Cisco Cisco Firepower Management Center 4000 Guia Do Programador

Página de 536
 
4-120
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures 
  Host Discovery and Connection Data Blocks
The following table describes the fields of the Scan Result data block.
List Block Type (11)
Generic Scan 
Results List
List Block Length
Scan Results
List
Generic Scan Results Block Type (108)
Generic Scan Results Block Length
Generic Scan Results...
User 
Product List
Generic List Block Type (31)
Generic List Block Length
User Product Data Blocks*
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Table 4-69
Scan Result Data Block Fields 
Field
Data Type
Description
Scan Result 
Block Type
uint32
Initiates a Scan Result data block. This value is always 
142
.
Scan Result 
Block Length
uint32
Number of bytes in the Scan Vulnerability data block, including eight 
bytes for the scan vulnerability block type and length fields, plus the 
number of bytes of scan vulnerability data that follows.
User ID
uint32
Contains the user identification number for the user who imported the 
scan result or ran the scan that produced the scan result.
Scan Type
uint32
Indicates how the results were added to the system.
IP Address
uint8[16]
IP address of the host affected by the vulnerabilities in the result, in IP 
address octets.
Port
uint16
Port used by the sub-server affected by the vulnerabilities in the 
results. 
Protocol
uint16
IANA protocol number or Ethertype. This is handled differently for 
Transport and Network layer protocols.
Transport layer protocols are identified by the IANA protocol number. 
For example: 
  •
6
 - TCP
  •
17
 - UDP
Network layer protocols are identified by the decimal form of the IEEE 
Registration Authority Ethertype. For example:
  •
2048
 - IP
Flag
uint16
Reserved