Advertisement
Guest User

Untitled

a guest
Oct 9th, 2015
100
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 24.75 KB | None | 0 0
  1. {
  2. "dnp3": {
  3. "response": {
  4. "iin": {
  5. "indicators": []
  6. },
  7. "application": {
  8. "complete": false,
  9. "objects": [
  10. {
  11. "items": [
  12. {
  13. "state": 0,
  14. "reserved": 0,
  15. "prefix": 0,
  16. "index": 0,
  17. "online": 0,
  18. "restart": 1,
  19. "comm_lost": 0,
  20. "remote_forced": 0,
  21. "local_forced": 0,
  22. "chatter_filter": 0
  23. },
  24. {
  25. "state": 0,
  26. "reserved": 0,
  27. "prefix": 0,
  28. "index": 1,
  29. "online": 0,
  30. "restart": 1,
  31. "comm_lost": 0,
  32. "remote_forced": 0,
  33. "local_forced": 0,
  34. "chatter_filter": 0
  35. },
  36. {
  37. "state": 0,
  38. "reserved": 0,
  39. "prefix": 0,
  40. "index": 2,
  41. "online": 0,
  42. "restart": 1,
  43. "comm_lost": 0,
  44. "remote_forced": 0,
  45. "local_forced": 0,
  46. "chatter_filter": 0
  47. },
  48. {
  49. "state": 0,
  50. "reserved": 0,
  51. "prefix": 0,
  52. "index": 3,
  53. "online": 0,
  54. "restart": 1,
  55. "comm_lost": 0,
  56. "remote_forced": 0,
  57. "local_forced": 0,
  58. "chatter_filter": 0
  59. },
  60. {
  61. "state": 0,
  62. "reserved": 0,
  63. "prefix": 0,
  64. "index": 4,
  65. "online": 0,
  66. "restart": 1,
  67. "comm_lost": 0,
  68. "remote_forced": 0,
  69. "local_forced": 0,
  70. "chatter_filter": 0
  71. },
  72. {
  73. "state": 0,
  74. "reserved": 0,
  75. "prefix": 0,
  76. "index": 5,
  77. "online": 0,
  78. "restart": 1,
  79. "comm_lost": 0,
  80. "remote_forced": 0,
  81. "local_forced": 0,
  82. "chatter_filter": 0
  83. },
  84. {
  85. "state": 0,
  86. "reserved": 0,
  87. "prefix": 0,
  88. "index": 6,
  89. "online": 0,
  90. "restart": 1,
  91. "comm_lost": 0,
  92. "remote_forced": 0,
  93. "local_forced": 0,
  94. "chatter_filter": 0
  95. },
  96. {
  97. "state": 0,
  98. "reserved": 0,
  99. "prefix": 0,
  100. "index": 7,
  101. "online": 0,
  102. "restart": 1,
  103. "comm_lost": 0,
  104. "remote_forced": 0,
  105. "local_forced": 0,
  106. "chatter_filter": 0
  107. },
  108. {
  109. "state": 0,
  110. "reserved": 0,
  111. "prefix": 0,
  112. "index": 8,
  113. "online": 0,
  114. "restart": 1,
  115. "comm_lost": 0,
  116. "remote_forced": 0,
  117. "local_forced": 0,
  118. "chatter_filter": 0
  119. },
  120. {
  121. "state": 0,
  122. "reserved": 0,
  123. "prefix": 0,
  124. "index": 9,
  125. "online": 0,
  126. "restart": 1,
  127. "comm_lost": 0,
  128. "remote_forced": 0,
  129. "local_forced": 0,
  130. "chatter_filter": 0
  131. }
  132. ],
  133. "group": 1,
  134. "variation": 2,
  135. "qualifier": 0,
  136. "prefix_code": 0,
  137. "range_code": 0,
  138. "start": 0,
  139. "stop": 9,
  140. "count": 10
  141. },
  142. {
  143. "items": [
  144. {
  145. "state": 0,
  146. "prefix": 0,
  147. "index": 0,
  148. "online": 0,
  149. "restart": 1,
  150. "comm_lost": 0,
  151. "remote_forced": 0,
  152. "local_forced": 0,
  153. "chatter_filter": 0
  154. },
  155. {
