64 #define NONE FB_IE_F_NONE
65 #define ER FB_IE_F_ENDIAN | FB_IE_F_REVERSIBLE
74 static fbInfoElement_t yaf_info_elements[] = {
75 FB_IE_INIT_FULL(
"initialTCPFlags",
CERT_PEN, 14, 1, ER | FB_IE_FLAGS,
76 0, 0, FB_UINT_8, NULL),
77 FB_IE_INIT_FULL(
"unionTCPFlags",
CERT_PEN, 15, 1, ER | FB_IE_FLAGS, 0, 0,
79 FB_IE_INIT_FULL(
"payload",
CERT_PEN, 18, FB_IE_VARLEN, FB_IE_F_REVERSIBLE,
80 0, 0, FB_OCTET_ARRAY, NULL),
81 FB_IE_INIT_FULL(
"reverseFlowDeltaMilliseconds",
CERT_PEN, 21, 4,
82 FB_IE_F_ENDIAN | FB_IE_QUANTITY | FB_UNITS_MILLISECONDS,
83 0, 0, FB_UINT_32, NULL),
84 FB_IE_INIT_FULL(
"silkAppLabel",
CERT_PEN, 33, 2,
85 FB_IE_F_ENDIAN | FB_IE_IDENTIFIER, 0, 0, FB_UINT_16, NULL),
86 FB_IE_INIT_FULL(
"payloadEntropy",
CERT_PEN, 35, 1, ER, 0, 0,
88 FB_IE_INIT_FULL(
"osName",
CERT_PEN, 36, FB_IE_VARLEN, FB_IE_F_REVERSIBLE,
89 0, 0, FB_STRING, NULL),
90 FB_IE_INIT_FULL(
"osVersion",
CERT_PEN, 37, FB_IE_VARLEN, FB_IE_F_REVERSIBLE,
91 0, 0, FB_STRING, NULL),
92 FB_IE_INIT_FULL(
"firstPacketBanner",
CERT_PEN, 38, FB_IE_VARLEN,
93 FB_IE_F_REVERSIBLE, 0, 0, FB_OCTET_ARRAY, NULL),
94 FB_IE_INIT_FULL(
"secondPacketBanner",
CERT_PEN, 39, FB_IE_VARLEN,
95 FB_IE_F_REVERSIBLE, 0, 0, FB_OCTET_ARRAY, NULL),
96 FB_IE_INIT_FULL(
"flowAttributes",
CERT_PEN, 40, 2, ER | FB_IE_FLAGS, 0, 0,
98 FB_IE_INIT_FULL(
"osFingerPrint",
CERT_PEN, 107, FB_IE_VARLEN,
99 FB_IE_F_REVERSIBLE, 0, 0, FB_STRING, NULL),
100 FB_IE_INIT_FULL(
"expiredFragmentCount",
CERT_PEN, 100, 4,
101 FB_IE_F_ENDIAN | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS,
102 0, 0, FB_UINT_32, NULL),
103 FB_IE_INIT_FULL(
"assembledFragmentCount",
CERT_PEN, 101, 4,
104 FB_IE_F_ENDIAN | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS,
105 0, 0, FB_UINT_32, NULL),
106 FB_IE_INIT_FULL(
"meanFlowRate",
CERT_PEN, 102, 4,
107 FB_IE_F_ENDIAN | FB_UNITS_FLOWS, 0, 0, FB_UINT_32, NULL),
108 FB_IE_INIT_FULL(
"meanPacketRate",
CERT_PEN, 103, 4,
109 FB_IE_F_ENDIAN | FB_UNITS_PACKETS, 0, 0, FB_UINT_32, NULL),
110 FB_IE_INIT_FULL(
"flowTableFlushEventCount",
CERT_PEN, 104, 4,
111 FB_IE_F_ENDIAN | FB_UNITS_FLOWS | FB_IE_TOTALCOUNTER,
112 0, 0, FB_UINT_32, NULL),
113 FB_IE_INIT_FULL(
"flowTablePeakCount",
CERT_PEN, 105, 4,
114 FB_IE_F_ENDIAN | FB_UNITS_FLOWS, 0, 0, FB_UINT_32, NULL),
115 FB_IE_INIT_FULL(
"yafFlowKeyHash",
CERT_PEN, 106, 4,
116 FB_IE_F_ENDIAN | FB_IE_IDENTIFIER, 0, 0, FB_UINT_32, NULL),
117 FB_IE_INIT_FULL(
"mptcpInitialDataSequenceNumber",
CERT_PEN, 289, 8,
118 FB_IE_F_ENDIAN, 0, 0, FB_UINT_64, NULL),
119 FB_IE_INIT_FULL(
"mptcpReceiverToken",
CERT_PEN, 290, 4,
120 FB_IE_F_ENDIAN | FB_IE_IDENTIFIER, 0, 0, FB_UINT_32, NULL),
121 FB_IE_INIT_FULL(
"mptcpMaximumSegmentSize",
CERT_PEN, 291, 2,
