Project

General

Profile

Actions

Feature #2319

open

Expose flow lifetime to the rulelanguage

Added by Stian Bergseth almost 4 years ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:
Beginner, C, Outreachy

Description

During the roadmap discussion in Prague someone asked for the possiblity to detect long lived sessions.
VictorJ said that this data was already stored somewhere.

I guess a sanity check of config for timeouts vs length of duration looked for in the signature would be a good idea


Related issues

Related to Task #2309: SuriCon 2017 brainstormNewVictor JulienActions
Related to Feature #3271: Add keyword to determine flow based speed/bwNewOISF DevActions
Actions #1

Updated by Victor Julien almost 4 years ago

  • Related to Task #2309: SuriCon 2017 brainstorm added
Actions #2

Updated by Victor Julien almost 4 years ago

  • Target version set to TBD
Actions #3

Updated by Victor Julien over 3 years ago

Stian are you planning to submit an implementation for this?

Actions #4

Updated by Victor Julien about 3 years ago

  • Assignee changed from Stian Bergseth to Anonymous
  • Effort set to low
  • Difficulty set to low
Actions #5

Updated by Andreas Herz over 2 years ago

  • Assignee set to Community Ticket
Actions #6

Updated by Victor Julien over 2 years ago

  • Label Beginner, Outreachy added
Actions #7

Updated by Andreas Herz almost 2 years ago

  • Related to Feature #3271: Add keyword to determine flow based speed/bw added
Actions #8

Updated by Andreas Herz almost 2 years ago

  • Assignee changed from Community Ticket to Stian Bergseth

Additional ideas we will split into dedicated issues:
Dump the flow table over unix socket.
Explore also loading the flow table into suricata as part of a state keeping.

Actions #9

Updated by Victor Julien about 1 year ago

  • Assignee changed from Stian Bergseth to Community Ticket
Actions #10

Updated by Shivani Bhardwaj about 1 year ago

  • Effort deleted (low)
  • Difficulty deleted (low)
  • Label C added
Actions

Also available in: Atom PDF