Project

General

Profile

Actions

Feature #3086

closed

app_proto for Torrent traffic

Added by Kenneth Kolano over 5 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
medium
Difficulty:
medium
Label:
Protocol

Description

Currently the app_proto registered for Torrent traffic is "failed". Can the detection be revised to detect Torrent traffic?

It should be identifiable by the payload pre-fix: "d1:ad2:id20:".


Related issues 1 (1 open0 closed)

Related to Suricata - Task #4151: Research: New protocol supportNewCommunity TicketActions
Actions #1

Updated by Andreas Herz over 5 years ago

  • Assignee set to Community Ticket
  • Target version set to TBD
  • Effort set to medium
  • Difficulty set to medium
Actions #2

Updated by Aaron Bungay about 4 years ago

Working on this.

Actions #3

Updated by Victor Julien about 4 years ago

  • Status changed from New to Assigned
  • Assignee changed from Community Ticket to Aaron Bungay
Actions #4

Updated by Victor Julien about 4 years ago

Are you doing protocol detection only or a full parser?

Actions #5

Updated by Victor Julien about 4 years ago

  • Related to Task #4151: Research: New protocol support added
Actions #6

Updated by Aaron Bungay about 4 years ago

Victor Julien wrote in #note-4:

Are you doing protocol detection only or a full parser?

Doing a full parser in rust for the BitTorrent DHT protocol :)

Actions #7

Updated by Victor Julien about 4 years ago

  • Target version changed from TBD to 7.0.0-beta1
  • Label Protocol added

Great!

Actions #8

Updated by Aaron Bungay almost 4 years ago

Victor Julien wrote in #note-7:

Great!

PR created - https://github.com/OISF/suricata/pull/5809 :)

Actions #9

Updated by Victor Julien over 2 years ago

  • Status changed from Assigned to In Review
  • Assignee changed from Aaron Bungay to Jason Ish
Actions #10

Updated by Victor Julien over 2 years ago

  • Subject changed from app_proto for Torrent traffic? to app_proto for Torrent traffic
Actions #11

Updated by Victor Julien about 2 years ago

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1
Actions #13

Updated by Jason Ish almost 2 years ago

  • Status changed from In Review to Closed

Merged to master.

Actions

Also available in: Atom PDF