Project

General

Profile

Actions

Bug #1136

closed

negated app-layer-protocol FP on multi-TX flows

Added by Victor Julien over 8 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

When a negated app-layer-protocol is inspected against a multi tx protocol, it FP's on new TX's.

A rule like:

alert udp .... (app-layer-protocol:!dns; ...)

will alert on DNS traffic, even though we properly detected the protocol.

Actions #1

Updated by Victor Julien over 8 years ago

  • Status changed from Assigned to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF