- Assignee set to OISF Dev
- Target version set to TBD
- Related to Task #2309: SuriCon 2017 brainstorm added
- Related to Feature #2485: http: log byte range with file extraction added
First step would be to document the chunks of file(s) as identified per sensor, if multiple sensors are in use.
- Has duplicate Bug #2326: File extraction not properly handling http range requests added
- Assignee changed from OISF Dev to Philippe Antoine
My understanding is the following :
We now log the byte-range but we would like suricata to handle the complete file reassembly (in case there is any).
Is that correct ?
Is there already an example of suricata of reassembly over TCP ? And in this case over different flows ?
- Status changed from New to Assigned
We will split those in multiple smaller tasks.
First is rebuilding the file if multiple requests/responses are in the same flow
Does anyone remember WHAT smaller tasks we wanted to create :)?
First is rebuilding file if multiple transactions are in the same flow (maybe first subclass, if they are in the right order)
Then next task would be to see what to do if the transactions are across many flows
- Target version changed from TBD to 6.0.0rc1
- Status changed from Assigned to In Review
Also available in: Atom