Actions
Feature #2283
closedturn content modifiers into 'sticky buffers'
Description
Turn all content modifiers into sticky buffers with a '<proto>.<buffer>[.<modifier>]' notation.
Support this dot-notation for all existing sticky buffers.
In both cases the existing rule keywords need to keep working for backwards compatibility. New keywords only need to support the new notation.
Some examples:
content:"abc"; http_uri; -> http.uri; content:"abc"; content:"abc"; http_raw_uri; -> http.uri.raw; content:"abc"; content:"abc"; http_client_body; -> http.request_body; content:"abc"; dns_query; content:"abc"; -> dns.query; content:"abc";
Internally, these keywords need to be registered through the 'v2 API', so that they support transforms.
Examples can be found in https://github.com/OISF/suricata/pull/3632
Updated by Victor Julien over 7 years ago
- Assignee set to Jason Williams
- Target version set to 70
Updated by Victor Julien over 6 years ago
- Description updated (diff)
- Assignee changed from Jason Williams to OISF Dev
- Target version changed from 70 to 5.0beta1
Updated by Victor Julien about 6 years ago
- Related to Feature #2952: modernize http_header_names added
Actions