Project

General

Profile

Actions

Optimization #3304

open

generic way to register buffers for logging and detection

Added by Andreas Herz about 5 years ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Currently creating support for logging protocol fields and matching protocol fields are distinct steps during development.

Goal is to unify this so the protocol parser implementations simply register a buffer/field once.


Related issues 4 (4 open0 closed)

Related to Suricata - Task #3288: Suricon 2019 brainstormAssignedVictor JulienActions
Related to Suricata - Task #4101: tracking: pluginsIn ProgressJason IshActions
Related to Suricata - Feature #4099: allow rule keyword registration from app-layerAssignedVictor JulienActions
Related to Suricata - Feature #7095: rdp: keywords additionsNewOISF DevActions
Actions #1

Updated by Victor Julien about 5 years ago

  • Subject changed from Make sure output of protocol parsers and keywords are both supported to generic way to register buffers for logging and detection
  • Description updated (diff)
Actions #2

Updated by Victor Julien about 5 years ago

  • Parent task deleted (#3288)
Actions #3

Updated by Victor Julien about 5 years ago

  • Related to Task #3288: Suricon 2019 brainstorm added
Actions #4

Updated by Victor Julien about 4 years ago

Actions #5

Updated by Philippe Antoine almost 2 years ago

As I see it, the main problem is that detection requires redmine ticket + suricata-verify test + documentation when logging does not

Actions #6

Updated by Philippe Antoine about 1 year ago

Idea about this : using magic rust derive that would parse a struct and see which fiels are annotated for logging and/or detection and create functions to log them or get the buffer/integer for detection

Actions #7

Updated by Victor Julien 6 months ago

  • Related to Feature #4099: allow rule keyword registration from app-layer added
Actions #8

Updated by Philippe Antoine 6 months ago

@Jason Ish was there not a duplicate ticket for this we talked about yesterday ?

Actions #9

Updated by Philippe Antoine 6 months ago

Actions

Also available in: Atom PDF