122 FB_IE_F_ENDIAN , 0, 0, FB_UINT_16, NULL),
123 FB_IE_INIT_FULL(
"mptcpAddressID",
CERT_PEN, 292, 1,
124 FB_IE_F_ENDIAN | FB_IE_IDENTIFIER, 0, 0, FB_UINT_8, NULL),
125 FB_IE_INIT_FULL(
"mptcpFlags",
CERT_PEN, 293, 1,
126 FB_IE_F_ENDIAN | FB_IE_FLAGS, 0, 0, FB_UINT_8, NULL),
128 FB_IE_INIT_FULL(
"smallPacketCount",
CERT_PEN, 500, 4,
129 ER | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS, 0, 0,
131 FB_IE_INIT_FULL(
"nonEmptyPacketCount",
CERT_PEN, 501, 4,
132 ER | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS, 0, 0,
134 FB_IE_INIT_FULL(
"dataByteCount",
CERT_PEN, 502, 8,
135 ER | FB_IE_TOTALCOUNTER | FB_UNITS_OCTETS, 0, 0,
137 FB_IE_INIT_FULL(
"averageInterarrivalTime",
CERT_PEN, 503, 8,
138 ER | FB_UNITS_MILLISECONDS, 0, 0, FB_UINT_64, NULL),
139 FB_IE_INIT_FULL(
"standardDeviationInterarrivalTime",
CERT_PEN, 504, 8,
140 ER | FB_UNITS_MILLISECONDS, 0, 0, FB_UINT_64, NULL),
141 FB_IE_INIT_FULL(
"firstNonEmptyPacketSize",
CERT_PEN, 505, 2,
142 ER | FB_IE_QUANTITY | FB_UNITS_OCTETS, 0, 0,
144 FB_IE_INIT_FULL(
"maxPacketSize",
CERT_PEN, 506, 2,
145 ER | FB_IE_QUANTITY | FB_UNITS_OCTETS, 0, 0,
147 FB_IE_INIT_FULL(
"firstEightNonEmptyPacketDirections",
CERT_PEN, 507, 1,
148 ER | FB_IE_FLAGS, 0, 0, FB_UINT_8, NULL),
149 FB_IE_INIT_FULL(
"standardDeviationPayloadLength",
CERT_PEN, 508, 2,
150 ER | FB_UNITS_OCTETS, 0, 0, FB_UINT_16, NULL),
151 FB_IE_INIT_FULL(
"tcpUrgentCount",
CERT_PEN, 509, 4,
152 ER | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS, 0, 0,
154 FB_IE_INIT_FULL(
"largePacketCount",
CERT_PEN, 510, 4,
155 ER | FB_IE_TOTALCOUNTER | FB_UNITS_PACKETS, 0, 0,
164 static fbInfoElement_t yaf_dpi_info_elements[] = {
165 FB_IE_INIT_FULL(
"httpServerString",
CERT_PEN, 110, FB_IE_VARLEN, NONE,
166 0, 0, FB_STRING, NULL),
167 FB_IE_INIT_FULL(
"httpUserAgent",
CERT_PEN, 111, FB_IE_VARLEN, NONE,
168 0, 0, FB_STRING, NULL),
169 FB_IE_INIT_FULL(
"httpGet",
CERT_PEN, 112, FB_IE_VARLEN, NONE,
170 0, 0, FB_STRING, NULL),
171 FB_IE_INIT_FULL(
"httpConnection",
CERT_PEN, 113, FB_IE_VARLEN, NONE,
172 0, 0, FB_STRING, NULL),
173 FB_IE_INIT_FULL(
"httpVersion",
CERT_PEN, 114, FB_IE_VARLEN, NONE,
174 0, 0, FB_STRING, NULL),
175 FB_IE_INIT_FULL(
"httpReferer",
CERT_PEN, 115, FB_IE_VARLEN, NONE,
176 0, 0, FB_STRING, NULL),
177 FB_IE_INIT_FULL(
"httpLocation",
CERT_PEN, 116, FB_IE_VARLEN, NONE,
178 0, 0, FB_STRING, NULL),
179 FB_IE_INIT_FULL(
"httpHost",
CERT_PEN, 117, FB_IE_VARLEN, NONE,
180 0, 0, FB_STRING, NULL),
181 FB_IE_INIT_FULL(
"httpContentLength",
CERT_PEN, 118, FB_IE_VARLEN, NONE,
182 0, 0, FB_STRING, NULL),
183 FB_IE_INIT_FULL(
"httpAge",
CERT_PEN, 119, FB_IE_VARLEN, NONE,
184 0, 0, FB_STRING, NULL),
185 FB_IE_INIT_FULL(