  156. "state": 0,
  157. "prefix": 0,
  158. "index": 1,
  159. "online": 0,
  160. "restart": 1,
  161. "comm_lost": 0,
  162. "remote_forced": 0,
  163. "local_forced": 0,
  164. "chatter_filter": 0
  165. },
  166. {
  167. "state": 0,
  168. "prefix": 0,
  169. "index": 2,
  170. "online": 0,
  171. "restart": 1,
  172. "comm_lost": 0,
  173. "remote_forced": 0,
  174. "local_forced": 0,
  175. "chatter_filter": 0
  176. },
  177. {
  178. "state": 0,
  179. "prefix": 0,
  180. "index": 3,
  181. "online": 0,
  182. "restart": 1,
  183. "comm_lost": 0,
  184. "remote_forced": 0,
  185. "local_forced": 0,
  186. "chatter_filter": 0
  187. },
  188. {
  189. "state": 0,
  190. "prefix": 0,
  191. "index": 4,
  192. "online": 0,
  193. "restart": 1,
  194. "comm_lost": 0,
  195. "remote_forced": 0,
  196. "local_forced": 0,
  197. "chatter_filter": 0
  198. },
  199. {
  200. "state": 0,
  201. "prefix": 0,
  202. "index": 5,
  203. "online": 0,
  204. "restart": 1,
  205. "comm_lost": 0,
  206. "remote_forced": 0,
  207. "local_forced": 0,
  208. "chatter_filter": 0
  209. },
  210. {
  211. "state": 0,
  212. "prefix": 0,
  213. "index": 6,
  214. "online": 0,
  215. "restart": 1,
  216. "comm_lost": 0,
  217. "remote_forced": 0,
  218. "local_forced": 0,
  219. "chatter_filter": 0
  220. },
  221. {
  222. "state": 0,
  223. "prefix": 0,
  224. "index": 7,
  225. "online": 0,
  226. "restart": 1,
  227. "comm_lost": 0,
  228. "remote_forced": 0,
  229. "local_forced": 0,
  230. "chatter_filter": 0
  231. },
  232. {
  233. "state": 0,
  234. "prefix": 0,
  235. "index": 8,
  236. "online": 0,
  237. "restart": 1,
  238. "comm_lost": 0,
  239. "remote_forced": 0,
  240. "local_forced": 0,
  241. "chatter_filter": 0
  242. },
  243. {
  244. "state": 0,
  245. "prefix": 0,
  246. "index": 9,
  247. "online": 0,
  248. "restart": 1,
  249. "comm_lost": 0,
  250. "remote_forced": 0,
  251. "local_forced": 0,
  252. "chatter_filter": 0
  253. }
  254. ],
  255. "group": 3,
  256. "variation": 2,
  257. "qualifier": 0,
  258. "prefix_code": 0,
  259. "range_code": 0,
  260. "start": 0,
  261. "stop": 9,
  262. "count": 10
  263. },
  264. {
  265. "items": [
  266. {
  267. "count": 0,
  268. "discontinuity": 0,
  269. "prefix": 0,
  270. "index": 0,
  271. "online": 0,
  272. "restart": 1,
  273. "comm_lost": 0,
  274. "remote_forced": 0,
  275. "local_forced": 0,
  276. "rollover": 0
  277. },
  278. {
  279. "count": 0,
  280. "discontinuity": 0,
  281. "prefix": 0,
  282. "index": 1,
  283. "online": 0,
  284. "restart": 1,
  285. "comm_lost": 0,
  286. "remote_forced": 0,
  287. "local_forced": 0,
  288. "rollover": 0
  289. },
  290. {
  291. "count": 0,
  292. "discontinuity": 0,
  293. "prefix": 0,
  294. "index": 2,
  295. "online": 0,
  296. "restart": 1,
  297. "comm_lost": 0,
  298. "remote_forced": 0,
  299. "local_forced": 0,
  300. "rollover": 0
  301. },
  302. {
  303. "count": 0,
  304. "discontinuity": 0,
  305. "prefix": 0,
  306. "index": 3,
  307. "online": 0,
  308. "restart": 1,
  309. "comm_lost": 0,
  310. "remote_forced": 0,
