Project

General

Custom queries

Profile

Actions

Feature #1373

closed

Allow different reassembly depth for filestore rules

Added by Duane Howard over 10 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

In order to capture full files, stream reassembly depth needs to be > file length, in many cases this would mean expanding stream reassembly to several MB. However for non-filestore rules most badness and detection can happen in the first few KB, so reassembling seems wasteful. It could be interesting to have a distinct option to reassemble streams that match of filestore rules to a different depth than those that are not filestore rules.

#5

Updated by Victor Julien over 9 years ago

  • Target version set to 70
#6

Updated by Andreas Herz over 9 years ago

  • Assignee set to OISF Dev
#8

Updated by Victor Julien about 9 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Giuseppe Longo
#10

Updated by Victor Julien over 8 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 70 to 3.2beta1
Actions

Also available in: Atom PDF