"httpAccept",
CERT_PEN, 120, FB_IE_VARLEN, NONE,
186 0, 0, FB_STRING, NULL),
187 FB_IE_INIT_FULL(
"httpAcceptLanguage",
CERT_PEN, 121, FB_IE_VARLEN, NONE,
188 0, 0, FB_STRING, NULL),
189 FB_IE_INIT_FULL(
"httpContentType",
CERT_PEN, 122, FB_IE_VARLEN, NONE,
190 0, 0, FB_STRING, NULL),
191 FB_IE_INIT_FULL(
"httpResponse",
CERT_PEN, 123, FB_IE_VARLEN, NONE,
192 0, 0, FB_STRING, NULL),
193 FB_IE_INIT_FULL(
"httpCookie",
CERT_PEN, 220, FB_IE_VARLEN, NONE,
194 0, 0, FB_STRING, NULL),
195 FB_IE_INIT_FULL(
"httpSetCookie",
CERT_PEN, 221, FB_IE_VARLEN, NONE,
196 0, 0, FB_STRING, NULL),
197 FB_IE_INIT_FULL(
"httpAuthorization",
CERT_PEN, 252, FB_IE_VARLEN, NONE,
198 0, 0, FB_STRING, NULL),
199 FB_IE_INIT_FULL(
"httpVia",
CERT_PEN, 253, FB_IE_VARLEN, NONE,
200 0, 0, FB_STRING, NULL),
201 FB_IE_INIT_FULL(
"httpX-Forwarded-For",
CERT_PEN, 254, FB_IE_VARLEN, NONE,
202 0, 0, FB_STRING, NULL),
203 FB_IE_INIT_FULL(
"httpRefresh",
CERT_PEN, 256, FB_IE_VARLEN, NONE,
204 0, 0, FB_STRING, NULL),
206 FB_IE_INIT_FULL(
"httpIMEI",
CERT_PEN, 257, FB_IE_VARLEN, NONE,
207 0, 0, FB_STRING, NULL),
208 FB_IE_INIT_FULL(
"httpIMSI",
CERT_PEN, 258, FB_IE_VARLEN, NONE,
209 0, 0, FB_STRING, NULL),
210 FB_IE_INIT_FULL(
"httpMSISDN",
CERT_PEN, 259, FB_IE_VARLEN, NONE,
211 0, 0, FB_STRING, NULL),
212 FB_IE_INIT_FULL(
"httpSubscriber",
CERT_PEN, 260, FB_IE_VARLEN, NONE,
213 0, 0, FB_STRING, NULL),
215 FB_IE_INIT_FULL(
"httpExpires",
CERT_PEN, 255, FB_IE_VARLEN, NONE,
216 0, 0, FB_STRING, NULL),
217 FB_IE_INIT_FULL(
"httpAcceptCharset",
CERT_PEN, 261, FB_IE_VARLEN, NONE,
218 0, 0, FB_STRING, NULL),
219 FB_IE_INIT_FULL(
"httpAcceptEncoding",
CERT_PEN, 262, FB_IE_VARLEN, NONE,
220 0, 0, FB_STRING, NULL),
221 FB_IE_INIT_FULL(
"httpAllow",
CERT_PEN, 263, FB_IE_VARLEN, NONE,
222 0, 0, FB_STRING, NULL),
223 FB_IE_INIT_FULL(
"httpDate",
CERT_PEN, 264, FB_IE_VARLEN, NONE,
224 0, 0, FB_STRING, NULL),
225 FB_IE_INIT_FULL(
"httpExpect",
CERT_PEN, 265, FB_IE_VARLEN, NONE,
226 0, 0, FB_STRING, NULL),
227 FB_IE_INIT_FULL(
"httpFrom",
CERT_PEN, 266, FB_IE_VARLEN, NONE,
228 0, 0, FB_STRING, NULL),
229 FB_IE_INIT_FULL(
"httpProxyAuthentication",
CERT_PEN, 267, FB_IE_VARLEN,
230 NONE, 0, 0, FB_STRING, NULL),
231 FB_IE_INIT_FULL(
"httpUpgrade",
CERT_PEN, 268, FB_IE_VARLEN, NONE,
232 0, 0, FB_STRING, NULL),
233 FB_IE_INIT_FULL(
"httpWarning",
CERT_PEN, 269, FB_IE_VARLEN, NONE,
234 0, 0, FB_STRING, NULL),
235 FB_IE_INIT_FULL(
"httpDNT",
CERT_PEN, 270, FB_IE_VARLEN, NONE,
236 0, 0, FB_STRING, NULL),
237 FB_IE_INIT_FULL(
"httpX-Forwarded-Proto",
CERT_PEN, 271, FB_IE_VARLEN,
238 NONE, 0, 0, FB_STRING, NULL),
239 FB_IE_INIT_FULL(
"httpX-Forwarded-Host",
CERT_PEN, 272, FB_IE_VARLEN, NONE,
