Project

General

Profile

Actions

Task #2309

open
VJ VJ

Task #4763: tracking: Suricon brainstorms

SuriCon 2017 brainstorm

Task #2309: SuriCon 2017 brainstorm

Added by Victor Julien over 8 years ago. Updated 5 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Meta ticket. Add relations to this ticket for the tickets discussed at SuriCon or created after SuriCon brainstorm.


Related issues 46 (8 open38 closed)

Related to Suricata - Feature #2308: threshold/suppress by http_hostAssignedTodd MortimerActions
Related to Suricata - Feature #2310: lua: expose xbitsNewCommunity TicketActions
Related to Suricata - Feature #2311: math on extracted valuesClosedJeff LucovskyActions
Related to Suricata - Feature #2312: http: parsing for async streamsClosedPhilippe AntoineActions
Related to Suricata - Task #2313: tracking: save & restore state when suricata restartsNewOISF DevActions
Related to Suricata - Feature #2314: protocol parser: rdpClosedZach KellyActions
Related to Suricata - Feature #646: smb log feature to be introducedClosedVictor JulienActions
Related to Suricata - Feature #2315: eve: ftp loggingClosedJeff LucovskyActions
Related to Suricata - Feature #2316: global memcapAssignedGiuseppe LongoActions
Related to Suricata - Optimization #2317: rcuNewOISF DevActions
Related to Suricata - Feature #2303: file-store enhancements (aka file-store v2): deduplication; hash-based naming; json metadata and cleanup toolingClosedJason IshActions
Related to Suricata - Task #2278: tracking: failing betterAssignedVictor JulienActions
Related to Suricata - Feature #550: Extract file attachments from FTPClosedEric LeblondActions
Related to Suricata - Feature #2192: JA3 TLS client fingerprintingClosedMats KlepslandActions
Related to Suricata - Feature #2279: TLS 1.3 decoding, SNI extraction and loggingClosedMats KlepslandActions
Related to Suricata - Feature #2280: http: rules that match both request and responseClosedPhilippe AntoineActions
Related to Suricata - Feature #1576: http: byte-range supportClosedPhilippe AntoineActions
Related to Suricata - Feature #2281: tcp stream: simpler IDS handling of overlap evasionsAssignedVictor JulienActions
Related to Suricata - Feature #120: Capture full session on alertClosedScott JordanActions
Related to Suricata - Feature #385: Configuration option to log all known (pcap) data for a stream when an alert firesClosedCommunity TicketActions
Related to Suricata - Task #2219: Save pcap only if alertRejectedActions
Related to Suricata - Feature #2290: lua: use script as transformClosedJeff LucovskyActions
Related to Suricata - Feature #2284: detect partial file transfersClosedActions
Related to Suricata - Feature #1705: hyperscan pcre integrationClosedActions
Related to Suricata - Feature #1006: transformation apiClosedVictor JulienActions
Related to Suricata - Feature #2291: traffic-id: ruleset for traffic classification and bypassClosedJason IshActions
Related to Suricata - Feature #2285: modify memcaps over unix socketClosedGiuseppe LongoActions
Related to Suricata - Feature #2283: turn content modifiers into 'sticky buffers'ClosedOISF DevActions
Related to Suricata - Feature #1948: allow filestore name configuration optionsClosedJason IshActions
Related to Suricata - Documentation #2286: doc: document best practices around handling file extractionClosedJason IshActions
Related to Suricata - Feature #2282: event log aka weird.logClosedJeff LucovskyActions
Related to Suricata - Optimization #2272: Analyze DNS response if query is not presentRejectedJason IshActions
Related to Suricata - Feature #741: Introduce endswith keywordClosedVictor JulienActions
Related to Suricata - Feature #742: startswith keywordClosedVictor JulienActions
Related to Suricata - Feature #735: Introduce content_len keywordClosedVictor JulienActions
Related to Suricata - Feature #2299: pcap: read directory with pcaps from the commandlineClosedDanny BrowningActions
Related to Suricata - Feature #2298: pcap: store pcaps in compressed formClosedActions
Related to Suricata - Feature #1828: YARA supportRejectedActions
Related to Suricata - Feature #1949: only write unique filesClosedJason IshActions
Related to Suricata - Feature #962: Can I log the mac address of the source?ClosedSascha SteinbissActions
Related to Suricata - Feature #2318: matching on large amounts of data with dynamic updatesClosedVictor JulienActions
Related to Suricata - Feature #2319: Expose flow lifetime to the rulelanguageRejectedActions
Related to Suricata - Feature #2320: configure host os policy over unix socketRejectedActions
Related to Suricata - Optimization #2321: yaml: clean up usage of listsNewOISF DevActions
Related to Suricata - Support #2322: create place for easy sharing of test casesClosedCommunity TicketActions
Related to Suricata - Feature #660: Update host policy from unix socketRejectedActions

