Project

General

Profile

Actions

Feature #273

open

IRC protocol detection support

Added by Victor Julien about 13 years ago. Updated over 3 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
medium
Label:
Protocol

Description

Support IRC in the protocol detection module so we can write rules like:
alert irc ....


Related issues 5 (4 open1 closed)

Related to Suricata - Feature #2757: improve protocol detectionIn ReviewPhilippe AntoineActions
Related to Suricata - Bug #2978: IRC traffic parsed by FTPNewPhilippe AntoineActions
Related to Suricata - Task #4151: Research: New protocol supportNewCommunity TicketActions
Related to Suricata - Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Blocked by Suricata - Feature #2572: extend protocol detection to specify flow directionClosedVictor JulienActions
Actions #1

Updated by Victor Julien about 13 years ago

  • Target version changed from 1.1beta2 to 1.1beta3
Actions #2

Updated by Victor Julien almost 13 years ago

  • Due date set to 04/29/2011
  • Assignee changed from Victor Julien to Anoop Saldanha
  • Estimated time set to 6.00 h

Anoop can you create a "probing parser" on top of task 209? Thanks!

Actions #3

Updated by Anoop Saldanha almost 13 years ago

Victor Julien wrote:

Anoop can you create a "probing parser" on top of task 209? Thanks!

cool

Actions #4

Updated by Victor Julien over 12 years ago

  • Target version changed from 1.1beta3 to 1.2

Retargeting to version 1.2 as some interaction issues with the ftp parser need to be addressed first.

Actions #5

Updated by Victor Julien over 12 years ago

  • Target version changed from 1.2 to TBD
Actions #6

Updated by Andreas Herz over 7 years ago

  • Assignee changed from Anoop Saldanha to OISF Dev

Is this still a thing to have dedicated IRC rules? :)

Actions #7

Updated by Victor Julien almost 6 years ago

  • Status changed from Assigned to New
  • Assignee deleted (OISF Dev)
  • Effort set to medium
  • Difficulty set to medium

This depends on protocol detection improvements. Right now patterns for ftp, smtp, and irc would be too similar and the proto detection is too dumb.

Actions #8

Updated by Victor Julien over 5 years ago

  • Blocked by Feature #2572: extend protocol detection to specify flow direction added
Actions #9

Updated by Victor Julien over 5 years ago

Actions #10

Updated by Victor Julien about 5 years ago

  • Assignee set to Community Ticket
Actions #11

Updated by Victor Julien almost 5 years ago

  • Related to Bug #2978: IRC traffic parsed by FTP added
Actions #12

Updated by Victor Julien over 3 years ago

  • Related to Task #4151: Research: New protocol support added
Actions #13

Updated by Victor Julien over 3 years ago

  • Related to Task #4097: Suricon 2020 brainstorm added
Actions #14

Updated by Victor Julien over 3 years ago

  • Label Protocol added
Actions

Also available in: Atom PDF