Cisco Cisco Firepower Management Center 2000 Guia Do Programador

Página de 536
 
4-77
FireSIGHT eStreamer Integration Guide
 
Chapter 4      Understanding Discovery & Connection Data Structures
  Host Discovery and Connection Data Blocks
Full Sub-Server Data Block
The Full Sub-Server data block conveys information about a sub-server associated with a server detected 
on a host, and includes information about the sub-server such as its vendor and version and any related 
VDB and third-party vulnerabilities for the sub-server on the host. A sub-server is a loadable module of 
a server that has its own associated vulnerabilities. A Full Host Server data block includes a Full 
Sub-Server data block for each sub-server detected on the host. The Full Sub-Server data block has a 
block type of 51 in the series 1 group of blocks.
Note
An asterisk (*) next to a series 1 data block name in the following diagram indicates that multiple 
instances of the data block may occur.
The following diagram shows the format of the Full Sub-Server data block:
String Block 
Type
uint32
Initiates a String data block containing the attribute name. This value 
is always 
0
.
String Block 
Length
uint32
Number of bytes in the String data block, including the string block 
type and length fields, plus the number of bytes in the attribute name.
Attribute Value
string
Value of the attribute.
Table 4-41
Attribute Value Data Block Fields (continued)
Field
Data Type
Description
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
Full Sub-Server Block Type (51)
Full Sub-Server Block Length
String Block Type (0)
String Block Length
Sub-Server Name String...
String Block Type (0)
String Block Length
Sub-Server Vendor Name String...
String Block Type (0)
String Block Length
Sub-Server Version String...
Generic List Block Type (31)