Project

General

Profile

Actions

Feature #2757

open

improve protocol detection

Added by Victor Julien over 5 years ago. Updated over 1 year ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Currently protocol detection is a mix of port independent pattern based matching and port depended 'probing parsers'. This has served reasonably well, but also has serious limitations. Protocols that are similar in structure (e.g. smtp, ftp and irc) are not well supported.

The goal of the improvement is to fix these limitations.


Files

sshsmb.pcap (1.84 KB) sshsmb.pcap Philippe Antoine, 07/28/2020 09:24 AM

Related issues 10 (9 open1 closed)

Related to Suricata - Feature #273: IRC protocol detection supportNewCommunity TicketActions
Related to Suricata - Feature #511: Port indepedent protocol identification (nDPI)NewCommunity TicketActions
Related to Suricata - Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Related to Suricata - Bug #2978: IRC traffic parsed by FTPNewPhilippe AntoineActions
Related to Suricata - Feature #2713: protocol detection w/o protocol parsingClosedPierre ChifflierActions
Related to Suricata - Task #3392: Tracking: protocol detection evasionsNewPhilippe AntoineActions
Related to Suricata - Feature #1125: smtp: improve protocol detectionIn ReviewPhilippe AntoineActions
Related to Suricata - Feature #6366: pop3 protocol detectionIn ReviewPhilippe AntoineActions
Related to Suricata - Bug #2886: IMAP protocol detection is incompleteIn ReviewMahmoud MaatuqActions
Related to Suricata - Bug #6591: protodetect: ftp parsed as smtpNewOISF DevActions
Actions

Also available in: Atom PDF