Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.Sign up
can't reassemble entire packet when get [tcp acked unseen segment] #335
When analyse traffic mirror, I always get the content_gap event and zeek will not reassemble the entire package.
I provide my pcap and bro script, run
There's two bits of info that are relevant here:
Point (1) is more relevant than (2) here because this particular pcap doesn't have further content, but I mention it just in case you do run into it. I think both issues are non-trivial to address anytime soon:
To better deal with (1) we'd likely need more buffering mechanisms in the TCP reassembly process to understand the past reassembly history/state and delay reporting gaps -- maybe not a great thing to add to a system aimed more at real-time analysis. Ideally, the capture setup would would show us the data before the associated ACKs of that data.
Improvements to (2) likely won't happen until HTTP/MIME analyzers get re-written. You may be able to find some use in detecting this type of problem via the