Project

General

Profile

Feature #2757

improve protocol detection

Added by Victor Julien 6 months ago. Updated about 8 hours ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Currently protocol detection is a mix of port independent pattern based matching and port depended 'probing parsers'. This has served reasonably well, but also has serious limitations. Protocols that are similar in structure (e.g. smtp, ftp and irc) are not well supported.

The goal of the improvement is to fix these limitations.


Related issues

Related to Feature #273: IRC protocol detection supportNewActions
Related to Feature #511: Port indepedent protocol identificationNewActions
Related to Feature #1125: smtp: improve protocol detectionAssignedActions
Related to Support #2685: SuriCon 2018 brainstormNewActions
Related to Bug #2393: One way TLS traffic not properly identifiedAssignedActions
Related to Bug #2978: IRC traffic parsed by FTPNewActions

History

#1

Updated by Victor Julien 6 months ago

  • Related to Feature #273: IRC protocol detection support added
#2

Updated by Victor Julien 6 months ago

  • Related to Feature #511: Port indepedent protocol identification added
#3

Updated by Victor Julien 6 months ago

  • Related to Feature #1125: smtp: improve protocol detection added
#4

Updated by Victor Julien 6 months ago

#5

Updated by Victor Julien 4 months ago

  • Related to Bug #2393: One way TLS traffic not properly identified added
#6

Updated by Victor Julien 3 months ago

  • Status changed from New to Assigned
  • Assignee set to Victor Julien
#7

Updated by Victor Julien about 1 month ago

  • Related to Bug #2978: IRC traffic parsed by FTP added
#8

Updated by Andreas Herz about 8 hours ago

  • Target version set to TBD

Also available in: Atom PDF