Project

General

Profile

Feature #2757

improve protocol detection

Added by Victor Julien 3 months ago. Updated 9 days ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

Currently protocol detection is a mix of port independent pattern based matching and port depended 'probing parsers'. This has served reasonably well, but also has serious limitations. Protocols that are similar in structure (e.g. smtp, ftp and irc) are not well supported.

The goal of the improvement is to fix these limitations.


Related issues

Related to Feature #273: IRC protocol detection supportNewActions
Related to Feature #511: Port indepedent protocol identificationNewActions
Related to Feature #1125: smtp: improve protocol detectionAssignedActions
Related to Support #2685: SuriCon 2018 brainstormNewActions
Related to Bug #2393: One way TLS traffic not properly identifiedNew12/21/2017Actions

History

#1

Updated by Victor Julien 3 months ago

  • Related to Feature #273: IRC protocol detection support added
#2

Updated by Victor Julien 3 months ago

  • Related to Feature #511: Port indepedent protocol identification added
#3

Updated by Victor Julien 3 months ago

  • Related to Feature #1125: smtp: improve protocol detection added
#4

Updated by Victor Julien 3 months ago

#5

Updated by Victor Julien 30 days ago

  • Related to Bug #2393: One way TLS traffic not properly identified added
#6

Updated by Victor Julien 9 days ago

  • Status changed from New to Assigned
  • Assignee set to Victor Julien

Also available in: Atom PDF