240 0, 0, FB_STRING, NULL),
241 FB_IE_INIT_FULL(
"httpX-Forwarded-Server",
CERT_PEN, 273, FB_IE_VARLEN,
242 NONE, 0, 0, FB_STRING, NULL),
243 FB_IE_INIT_FULL(
"httpX-DeviceID",
CERT_PEN, 274, FB_IE_VARLEN, NONE,
244 0, 0, FB_STRING, NULL),
245 FB_IE_INIT_FULL(
"httpX-Profile",
CERT_PEN, 275, FB_IE_VARLEN, NONE,
246 0, 0, FB_STRING, NULL),
247 FB_IE_INIT_FULL(
"httpLastModified",
CERT_PEN, 276, FB_IE_VARLEN, NONE,
248 0, 0, FB_STRING, NULL),
249 FB_IE_INIT_FULL(
"httpContentEncoding",
CERT_PEN, 277, FB_IE_VARLEN, NONE,
250 0, 0, FB_STRING, NULL),
251 FB_IE_INIT_FULL(
"httpContentLanguage",
CERT_PEN, 278, FB_IE_VARLEN, NONE,
252 0, 0, FB_STRING, NULL),
253 FB_IE_INIT_FULL(
"httpContentLocation",
CERT_PEN, 279, FB_IE_VARLEN, NONE,
254 0, 0, FB_STRING, NULL),
255 FB_IE_INIT_FULL(
"httpX-UA-Compatible",
CERT_PEN, 280, FB_IE_VARLEN, NONE,
256 0, 0, FB_STRING, NULL),
258 FB_IE_INIT_FULL(
"pop3TextMessage",
CERT_PEN, 124, FB_IE_VARLEN, NONE,
259 0, 0, FB_STRING, NULL),
261 FB_IE_INIT_FULL(
"ircTextMessage",
CERT_PEN, 125, FB_IE_VARLEN, NONE,
262 0, 0, FB_STRING, NULL),
264 FB_IE_INIT_FULL(
"tftpFilename",
CERT_PEN, 126, FB_IE_VARLEN, NONE,
265 0, 0, FB_STRING, NULL),
266 FB_IE_INIT_FULL(
"tftpMode",
CERT_PEN, 127, FB_IE_VARLEN, NONE,
267 0, 0, FB_STRING, NULL),
269 FB_IE_INIT_FULL(
"slpVersion",
CERT_PEN, 128, 1, FB_IE_F_ENDIAN,
270 0, 0, FB_UINT_8, NULL),
271 FB_IE_INIT_FULL(
"slpMessageType",
CERT_PEN, 129, 1, FB_IE_F_ENDIAN,
272 0, 0, FB_UINT_8, NULL),
273 FB_IE_INIT_FULL(
"slpString",
CERT_PEN, 130, FB_IE_VARLEN, NONE,
274 0, 0, FB_STRING, NULL),
276 FB_IE_INIT_FULL(
"ftpReturn",
CERT_PEN, 131, FB_IE_VARLEN, NONE,
277 0, 0, FB_STRING, NULL),
278 FB_IE_INIT_FULL(
"ftpUser",
CERT_PEN, 132, FB_IE_VARLEN, NONE,
279 0, 0, FB_STRING, NULL),
280 FB_IE_INIT_FULL(
"ftpPass",
CERT_PEN,133, FB_IE_VARLEN, NONE,
281 0, 0, FB_STRING, NULL),
282 FB_IE_INIT_FULL(
"ftpType",
CERT_PEN,134, FB_IE_VARLEN, NONE,
283 0, 0, FB_STRING, NULL),
284 FB_IE_INIT_FULL(
"ftpRespCode",
CERT_PEN,135, FB_IE_VARLEN, NONE,
285 0, 0, FB_STRING, NULL),
287 FB_IE_INIT_FULL(
"imapCapability",
CERT_PEN, 136, FB_IE_VARLEN, NONE,
288 0, 0, FB_STRING, NULL),
289 FB_IE_INIT_FULL(
"imapLogin",
CERT_PEN, 137, FB_IE_VARLEN, NONE,
290 0, 0, FB_STRING, NULL),
291 FB_IE_INIT_FULL(
"imapStartTLS",
CERT_PEN, 138, FB_IE_VARLEN, NONE,
292 0, 0, FB_STRING, NULL),
293 FB_IE_INIT_FULL(
"imapAuthenticate",
CERT_PEN, 139, FB_IE_VARLEN, NONE,
294 0, 0, FB_STRING, NULL),
295 FB_IE_INIT_FULL(
"imapCommand",
CERT_PEN, 140, FB_IE_VARLEN, NONE,
296 0, 0, FB_STRING, NULL),
297 FB_IE_INIT_FULL(
"imapExists",
CERT_PEN, 141, FB_IE_VARLEN, NONE,
298 0, 0, FB_STRING, NULL),
299 FB_IE_INIT_FULL(
"imapRecent",
