Project

General

Profile

Actions

Feature #2713

open

protocol detection w/o protocol parsing

Added by Victor Julien over 4 years ago. Updated over 3 years ago.

Status:
Feedback
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

At the Suricon2018 it was requested to add better support for detection of protocols w/o implementing full parsers.

Pierre, could you fill in more details of what you have in mind?


Related issues 2 (2 open0 closed)

Related to Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Related to Feature #2757: improve protocol detectionIn ReviewPhilippe AntoineActions
Actions #1

Updated by Victor Julien over 4 years ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
Actions #2

Updated by Philippe Antoine over 3 years ago

Are there specific protocols in mind ?
What is the use case ?
We have to watch for evasions to use this in a rules context...

Actions #3

Updated by Philippe Antoine over 3 years ago

Actions

Also available in: Atom PDF