Project

General

Profile

Actions

Feature #2269

open

TLS: tls.version: allow negation or comparison

Added by B F almost 4 years ago. Updated 3 months ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
low
Difficulty:
low
Label:

Description

According to the documentation it is possible to match on “1.0”, “1.1”, “1.2” with tls.version (http://suricata.readthedocs.io/en/latest/rules/tls-keywords.html).

I propose to
a) allow negation for this keyword, i.e. alert on all version that are NOT 1.2 for example
or
b) allow some kind of comparison with >, <, <=, >= (with would probably need some ordered table with the versions, as the version can also be SSL.

Also (at least in the case of b)) there should be a solution to cover tls.version "UNDETERMINED"

Actions #1

Updated by Andreas Herz almost 4 years ago

  • Assignee set to Anonymous
  • Target version set to TBD
Actions #2

Updated by Victor Julien about 3 years ago

  • Effort set to low
  • Difficulty set to low
Actions #3

Updated by Andreas Herz over 2 years ago

  • Assignee set to Community Ticket
Actions #4

Updated by Philippe Antoine 7 months ago

  • Status changed from New to In Review
Actions #5

Updated by Philippe Antoine 3 months ago

  • Target version changed from TBD to 7.0rc1
Actions

Also available in: Atom PDF