CERT_PEN, 142, FB_IE_VARLEN, NONE,
300 0, 0, FB_STRING, NULL),
302 FB_IE_INIT_FULL(
"rtspURL",
CERT_PEN, 143, FB_IE_VARLEN, NONE,
303 0, 0, FB_STRING, NULL),
304 FB_IE_INIT_FULL(
"rtspVersion",
CERT_PEN, 144, FB_IE_VARLEN, NONE,
305 0, 0, FB_STRING, NULL),
306 FB_IE_INIT_FULL(
"rtspReturnCode",
CERT_PEN, 145, FB_IE_VARLEN, NONE,
307 0, 0, FB_STRING, NULL),
308 FB_IE_INIT_FULL(
"rtspContentLength",
CERT_PEN, 146, FB_IE_VARLEN, NONE,
309 0, 0, FB_STRING, NULL),
310 FB_IE_INIT_FULL(
"rtspCommand",
CERT_PEN, 147, FB_IE_VARLEN, NONE,
311 0, 0, FB_STRING, NULL),
312 FB_IE_INIT_FULL(
"rtspContentType",
CERT_PEN, 148, FB_IE_VARLEN, NONE,
313 0, 0, FB_STRING, NULL),
314 FB_IE_INIT_FULL(
"rtspTransport",
CERT_PEN, 149, FB_IE_VARLEN, NONE,
315 0, 0, FB_STRING, NULL),
316 FB_IE_INIT_FULL(
"rtspCSeq",
CERT_PEN, 150, FB_IE_VARLEN, NONE,
317 0, 0, FB_STRING, NULL),
318 FB_IE_INIT_FULL(
"rtspLocation",
CERT_PEN, 151, FB_IE_VARLEN, NONE,
319 0, 0, FB_STRING, NULL),
320 FB_IE_INIT_FULL(
"rtspPacketsReceived",
CERT_PEN, 152, FB_IE_VARLEN, NONE,
321 0, 0, FB_STRING, NULL),
322 FB_IE_INIT_FULL(
"rtspUserAgent",
CERT_PEN, 153, FB_IE_VARLEN, NONE,
323 0, 0, FB_STRING, NULL),
324 FB_IE_INIT_FULL(
"rtspJitter",
CERT_PEN, 154, FB_IE_VARLEN, NONE,
325 0, 0, FB_STRING, NULL),
327 FB_IE_INIT_FULL(
"sipInvite",
CERT_PEN, 155, FB_IE_VARLEN, NONE,
328 0, 0, FB_STRING, NULL),
329 FB_IE_INIT_FULL(
"sipCommand",
CERT_PEN, 156, FB_IE_VARLEN, NONE,
330 0, 0, FB_STRING, NULL),
331 FB_IE_INIT_FULL(
"sipVia",
CERT_PEN, 157, FB_IE_VARLEN, NONE,
332 0, 0, FB_STRING, NULL),
333 FB_IE_INIT_FULL(
"sipMaxForwards",
CERT_PEN, 158, FB_IE_VARLEN, NONE,
334 0, 0, FB_STRING, NULL),
335 FB_IE_INIT_FULL(
"sipAddress",
CERT_PEN, 159, FB_IE_VARLEN, NONE,
336 0, 0, FB_STRING, NULL),
337 FB_IE_INIT_FULL(
"sipContentLength",
CERT_PEN, 160, FB_IE_VARLEN, NONE,
338 0, 0, FB_STRING, NULL),
339 FB_IE_INIT_FULL(
"sipUserAgent",
CERT_PEN, 161, FB_IE_VARLEN, NONE,
340 0, 0, FB_STRING, NULL),
342 FB_IE_INIT_FULL(
"smtpHello",
CERT_PEN, 162, FB_IE_VARLEN, NONE,
343 0, 0, FB_STRING, NULL),
344 FB_IE_INIT_FULL(
"smtpFrom",
CERT_PEN, 163, FB_IE_VARLEN, NONE,
345 0, 0, FB_STRING, NULL),
346 FB_IE_INIT_FULL(
"smtpTo",
CERT_PEN, 164, FB_IE_VARLEN, NONE,
347 0, 0, FB_STRING, NULL),
348 FB_IE_INIT_FULL(
"smtpContentType",
CERT_PEN, 165, FB_IE_VARLEN, NONE,
349 0, 0, FB_STRING, NULL),
350 FB_IE_INIT_FULL(
"smtpSubject",
CERT_PEN, 166, FB_IE_VARLEN, NONE,
351 0, 0, FB_STRING, NULL),
352 FB_IE_INIT_FULL(
"smtpFilename",
CERT_PEN, 167, FB_IE_VARLEN, NONE,
353 0, 0, FB_STRING, NULL),
354 FB_IE_INIT_FULL(
"smtpContentDisposition",
CERT_PEN, 168, FB_IE_VARLEN,
355 NONE, 0, 0, FB_STRING, NULL),
356 FB_IE_INIT_FULL(
