Project

General

Profile

Feature #2757

improve protocol detection

Added by Victor Julien about 1 month ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:

Description

Currently protocol detection is a mix of port independent pattern based matching and port depended 'probing parsers'. This has served reasonably well, but also has serious limitations. Protocols that are similar in structure (e.g. smtp, ftp and irc) are not well supported.

The goal of the improvement is to fix these limitations.


Related issues

Related to Feature #273: IRC protocol detection supportNew
Related to Feature #511: Port indepedent protocol identificationNew
Related to Feature #1125: smtp: improve protocol detectionNew
Related to Support #2685: SuriCon 2018 brainstormNew

History

#1 Updated by Victor Julien about 1 month ago

  • Related to Feature #273: IRC protocol detection support added

#2 Updated by Victor Julien about 1 month ago

  • Related to Feature #511: Port indepedent protocol identification added

#3 Updated by Victor Julien about 1 month ago

  • Related to Feature #1125: smtp: improve protocol detection added

#4 Updated by Victor Julien about 1 month ago

Also available in: Atom PDF