  311. "local_forced": 0,
  312. "rollover": 0
  313. },
  314. {
  315. "count": 0,
  316. "discontinuity": 0,
  317. "prefix": 0,
  318. "index": 4,
  319. "online": 0,
  320. "restart": 1,
  321. "comm_lost": 0,
  322. "remote_forced": 0,
  323. "local_forced": 0,
  324. "rollover": 0
  325. },
  326. {
  327. "count": 0,
  328. "discontinuity": 0,
  329. "prefix": 0,
  330. "index": 5,
  331. "online": 0,
  332. "restart": 1,
  333. "comm_lost": 0,
  334. "remote_forced": 0,
  335. "local_forced": 0,
  336. "rollover": 0
  337. },
  338. {
  339. "count": 0,
  340. "discontinuity": 0,
  341. "prefix": 0,
  342. "index": 6,
  343. "online": 0,
  344. "restart": 1,
  345. "comm_lost": 0,
  346. "remote_forced": 0,
  347. "local_forced": 0,
  348. "rollover": 0
  349. },
  350. {
  351. "count": 0,
  352. "discontinuity": 0,
  353. "prefix": 0,
  354. "index": 7,
  355. "online": 0,
  356. "restart": 1,
  357. "comm_lost": 0,
  358. "remote_forced": 0,
  359. "local_forced": 0,
  360. "rollover": 0
  361. },
  362. {
  363. "count": 0,
  364. "discontinuity": 0,
  365. "prefix": 0,
  366. "index": 8,
  367. "online": 0,
  368. "restart": 1,
  369. "comm_lost": 0,
  370. "remote_forced": 0,
  371. "local_forced": 0,
  372. "rollover": 0
  373. },
  374. {
  375. "count": 0,
  376. "discontinuity": 0,
  377. "prefix": 0,
  378. "index": 9,
  379. "online": 0,
  380. "restart": 1,
  381. "comm_lost": 0,
  382. "remote_forced": 0,
  383. "local_forced": 0,
  384. "rollover": 0
  385. }
  386. ],
  387. "group": 20,
  388. "variation": 1,
  389. "qualifier": 0,
  390. "prefix_code": 0,
  391. "range_code": 0,
  392. "start": 0,
  393. "stop": 9,
  394. "count": 10
  395. },
  396. {
  397. "items": [
  398. {
  399. "count": 0,
  400. "discontinuity": 0,
  401. "prefix": 0,
  402. "index": 0,
  403. "online": 0,
  404. "restart": 1,
  405. "comm_lost": 0,
  406. "remote_forced": 0,
  407. "local_forced": 0,
  408. "rollover": 0
  409. },
  410. {
  411. "count": 0,
  412. "discontinuity": 0,
  413. "prefix": 0,
  414. "index": 1,
  415. "online": 0,
  416. "restart": 1,
  417. "comm_lost": 0,
  418. "remote_forced": 0,
  419. "local_forced": 0,
  420. "rollover": 0
  421. },
  422. {
  423. "count": 0,
  424. "discontinuity": 0,
  425. "prefix": 0,
  426. "index": 2,
  427. "online": 0,
  428. "restart": 1,
  429. "comm_lost": 0,
  430. "remote_forced": 0,
  431. "local_forced": 0,
  432. "rollover": 0
  433. },
  434. {
  435. "count": 0,
  436. "discontinuity": 0,
  437. "prefix": 0,
  438. "index": 3,
  439. "online": 0,
  440. "restart": 1,
  441. "comm_lost": 0,
  442. "remote_forced": 0,
  443. "local_forced": 0,
  444. "rollover": 0
  445. },
  446. {
  447. "count": 0,
  448. "discontinuity": 0,
  449. "prefix": 0,
  450. "index": 4,
  451. "online": 0,
  452. "restart": 1,
  453. "comm_lost": 0,
  454. "remote_forced": 0,
  455. "local_forced": 0,
  456. "rollover": 0
  457. },
  458. {
  459. "count": 0,
  460. "discontinuity": 0,
  461. "prefix": 0,
  462. "index": 5,
  463. "online": 0,
  464. "restart": 1,
  465. "comm_lost": 0,
  466. "remote_forced": 0,