"smtpResponse",
CERT_PEN, 169, FB_IE_VARLEN, NONE,
357 0, 0, FB_STRING, NULL),
358 FB_IE_INIT_FULL(
"smtpEnhanced",
CERT_PEN, 170, FB_IE_VARLEN, NONE,
359 0, 0, FB_STRING, NULL),
360 FB_IE_INIT_FULL(
"smtpSize",
CERT_PEN, 222, FB_IE_VARLEN, NONE,
361 0, 0, FB_STRING, NULL),
362 FB_IE_INIT_FULL(
"smtpDate",
CERT_PEN, 251, FB_IE_VARLEN, NONE,
363 0, 0, FB_STRING, NULL),
365 FB_IE_INIT_FULL(
"sshVersion",
CERT_PEN, 171, FB_IE_VARLEN, NONE,
366 0, 0, FB_STRING, NULL),
368 FB_IE_INIT_FULL(
"nntpResponse",
CERT_PEN, 172, FB_IE_VARLEN, NONE,
369 0, 0, FB_STRING, NULL),
370 FB_IE_INIT_FULL(
"nntpCommand",
CERT_PEN, 173, FB_IE_VARLEN, NONE,
371 0, 0, FB_STRING, NULL),
373 FB_IE_INIT_FULL(
"dnsQueryResponse",
CERT_PEN, 174, 1, FB_IE_F_ENDIAN,
374 0, 0, FB_UINT_8, NULL),
375 FB_IE_INIT_FULL(
"dnsQRType",
CERT_PEN, 175, 2, FB_IE_F_ENDIAN,
376 0, 0, FB_UINT_16, NULL),
377 FB_IE_INIT_FULL(
"dnsAuthoritative",
CERT_PEN, 176, 1, FB_IE_F_ENDIAN,
378 0, 0, FB_UINT_8, NULL),
379 FB_IE_INIT_FULL(
"dnsNXDomain",
CERT_PEN, 177, 1, FB_IE_F_ENDIAN,
380 0, 0, FB_UINT_8, NULL),
381 FB_IE_INIT_FULL(
"dnsRRSection",
CERT_PEN, 178, 1, FB_IE_F_ENDIAN,
382 0, 0, FB_UINT_8, NULL),
383 FB_IE_INIT_FULL(
"dnsQName",
CERT_PEN, 179, FB_IE_VARLEN, NONE,
384 0, 0, FB_STRING, NULL),
385 FB_IE_INIT_FULL(
"dnsCName",
CERT_PEN, 180, FB_IE_VARLEN, NONE,
386 0, 0, FB_STRING, NULL),
387 FB_IE_INIT_FULL(
"dnsMXPreference",
CERT_PEN, 181, 2, FB_IE_F_ENDIAN,
388 0, 0, FB_UINT_16, NULL),
389 FB_IE_INIT_FULL(
"dnsMXExchange",
CERT_PEN, 182, FB_IE_VARLEN, NONE,
390 0, 0, FB_STRING, NULL),
391 FB_IE_INIT_FULL(
"dnsNSDName",
CERT_PEN, 183, FB_IE_VARLEN, NONE,
392 0, 0, FB_STRING, NULL),
393 FB_IE_INIT_FULL(
"dnsPTRDName",
CERT_PEN, 184, FB_IE_VARLEN, NONE,
394 0, 0, FB_STRING, NULL),
395 FB_IE_INIT_FULL(
"dnsTTL",
CERT_PEN, 199, 4, FB_IE_F_ENDIAN,
396 0, 0, FB_UINT_32, NULL),
397 FB_IE_INIT_FULL(
"dnsTXTData",
CERT_PEN, 208, FB_IE_VARLEN, NONE,
398 0, 0, FB_STRING, NULL),
399 FB_IE_INIT_FULL(
"dnsSOASerial",
CERT_PEN, 209, 4, FB_IE_F_ENDIAN,
400 0, 0, FB_UINT_32, NULL),
401 FB_IE_INIT_FULL(
"dnsSOARefresh",
CERT_PEN, 210, 4, FB_IE_F_ENDIAN,
402 0, 0, FB_UINT_32, NULL),
403 FB_IE_INIT_FULL(
"dnsSOARetry",
CERT_PEN, 211, 4, FB_IE_F_ENDIAN,
404 0, 0, FB_UINT_32, NULL),
405 FB_IE_INIT_FULL(
"dnsSOAExpire",
CERT_PEN, 212, 4, FB_IE_F_ENDIAN,
406 0, 0, FB_UINT_32, NULL),
407 FB_IE_INIT_FULL(
"dnsSOAMinimum",
CERT_PEN, 213, 4, FB_IE_F_ENDIAN,
408 0, 0, FB_UINT_32, NULL),
409 FB_IE_INIT_FULL(
"dnsSOAMName",
CERT_PEN, 214, FB_IE_VARLEN, NONE,
410 0, 0, FB_STRING, NULL),
411 FB_IE_INIT_FULL(
"dnsSOARName",
CERT_PEN, 215, FB_IE_VARLEN, NONE,
412 0, 0, FB_STRING, NULL),
413 FB_IE_INIT_FULL(
"dnsSRVPriority",