VJ Updated by Victor Julien over 8 years ago Actions #1

  • Related to Feature #2308: threshold/suppress by http_host added

VJ Updated by Victor Julien over 8 years ago Actions #2

VJ Updated by Victor Julien over 8 years ago Actions #3

VJ Updated by Victor Julien over 8 years ago Actions #4

  • Related to Feature #2312: http: parsing for async streams added

VJ Updated by Victor Julien over 8 years ago Actions #5

  • Related to Task #2313: tracking: save & restore state when suricata restarts added

VJ Updated by Victor Julien over 8 years ago Actions #6

VJ Updated by Victor Julien over 8 years ago Actions #7

  • Related to Feature #646: smb log feature to be introduced added

VJ Updated by Victor Julien over 8 years ago Actions #8

VJ Updated by Victor Julien over 8 years ago Actions #9

VJ Updated by Victor Julien over 8 years ago Actions #10

VJ Updated by Victor Julien over 8 years ago Actions #11

  • Related to Feature #2303: file-store enhancements (aka file-store v2): deduplication; hash-based naming; json metadata and cleanup tooling added

VJ Updated by Victor Julien over 8 years ago Actions #12

  • Related to Task #2278: tracking: failing better added

VJ Updated by Victor Julien over 8 years ago Actions #13

  • Related to Feature #550: Extract file attachments from FTP added

VJ Updated by Victor Julien over 8 years ago Actions #14

VJ Updated by Victor Julien over 8 years ago Actions #15

  • Related to Feature #2279: TLS 1.3 decoding, SNI extraction and logging added

VJ Updated by Victor Julien over 8 years ago Actions #16

  • Related to Feature #2280: http: rules that match both request and response added

VJ Updated by Victor Julien over 8 years ago Actions #17

VJ Updated by Victor Julien over 8 years ago Actions #18

  • Related to Feature #2281: tcp stream: simpler IDS handling of overlap evasions added

VJ Updated by Victor Julien over 8 years ago Actions #19

  • Related to Feature #120: Capture full session on alert added

VJ Updated by Victor Julien over 8 years ago Actions #20

  • Related to Feature #385: Configuration option to log all known (pcap) data for a stream when an alert fires added

VJ Updated by Victor Julien over 8 years ago Actions #21

  • Related to Task #2219: Save pcap only if alert added

VJ Updated by Victor Julien over 8 years ago Actions #22

VJ Updated by Victor Julien over 8 years ago Actions #23

VJ Updated by Victor Julien over 8 years ago Actions #24

VJ Updated by Victor Julien over 8 years ago Actions #25

VJ Updated by Victor Julien over 8 years ago Actions #26

  • Related to Feature #2291: traffic-id: ruleset for traffic classification and bypass added

VJ Updated by Victor Julien over 8 years ago Actions #27

  • Related to Feature #2285: modify memcaps over unix socket added

VJ Updated by Victor Julien over 8 years ago Actions #28

  • Related to Feature #2283: turn content modifiers into 'sticky buffers' added

VJ Updated by Victor Julien over 8 years ago Actions #29

  • Related to Feature #1948: allow filestore name configuration options added

VJ Updated by Victor Julien over 8 years ago Actions #30

  • Related to Documentation #2286: doc: document best practices around handling file extraction added

VJ Updated by Victor Julien over 8 years ago Actions #31

VJ Updated by Victor Julien over 8 years ago Actions #32

VJ Updated by Victor Julien over 8 years ago Actions #33

VJ Updated by Victor Julien over 8 years ago Actions #34

VJ Updated by Victor Julien over 8 years ago Actions #35

  • Related to Feature #735: Introduce content_len keyword added

VJ Updated by Victor Julien over 8 years ago Actions #36

  • Related to Feature #2299: pcap: read directory with pcaps from the commandline added

VJ Updated by Victor Julien over 8 years ago Actions #37

  • Related to Feature #2298: pcap: store pcaps in compressed form added

VJ Updated by Victor Julien over 8 years ago Actions #38

VJ Updated by Victor Julien over 8 years ago Actions #39

VJ Updated by Victor Julien over 8 years ago Actions #40

  • Related to Feature #962: Can I log the mac address of the source? added

VJ Updated by Victor Julien over 8 years ago Actions #41

  • Related to Feature #2318: matching on large amounts of data with dynamic updates added

VJ Updated by Victor Julien over 8 years ago Actions #42

  • Related to Feature #2319: Expose flow lifetime to the rulelanguage added

VJ Updated by Victor Julien over 8 years ago Actions #43

  • Related to Feature #2320: configure host os policy over unix socket added

VJ Updated by Victor Julien over 8 years ago Actions #44

VJ Updated by Victor Julien over 8 years ago Actions #45

  • Related to Support #2322: create place for easy sharing of test cases added

VJ Updated by Victor Julien almost 8 years ago Actions #46

  • Related to Feature #660: Update host policy from unix socket added

VJ Updated by Victor Julien almost 6 years ago Actions #47

  • Tracker changed from Support to Task
  • Target version set to Support

VJ Updated by Victor Julien over 4 years ago Actions #48

  • Parent task set to #4763

VJ Updated by Victor Julien almost 4 years ago Actions #49

  • Status changed from New to Assigned

JI Updated by Jason Ish 5 months ago Actions #50

  • Target version changed from Support to TBD
Actions

Also available in: PDF Atom