Actions
Feature #2713
closedprotocol detection w/o protocol parsing
Effort:
Difficulty:
Label:
Description
At the Suricon2018 it was requested to add better support for detection of protocols w/o implementing full parsers.
Pierre, could you fill in more details of what you have in mind?
Updated by Victor Julien almost 6 years ago
- Related to Task #2685: SuriCon 2018 brainstorm added
Updated by Philippe Antoine about 5 years ago
Are there specific protocols in mind ?
What is the use case ?
We have to watch for evasions to use this in a rules context...
Updated by Philippe Antoine about 5 years ago
- Related to Task #2757: improve protocol detection added
Updated by Philippe Antoine about 1 year ago
- Related to Feature #6366: pop3 protocol detection added
Updated by Philippe Antoine about 1 year ago
- Status changed from Feedback to Closed
Closing as stale, feel free to reopen if tou have specific protocols in mind Pierre
Actions