Project

General

Profile

Actions

Optimization #1873

closed

Classtypes missing on decoder-events,files, and stream-events

Added by Jack Mott over 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Hi,

These rules do not have an associated classtype with them. Could you take a look and determine if that would be a relevant addition?

Best,

Jack

Actions #1

Updated by Andreas Herz about 6 years ago

  • Tracker changed from Bug to Optimization
  • Assignee set to OISF Dev
  • Target version set to TBD

stream-events has classtype, do you have anything special in mind?

Actions #2

Updated by Andreas Herz over 5 years ago

We have some shipped rules with classtypes and some without:

(classtype:protocol-command-decode)
  • app-layer-events.rules
  • http-events.rules
  • smtp-events.rules
  • stream-events.rules
  • tls-events.rules
(no classtype)
  • decoder-events.rules
  • dnp3-events.rules
  • dns-events.rules
  • files.rules
  • modbus-events.rules

Something we just forgot or is that for a specific reason?

Actions #3

Updated by Victor Julien over 5 years ago

Seems it was forgotten. Btw the files.rules file is really only meant to be an example.

Actions #4

Updated by Andreas Herz over 5 years ago

Yep that's also why the rules in there are commented, so would it be ok to add the classtype:protocol-command-decode to the 4 rule files left?

Actions #5

Updated by Andreas Herz over 5 years ago

  • Assignee changed from OISF Dev to Andreas Herz
Actions #6

Updated by Victor Julien over 5 years ago

  • Status changed from New to Closed
  • Target version changed from TBD to 4.0beta1
Actions

Also available in: Atom PDF