Project

General

Profile

Actions

Feature #1979

open

TCP/IP packets normalization/scrubbing

Added by op suri almost 5 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
high
Difficulty:
medium
Label:

Description

Snort is capable of normalizing network traffic see : https://snort.org/faq/readme-normalize

For example if one wants clear the reserved bits in the TCP header, in Snort this would be possible using the following: preprocessor normalize_tcp: [rsv]

I am convinced that TCP/IP packets normalization is possible in Suricata, but I don't know where to configure it.

Can you please help me?

Thank you.

Actions #1

Updated by Victor Julien almost 5 years ago

  • Priority changed from High to Normal
  • Target version deleted (3.2.1)
Actions #2

Updated by Victor Julien almost 5 years ago

  • Subject changed from TCP/IP packets normalization to TCP/IP packets normalization/scrubbing
  • Target version set to TBD

Suricata does not (yet) have a packet normalization/scrubbing feature.

Actions #3

Updated by op suri almost 5 years ago

Thank you for your reply.

Since you mentioned that suricata does not (yet) have a packet scrubbing feature, is there any short term plan to implement it?

Actions #4

Updated by Victor Julien almost 5 years ago

There are no plans for it at this time. Perhaps you or someone else in the community can take on the effort.

Actions #5

Updated by op suri almost 5 years ago

I understand that suricata does not have the normalization feature.

Your advice is appreciated to the following problem

1) I have a suricata up and running with rules generating alerts.

2) "abnormal" TCP/IP traffic/packets was identified based on rules.

3) From what I do see as features on suricata is: drop (reject), pass, alert

4) GOAL: is to clear some fields on packets instead of dropping the whole packets/traffic

Question: 
Is Suricata capable of 4)? if not what is your recommendation to reach this goal?

Thank you in advance

Actions #6

Updated by Victor Julien almost 5 years ago

No, not at this time.

Actions #7

Updated by Victor Julien about 3 years ago

  • Effort set to high
  • Difficulty set to medium
Actions #8

Updated by Victor Julien over 2 years ago

  • Assignee set to Community Ticket
Actions

Also available in: Atom PDF