  467. "local_forced": 0,
  468. "rollover": 0
  469. },
  470. {
  471. "count": 0,
  472. "discontinuity": 0,
  473. "prefix": 0,
  474. "index": 6,
  475. "online": 0,
  476. "restart": 1,
  477. "comm_lost": 0,
  478. "remote_forced": 0,
  479. "local_forced": 0,
  480. "rollover": 0
  481. },
  482. {
  483. "count": 0,
  484. "discontinuity": 0,
  485. "prefix": 0,
  486. "index": 7,
  487. "online": 0,
  488. "restart": 1,
  489. "comm_lost": 0,
  490. "remote_forced": 0,
  491. "local_forced": 0,
  492. "rollover": 0
  493. },
  494. {
  495. "count": 0,
  496. "discontinuity": 0,
  497. "prefix": 0,
  498. "index": 8,
  499. "online": 0,
  500. "restart": 1,
  501. "comm_lost": 0,
  502. "remote_forced": 0,
  503. "local_forced": 0,
  504. "rollover": 0
  505. },
  506. {
  507. "count": 0,
  508. "discontinuity": 0,
  509. "prefix": 0,
  510. "index": 9,
  511. "online": 0,
  512. "restart": 1,
  513. "comm_lost": 0,
  514. "remote_forced": 0,
  515. "local_forced": 0,
  516. "rollover": 0
  517. }
  518. ],
  519. "group": 21,
  520. "variation": 1,
  521. "qualifier": 0,
  522. "prefix_code": 0,
  523. "range_code": 0,
  524. "start": 0,
  525. "stop": 9,
  526. "count": 10
  527. },
  528. {
  529. "items": [
  530. {
  531. "value": 0,
  532. "reserved": 0,
  533. "reference_err": 0,
  534. "prefix": 0,
  535. "index": 0,
  536. "online": 0,
  537. "restart": 1,
  538. "comm_lost": 0,
  539. "remote_forced": 0,
  540. "local_forced": 0,
  541. "over_range": 0
  542. }
  543. ],
  544. "group": 30,
  545. "variation": 5,
  546. "qualifier": 0,
  547. "prefix_code": 0,
  548. "range_code": 0,
  549. "start": 0,
  550. "stop": 0,
  551. "count": 1
  552. },
  553. {
  554. "items": [
  555. {
  556. "value": 0,
  557. "reserved": 0,
  558. "reference_err": 0,
  559. "prefix": 0,
  560. "index": 1,
  561. "online": 0,
  562. "restart": 1,
  563. "comm_lost": 0,
  564. "remote_forced": 0,
  565. "local_forced": 0,
  566. "over_range": 0
  567. },
  568. {
  569. "value": 0,
  570. "reserved": 0,
  571. "reference_err": 0,
  572. "prefix": 0,
  573. "index": 2,
  574. "online": 0,
  575. "restart": 1,
  576. "comm_lost": 0,
  577. "remote_forced": 0,
  578. "local_forced": 0,
  579. "over_range": 0
  580. },
  581. {
  582. "value": 0,
  583. "reserved": 0,
  584. "reference_err": 0,
  585. "prefix": 0,
  586. "index": 3,
  587. "online": 0,
  588. "restart": 1,
  589. "comm_lost": 0,
  590. "remote_forced": 0,
  591. "local_forced": 0,
  592. "over_range": 0
  593. },
  594. {
  595. "value": 0,
  596. "reserved": 0,
  597. "reference_err": 0,
  598. "prefix": 0,
  599. "index": 4,
  600. "online": 0,
  601. "restart": 1,
  602. "comm_lost": 0,
  603. "remote_forced": 0,
  604. "local_forced": 0,
  605. "over_range": 0
  606. },
  607. {
  608. "value": 0,
  609. "reserved": 0,
  610. "reference_err": 0,
  611. "prefix": 0,
  612. "index": 5,
  613. "online": 0,
  614. "restart": 1,
  615. "comm_lost": 0,
  616. "remote_forced": 0,
  617. "local_forced": 0,
  618. "over_range": 0
  619. },
  620. {
  621. "value": 0,
  622. "reserved": 0,