CERT_PEN, 216, 2, FB_IE_F_ENDIAN,
414 0, 0, FB_UINT_16, NULL),
415 FB_IE_INIT_FULL(
"dnsSRVWeight",
CERT_PEN, 217, 2, FB_IE_F_ENDIAN,
416 0, 0, FB_UINT_16, NULL),
417 FB_IE_INIT_FULL(
"dnsSRVPort",
CERT_PEN, 218, 2, FB_IE_F_ENDIAN,
418 0, 0, FB_UINT_16, NULL),
419 FB_IE_INIT_FULL(
"dnsSRVTarget",
CERT_PEN, 219, FB_IE_VARLEN, NONE,
420 0, 0, FB_STRING, NULL),
421 FB_IE_INIT_FULL(
"dnsID",
CERT_PEN, 226, 2, FB_IE_F_ENDIAN,
422 0, 0, FB_UINT_16, NULL),
424 FB_IE_INIT_FULL(
"dnsAlgorithm",
CERT_PEN, 227, 1, FB_IE_F_ENDIAN,
425 0, 0, FB_UINT_8, NULL),
426 FB_IE_INIT_FULL(
"dnsKeyTag",
CERT_PEN, 228, 2, FB_IE_F_ENDIAN,
427 0, 0, FB_UINT_16, NULL),
428 FB_IE_INIT_FULL(
"dnsSigner",
CERT_PEN, 229, FB_IE_VARLEN, NONE,
429 0, 0, FB_STRING, NULL),
430 FB_IE_INIT_FULL(
"dnsSignature",
CERT_PEN, 230, FB_IE_VARLEN, NONE,
431 0, 0, FB_OCTET_ARRAY, NULL),
432 FB_IE_INIT_FULL(
"dnsDigest",
CERT_PEN, 231, FB_IE_VARLEN, NONE,
433 0, 0, FB_OCTET_ARRAY, NULL),
434 FB_IE_INIT_FULL(
"dnsPublicKey",
CERT_PEN, 232, FB_IE_VARLEN, NONE,
435 0, 0, FB_OCTET_ARRAY, NULL),
436 FB_IE_INIT_FULL(
"dnsSalt",
CERT_PEN, 233, FB_IE_VARLEN, NONE,
437 0, 0, FB_OCTET_ARRAY, NULL),
438 FB_IE_INIT_FULL(
"dnsHashData",
CERT_PEN, 234, FB_IE_VARLEN, NONE,
439 0, 0, FB_OCTET_ARRAY, NULL),
440 FB_IE_INIT_FULL(
"dnsIterations",
CERT_PEN, 235, 2, FB_IE_F_ENDIAN,
441 0, 0, FB_UINT_16, NULL),
442 FB_IE_INIT_FULL(
"dnsSignatureExpiration",
CERT_PEN, 236, 4,
443 FB_IE_F_ENDIAN, 0, 0, FB_UINT_32, NULL),
444 FB_IE_INIT_FULL(
"dnsSignatureInception",
CERT_PEN, 237, 4, FB_IE_F_ENDIAN,
445 0, 0, FB_UINT_32, NULL),
446 FB_IE_INIT_FULL(
"dnsDigestType",
CERT_PEN, 238, 1, FB_IE_F_ENDIAN,
447 0, 0, FB_UINT_8, NULL),
448 FB_IE_INIT_FULL(
"dnsLabels",
CERT_PEN, 239, 1, FB_IE_F_ENDIAN,
449 0, 0, FB_UINT_8, NULL),
450 FB_IE_INIT_FULL(
"dnsTypeCovered",
CERT_PEN, 240, 2, FB_IE_F_ENDIAN,
451 0, 0, FB_UINT_16, NULL),
452 FB_IE_INIT_FULL(
"dnsFlags",
CERT_PEN, 241, 2,
453 FB_IE_F_ENDIAN | FB_IE_FLAGS, 0, 0, FB_UINT_16, NULL),
455 FB_IE_INIT_FULL(
"sslCipher",
CERT_PEN, 185, 4, FB_IE_F_ENDIAN,
456 0, 0, FB_UINT_32, NULL),
457 FB_IE_INIT_FULL(
"sslClientVersion",
CERT_PEN, 186, 1, FB_IE_F_ENDIAN,
458 0, 0, FB_UINT_8, NULL),
459 FB_IE_INIT_FULL(
"sslServerCipher",
CERT_PEN, 187, 4, FB_IE_F_ENDIAN,
460 0, 0, FB_UINT_32, NULL),
461 FB_IE_INIT_FULL(
"sslCompressionMethod",
CERT_PEN, 188, 1, FB_IE_F_ENDIAN,
462 0, 0, FB_UINT_8, NULL),
463 FB_IE_INIT_FULL(
"sslCertVersion",
CERT_PEN, 189, 1, FB_IE_F_ENDIAN,
464 0, 0, FB_UINT_8, NULL),
465 FB_IE_INIT_FULL(
"sslCertSignature",
CERT_PEN, 190, FB_IE_VARLEN, NONE,
466 0, 0, FB_OCTET_ARRAY, NULL),
467 FB_IE_INIT_FULL(
"sslCertSerialNumber",
CERT_PEN, 244, FB_IE_VARLEN, NONE,
