Project

General

Profile

Actions

Feature #2280

closed
VJ PA

Feature #5665: rules: bidirectional transaction matching

http: rules that match both request and response

Feature #2280: http: rules that match both request and response

Added by Victor Julien over 8 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Introduce support for matching on fields from both request and response side in a single rule in http.

This will have some limitations around body matching.


Related issues 2 (2 open0 closed)

Related to Suricata - Task #2309: SuriCon 2017 brainstormAssignedVictor JulienActions
Related to Suricata - Task #3288: Suricon 2019 brainstormAssignedVictor JulienActions

AH Updated by Andreas Herz over 8 years ago Actions #1

  • Assignee set to OISF Dev
  • Target version set to TBD

VJ Updated by Victor Julien over 8 years ago Actions #2

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Victor Julien

VJ Updated by Victor Julien over 8 years ago Actions #3

  • Related to Task #2309: SuriCon 2017 brainstorm added

VJ Updated by Victor Julien over 6 years ago Actions #4

  • Related to Task #3288: Suricon 2019 brainstorm added

PA Updated by Philippe Antoine over 4 years ago Actions #5

I do not understand what is expected here...

XL Updated by xiaolong li over 4 years ago Actions #6

Philippe Antoine wrote in #note-5:

I do not understand what is expected here...

How to match http GET request with 404 NOT FOUND response?

VJ Updated by Victor Julien over 3 years ago Actions #7

  • Related to Feature #5665: rules: bidirectional transaction matching added

VJ Updated by Victor Julien almost 2 years ago Actions #8

  • Parent task set to #5665

PA Updated by Philippe Antoine almost 2 years ago Actions #9

#5665 should cover this completely and more (not only http)

PA Updated by Philippe Antoine about 1 year ago Actions #10

  • Status changed from Assigned to Closed
  • Assignee changed from Victor Julien to Philippe Antoine
  • Target version changed from TBD to 8.0.0-beta1
Actions

Also available in: PDF Atom