  623. "reference_err": 0,
  624. "prefix": 0,
  625. "index": 6,
  626. "online": 0,
  627. "restart": 1,
  628. "comm_lost": 0,
  629. "remote_forced": 0,
  630. "local_forced": 0,
  631. "over_range": 0
  632. },
  633. {
  634. "value": 0,
  635. "reserved": 0,
  636. "reference_err": 0,
  637. "prefix": 0,
  638. "index": 7,
  639. "online": 0,
  640. "restart": 1,
  641. "comm_lost": 0,
  642. "remote_forced": 0,
  643. "local_forced": 0,
  644. "over_range": 0
  645. },
  646. {
  647. "value": 0,
  648. "reserved": 0,
  649. "reference_err": 0,
  650. "prefix": 0,
  651. "index": 8,
  652. "online": 0,
  653. "restart": 1,
  654. "comm_lost": 0,
  655. "remote_forced": 0,
  656. "local_forced": 0,
  657. "over_range": 0
  658. },
  659. {
  660. "value": 0,
  661. "reserved": 0,
  662. "reference_err": 0,
  663. "prefix": 0,
  664. "index": 9,
  665. "online": 0,
  666. "restart": 1,
  667. "comm_lost": 0,
  668. "remote_forced": 0,
  669. "local_forced": 0,
  670. "over_range": 0
  671. }
  672. ],
  673. "group": 30,
  674. "variation": 1,
  675. "qualifier": 0,
  676. "prefix_code": 0,
  677. "range_code": 0,
  678. "start": 1,
  679. "stop": 9,
  680. "count": 9
  681. },
  682. {
  683. "items": [
  684. {
  685. "state": 0,
  686. "reserved1": 0,
  687. "prefix": 0,
  688. "index": 0,
  689. "online": 0,
  690. "restart": 1,
  691. "comm_lost": 0,
  692. "remote_forced": 0,
  693. "local_forced": 0,
  694. "reserved0": 0
  695. },
  696. {
  697. "state": 0,
  698. "reserved1": 0,
  699. "prefix": 0,
  700. "index": 1,
  701. "online": 0,
  702. "restart": 1,
  703. "comm_lost": 0,
  704. "remote_forced": 0,
  705. "local_forced": 0,
  706. "reserved0": 0
  707. },
  708. {
  709. "state": 0,
  710. "reserved1": 0,
  711. "prefix": 0,
  712. "index": 2,
  713. "online": 0,
  714. "restart": 1,
  715. "comm_lost": 0,
  716. "remote_forced": 0,
  717. "local_forced": 0,
  718. "reserved0": 0
  719. },
  720. {
  721. "state": 0,
  722. "reserved1": 0,
  723. "prefix": 0,
  724. "index": 3,
  725. "online": 0,
  726. "restart": 1,
  727. "comm_lost": 0,
  728. "remote_forced": 0,
  729. "local_forced": 0,
  730. "reserved0": 0
  731. },
  732. {
  733. "state": 0,
  734. "reserved1": 0,
  735. "prefix": 0,
  736. "index": 4,
  737. "online": 0,
  738. "restart": 1,
  739. "comm_lost": 0,
  740. "remote_forced": 0,
  741. "local_forced": 0,
  742. "reserved0": 0
  743. },
  744. {
  745. "state": 0,
  746. "reserved1": 0,
  747. "prefix": 0,
  748. "index": 5,
  749. "online": 0,
  750. "restart": 1,
  751. "comm_lost": 0,
  752. "remote_forced": 0,
  753. "local_forced": 0,
  754. "reserved0": 0
  755. },
  756. {
  757. "state": 0,
  758. "reserved1": 0,
  759. "prefix": 0,
  760. "index": 6,
  761. "online": 0,
  762. "restart": 1,
  763. "comm_lost": 0,
  764. "remote_forced": 0,
  765. "local_forced": 0,
  766. "reserved0": 0
  767. },
  768. {
  769. "state": 0,
  770. "reserved1": 0,
  771. "prefix": 0,
  772. "index": 7,
  773. "online": 0,
  774. "restart": 1,
  775. "comm_lost": 0,
  776. "remote_forced": 0,
  777. "local_forced": 0,