468 0, 0, FB_OCTET_ARRAY, NULL),
469 FB_IE_INIT_FULL(
"sslObjectType",
CERT_PEN, 245, 1, FB_IE_F_ENDIAN,
470 0, 0, FB_UINT_8, NULL),
471 FB_IE_INIT_FULL(
"sslObjectValue",
CERT_PEN, 246, FB_IE_VARLEN, NONE,
472 0, 0, FB_OCTET_ARRAY, NULL),
473 FB_IE_INIT_FULL(
"sslCertValidityNotBefore",
CERT_PEN, 247, FB_IE_VARLEN,
474 NONE, 0, 0, FB_STRING, NULL),
475 FB_IE_INIT_FULL(
"sslCertValidityNotAfter",
CERT_PEN, 248, FB_IE_VARLEN,
476 NONE, 0, 0, FB_STRING, NULL),
477 FB_IE_INIT_FULL(
"sslPublicKeyAlgorithm",
CERT_PEN, 249, FB_IE_VARLEN,
478 NONE, 0, 0, FB_OCTET_ARRAY, NULL),
479 FB_IE_INIT_FULL(
"sslPublicKeyLength",
CERT_PEN, 250, 2, FB_IE_F_ENDIAN,
480 0, 0, FB_UINT_16, NULL),
481 FB_IE_INIT_FULL(
"sslServerName",
CERT_PEN, 294, FB_IE_VARLEN, NONE,
482 0, 0, FB_STRING, NULL),
483 FB_IE_INIT_FULL(
"sslCertificateHash",
CERT_PEN, 295, FB_IE_VARLEN, NONE,
484 0, 0, FB_OCTET_ARRAY, NULL),
485 FB_IE_INIT_FULL(
"sslCertificate",
CERT_PEN, 296, FB_IE_VARLEN, NONE,
486 0, 0, FB_OCTET_ARRAY, NULL),
488 FB_IE_INIT_FULL(
"mysqlUsername",
CERT_PEN, 223, FB_IE_VARLEN, NONE,
489 0, 0, FB_STRING, NULL),
490 FB_IE_INIT_FULL(
"mysqlCommandCode",
CERT_PEN, 224, 1, FB_IE_F_ENDIAN,
491 0, 0, FB_UINT_8, NULL),
492 FB_IE_INIT_FULL(
"mysqlCommandText",
CERT_PEN, 225, FB_IE_VARLEN, NONE,
493 0, 0, FB_STRING, NULL),
495 FB_IE_INIT_FULL(
"dnp3SourceAddress",
CERT_PEN, 281, 2, FB_IE_F_ENDIAN,
496 0, 0, FB_UINT_16, NULL),
497 FB_IE_INIT_FULL(
"dnp3DestinationAddress",
CERT_PEN, 282, 2,
498 FB_IE_F_ENDIAN, 0, 0, FB_UINT_16, NULL),
499 FB_IE_INIT_FULL(
"dnp3Function",
CERT_PEN, 283, 1, FB_IE_F_ENDIAN,
500 0, 0, FB_UINT_8, NULL),
501 FB_IE_INIT_FULL(
"dnp3ObjectData",
CERT_PEN, 284, FB_IE_VARLEN, NONE,
502 0, 0, FB_OCTET_ARRAY, NULL),
503 FB_IE_INIT_FULL(
"modbusData",
CERT_PEN, 285, FB_IE_VARLEN, NONE,
504 0, 0, FB_OCTET_ARRAY, NULL),
505 FB_IE_INIT_FULL(
"ethernetIPData",
CERT_PEN, 286, FB_IE_VARLEN, NONE,
506 0, 0, FB_OCTET_ARRAY, NULL),
507 FB_IE_INIT_FULL(
"rtpPayloadType",
CERT_PEN, 287, 1, ER,
508 0, 0, FB_UINT_8, NULL),
509 FB_IE_INIT_FULL(
"sslRecordVersion",
CERT_PEN, 288, 2, FB_IE_F_ENDIAN,
510 0, 0, FB_UINT_16, NULL),
514 static fbInfoElement_t yaf_dhcp_info_elements[] = {
515 FB_IE_INIT_FULL(
"dhcpFingerPrint",
CERT_PEN, 242, FB_IE_VARLEN,
516 FB_IE_F_REVERSIBLE, 0, 0, FB_STRING, NULL),
517 FB_IE_INIT_FULL(
"dhcpVendorCode",
CERT_PEN, 243, FB_IE_VARLEN,
518 FB_IE_F_REVERSIBLE, 0, 0, FB_STRING, NULL),
519 FB_IE_INIT_FULL(
"dhcpOption",
CERT_PEN, 297, 1, FB_IE_F_ENDIAN,
520 0, 0, FB_UINT_8, NULL),
#define CERT_PEN
This is the CERT Private Enterprise Number (PEN) assigned by IANA, used to define our enterprise data...
Definition: yafcore.h:110