@github-project-automation github-project-automation bot moved this from Todo (develop) to Done in Malcolm Nov 4, 2024
@mmguero mmguero moved this from Done to Migrated in Malcolm Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request ics Relating to ICS (Industrial Control Systems) devices zeek Relating to Malcolm's use of Zeek
Projects
Status: Migrated
Development

No branches or pull requests

1 participant