Project

General

Profile

Actions

Feature #1979

open

TCP/IP packets normalization/scrubbing

Added by op suri about 6 years ago. Updated almost 4 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
high
Difficulty:
medium
Label:

Description

Snort is capable of normalizing network traffic see : https://snort.org/faq/readme-normalize

For example if one wants clear the reserved bits in the TCP header, in Snort this would be possible using the following: preprocessor normalize_tcp: [rsv]

I am convinced that TCP/IP packets normalization is possible in Suricata, but I don't know where to configure it.

Can you please help me?

Thank you.

Actions

Also available in: Atom PDF