Project

General

Profile

Actions

Feature #3271

open

Add keyword to determine flow based speed/bw

Added by Andreas Herz over 4 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It would be helpful to have a keyword to match a specific bandwith/rate as this could be also used to bypass high traffic flows.

The simple form would be bytes in relation to flow age, pkts and bytes are already tracked as well. It's harder if it needs to be some sliding window with a period of time.


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #2319: Expose flow lifetime to the rulelanguageRejectedActions
Related to Suricata - Task #5645: tracking: elephant flow detectionNewOISF DevActions
Actions

Also available in: Atom PDF