Project

General

Profile

Actions

Feature #2198

closed

Extend the DNS parser to accept dns_response keyword in signatures

Feature #2198: Extend the DNS parser to accept dns_response keyword in signatures

Added by Anonymous almost 9 years ago. Updated about 1 year ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

For A and AAAA records it would be interesting to match on the IP received from the DNS resolver.
In particular this could be useful to check for potentially sink-holed domains.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #2448: dns: additional buffers for DNS ResponsesNewJason IshActions
Is duplicate of Suricata - Feature #7012: rules: add dns.response sticky bufferClosedNathan ScrivensActions

AH Updated by Andreas Herz almost 9 years ago Actions #1

  • Tracker changed from Bug to Feature
  • Target version changed from 70 to TBD

Since you assigned yourself, do you want to submit that?

Updated by Anonymous almost 9 years ago Actions #2

Andreas Herz wrote:

Since you assigned yourself, do you want to submit that?

Yes, it is in the pipeline.
Do you want me to focus on a Rust implentation?

AH Updated by Andreas Herz almost 9 years ago Actions #3

Depends on what you prefer, IMHO it would be nice to have it in Rust.

JI Updated by Jason Ish over 8 years ago Actions #4

  • Related to Feature #2448: dns: additional buffers for DNS Responses added

AH Updated by Andreas Herz about 7 years ago Actions #5

  • Assignee changed from Anonymous to Stian Bergseth

VJ Updated by Victor Julien over 6 years ago Actions #6

  • Assignee changed from Stian Bergseth to Community Ticket

VJ Updated by Victor Julien about 1 year ago Actions #7

  • Status changed from New to Rejected
  • Assignee deleted (Community Ticket)
  • Target version deleted (TBD)

Done in #7012

VJ Updated by Victor Julien about 1 year ago Actions #8

  • Is duplicate of Feature #7012: rules: add dns.response sticky buffer added
Actions

Also available in: PDF Atom