Project

General

Profile

Actions

Support #2508

closed

Suricata cannot decode 6LoWPAN captures

Added by Cem YEŞİLTEPE almost 6 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

Hello,

I am currently working on about intrusion detection of internet of things routing attacks for my master thesis. I have been trying to use suricata for that but as far as I see, suricata cannot decode 6LoWPAN and IEEE 802.15.4 protocols although I have related decoder files. Do you have any sugguestions about this issue? How can I use suricata to work with 6LoWPAN and IEEE 802.15.4 protocols? Decoder files that I already have are listed below:

decode-6lowpan.c
decode-6lowpan.h
decode-6lowpan.o
decode.c
decode-erspan.c
decode-erspan.h
decode-erspan.o
decode-ethernet.c
decode-ethernet.h
decode-ethernet.o
decode-events.c
decode-events.h
decode-events.o
decode-gre.c
decode-gre.h
decode-gre.o
decode.h
decode-icmpv4.c
decode-icmpv4.h
decode-icmpv4.o
decode-icmpv6.c
decode-icmpv6.h
decode-icmpv6.o
decode-ieee-802154.c
decode-ieee-802154.h
decode-ieee-802154.o
decode-ipv4.c
decode-ipv4.h
decode-ipv4.o
decode-ipv6.c
decode-ipv6.h
decode-ipv6.o
decode-mpls.c
decode-mpls.h
decode-mpls.o
decode-null.c
decode-null.h
decode-null.o
decode.o
decode-ppp.c
decode-ppp.h
decode-ppp.o
decode-pppoe.c
decode-pppoe.h
decode-pppoe.o
decode-raw.c
decode-raw.h
decode-raw.o
decode-sctp.c
decode-sctp.h
decode-sctp.o
decode-sll.c
decode-sll.h
decode-sll.o
decode-tcp.c
decode-tcp.h
decode-tcp.o
decode-template.c
decode-template.h
decode-template.o
decode-teredo.c
decode-teredo.h
decode-teredo.o
decode-udp.c
decode-udp.h
decode-udp.o
decode-vlan.c
decode-vlan.h
decode-vlan.o
decode-zigbee.c
decode-zigbee.h
decode-zigbee.o

Actions #1

Updated by Andreas Herz almost 6 years ago

  • Assignee set to Cem YEŞİLTEPE
  • Target version set to Support

Did you write those decoder? They are not included in suricata out of the box. Without more detail it's hard rather difficult to help

Actions #2

Updated by Victor Julien almost 6 years ago

  • Priority changed from High to Normal
  • Difficulty deleted (high)
Actions #3

Updated by Victor Julien about 5 years ago

  • Status changed from New to Closed
  • Assignee deleted (Cem YEŞİLTEPE)
  • Target version deleted (Support)
Actions

Also available in: Atom PDF