Project

General

Profile

Actions

Feature #2312

closed
VJ PA

http: parsing for async streams

Feature #2312: http: parsing for async streams

Added by Victor Julien over 8 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Currently the parser requires traffic from both sides to be useful/effective.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #2309: SuriCon 2017 brainstormAssignedVictor JulienActions

VJ Updated by Victor Julien over 8 years ago Actions #1

  • Related to Task #2309: SuriCon 2017 brainstorm added

RH Updated by Raymond Hansen over 7 years ago Actions #2

Jeffrey has created an http parser that we should evaluate for use. Should include http2?

PC Updated by Pierre Chifflier over 7 years ago Actions #3

  • Geoffroy :)

PA Updated by Philippe Antoine almost 7 years ago Actions #4

Currently the parser requires traffic from both sides to be useful/effective.

How so ?
From my experience of the code, it is "effective" as it should match signature with http keywords
I did not test it yet but I would like what is expected first.

VJ Updated by Victor Julien almost 7 years ago Actions #5

Not sure if this is still true. Some updates were made to libhtp and suricata to allow for this. I think it's a good idea to create some test cases (suricata-verify) for both all request and all response traffic. I'm especially curious how multi-tx sessions work.

VJ Updated by Victor Julien over 6 years ago Actions #6

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Philippe Antoine

Philippe, can you make some SV tests for this? TS only, TC only. Checking logging, file extraction, signature matching?

VJ Updated by Victor Julien about 6 years ago Actions #7

  • Target version changed from TBD to 6.0.0beta1

PA Updated by Philippe Antoine about 6 years ago Actions #8

  • Status changed from Assigned to In Review

PA Updated by Philippe Antoine about 6 years ago Actions #9

  • Status changed from In Review to Closed
Actions

Also available in: PDF Atom