  778. "reserved0": 0
  779. },
  780. {
  781. "state": 0,
  782. "reserved1": 0,
  783. "prefix": 0,
  784. "index": 8,
  785. "online": 0,
  786. "restart": 1,
  787. "comm_lost": 0,
  788. "remote_forced": 0,
  789. "local_forced": 0,
  790. "reserved0": 0
  791. },
  792. {
  793. "state": 0,
  794. "reserved1": 0,
  795. "prefix": 0,
  796. "index": 9,
  797. "online": 0,
  798. "restart": 1,
  799. "comm_lost": 0,
  800. "remote_forced": 0,
  801. "local_forced": 0,
  802. "reserved0": 0
  803. }
  804. ],
  805. "group": 10,
  806. "variation": 2,
  807. "qualifier": 0,
  808. "prefix_code": 0,
  809. "range_code": 0,
  810. "start": 0,
  811. "stop": 9,
  812. "count": 10
  813. },
  814. {
  815. "count": 10,
  816. "stop": 9,
  817. "start": 0,
  818. "range_code": 0,
  819. "prefix_code": 0,
  820. "qualifier": 0,
  821. "variation": 1,
  822. "group": 40
  823. }
  824. ],
  825. "function_code": 129,
  826. "control": {
  827. "sequence": 2,
  828. "uns": false,
  829. "con": false,
  830. "fin": true,
  831. "fir": true
  832. }
  833. },
  834. "dst": 1,
  835. "src": 10,
  836. "control": {
  837. "function_code": 4,
  838. "fcv": false,
  839. "fcb": false,
  840. "pri": true,
  841. "dir": false
  842. },
  843. "type": "response"
  844. },
  845. "request": {
  846. "application": {
  847. "complete": true,
  848. "objects": [
  849. {
  850. "count": 0,
  851. "stop": 0,
  852. "start": 0,
  853. "range_code": 6,
  854. "prefix_code": 0,
  855. "qualifier": 6,
  856. "variation": 2,
  857. "group": 60
  858. },
  859. {
  860. "count": 0,
  861. "stop": 0,
  862. "start": 0,
  863. "range_code": 6,
  864. "prefix_code": 0,
  865. "qualifier": 6,
  866. "variation": 3,
  867. "group": 60
  868. },
  869. {
  870. "count": 0,
  871. "stop": 0,
  872. "start": 0,
  873. "range_code": 6,
  874. "prefix_code": 0,
  875. "qualifier": 6,
  876. "variation": 4,
  877. "group": 60
  878. },
  879. {
  880. "count": 0,
  881. "stop": 0,
  882. "start": 0,
  883. "range_code": 6,
  884. "prefix_code": 0,
  885. "qualifier": 6,
  886. "variation": 1,
  887. "group": 60
  888. }
  889. ],
  890. "function_code": 1,
  891. "control": {
  892. "sequence": 2,
  893. "uns": false,
  894. "con": false,
  895. "fin": true,
  896. "fir": true
  897. }
  898. },
  899. "dst": 10,
  900. "src": 1,
  901. "control": {
  902. "function_code": 4,
  903. "fcv": false,
  904. "fcb": false,
  905. "pri": true,
  906. "dir": true
  907. },
  908. "type": "request"
  909. }
  910. },
  911. "alert": {
  912. "severity": 3,
  913. "category": "",
  914. "signature": "SURICATA DNP3 Unknown object",
  915. "rev": 1,
  916. "signature_id": 2270004,
  917. "gid": 1,
  918. "action": "allowed"
  919. },
  920. "tx_id": 3,
  921. "proto": "TCP",
  922. "timestamp": "2015-07-14T11:45:56.361312-0600",
  923. "flow_id": 106790066891968,
  924. "pcap_cnt": 21,
  925. "event_type": "alert",
  926. "src_ip": "127.0.0.1",
  927. "src_port": 20000,
  928. "dest_ip": "127.0.0.1",
  929. "dest_port": 59602
  930. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement