Project

General

Profile

Actions

Feature #3271

open

Add keyword to determine flow based speed/bw

Added by Andreas Herz about 5 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It would be helpful to have a keyword to match a specific bandwith/rate as this could be also used to bypass high traffic flows.

The simple form would be bytes in relation to flow age, pkts and bytes are already tracked as well. It's harder if it needs to be some sliding window with a period of time.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #2319: Expose flow lifetime to the rulelanguageRejectedActions
Related to Suricata - Task #5645: tracking: elephant flow detectionNewOISF DevActions
Actions #1

Updated by Andreas Herz about 5 years ago

  • Related to Feature #2319: Expose flow lifetime to the rulelanguage added
Actions #2

Updated by Victor Julien about 2 years ago

  • Related to Task #5645: tracking: elephant flow detection added
Actions

Also available in: Atom PDF