Project

General

Profile

Actions

Bug #3375

open
VJ VJ

tracking: file tracking/inspection performance issues

Bug #3375: tracking: file tracking/inspection performance issues

Added by Victor Julien over 6 years ago. Updated 6 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

In certain cases we can see the PrefilterTxFiledata at the top of perf measurements. This has uncovered various issues:

SMTP: tx id not set on files
SMTP: 'raw-message' as files support doesn't set files up properly
SMB: post-GAP we can have dangling txs that are neither updated nor closed

HTTP: pipelining requests can operate on wrong files (and set events in wrong tx)


Related issues 16 (1 open15 closed)

Related to Suricata - Bug #3376: http: pipelining tx id handling brokenClosedVictor JulienActions
Related to Suricata - Bug #3397: smtp: file tracking issues when more than one attachment in a txClosedVictor JulienActions
Related to Suricata - Bug #3398: smtp: 'raw-message' option file tracking issues with multi-txClosedVictor JulienActions
Related to Suricata - Bug #3399: smb: post-GAP some transactions never closeClosedVictor JulienActions
Related to Suricata - Bug #3400: smb: post-GAP file tx handlingClosedVictor JulienActions
Related to Suricata - Bug #3401: smb1: 'event only' transactions for bad requests never closeClosedVictor JulienActions
Related to Suricata - Bug #3393: http: pipelining tx id handling broken (4.1.x)ClosedVictor JulienActions
Related to Suricata - Bug #3404: smtp: file tracking issues when more than one attachment in a tx (4.1.x)ClosedVictor JulienActions
Related to Suricata - Bug #3403: smb1: 'event only' transactions for bad requests never close (4.1.x)ClosedVictor JulienActions
Related to Suricata - Bug #3402: smb: post-GAP some transactions never close (4.1.x)ClosedVictor JulienActions
Related to Suricata - Bug #3424: nfs: post-GAP some transactions never closeClosedVictor JulienActions
Related to Suricata - Bug #3425: nfs: post-GAP file tx handlingClosedVictor JulienActions
Related to Suricata - Bug #3699: smb: post-GAP file handlingClosedVictor JulienActions
Related to Suricata - Bug #3700: nfs: post-GAP file handlingClosedVictor JulienActions
Related to Suricata - Task #4444: files: store files in transactions instead of per flow stateClosedVictor JulienActions
Related to Suricata - Task #6217: research: increased tcp.overlap after file data changesAssignedVictor JulienActions

VJ Updated by Victor Julien over 6 years ago Actions #1

  • Affected Versions 4.1.5, 5.0.0 added

VJ Updated by Victor Julien over 6 years ago Actions #2

  • Related to Bug #3376: http: pipelining tx id handling broken added

VJ Updated by Victor Julien over 6 years ago Actions #3

  • Related to Bug #3397: smtp: file tracking issues when more than one attachment in a tx added

VJ Updated by Victor Julien over 6 years ago Actions #4

  • Related to Bug #3398: smtp: 'raw-message' option file tracking issues with multi-tx added

VJ Updated by Victor Julien over 6 years ago Actions #5

  • Related to Bug #3399: smb: post-GAP some transactions never close added

VJ Updated by Victor Julien over 6 years ago Actions #6

  • Related to Bug #3400: smb: post-GAP file tx handling added

VJ Updated by Victor Julien over 6 years ago Actions #7

  • Related to Bug #3401: smb1: 'event only' transactions for bad requests never close added

VJ Updated by Victor Julien over 6 years ago Actions #8

  • Related to Bug #3393: http: pipelining tx id handling broken (4.1.x) added

VJ Updated by Victor Julien over 6 years ago Actions #9

  • Related to Bug #3404: smtp: file tracking issues when more than one attachment in a tx (4.1.x) added

VJ Updated by Victor Julien over 6 years ago Actions #10

  • Related to Bug #3403: smb1: 'event only' transactions for bad requests never close (4.1.x) added

VJ Updated by Victor Julien over 6 years ago Actions #11

  • Related to Bug #3402: smb: post-GAP some transactions never close (4.1.x) added

VJ Updated by Victor Julien over 6 years ago Actions #12

  • Related to Bug #3424: nfs: post-GAP some transactions never close added

VJ Updated by Victor Julien over 6 years ago Actions #13

  • Related to Bug #3425: nfs: post-GAP file tx handling added

VJ Updated by Victor Julien almost 6 years ago Actions #14

  • Related to Bug #3699: smb: post-GAP file handling added

VJ Updated by Victor Julien almost 6 years ago Actions #15

  • Related to Bug #3700: nfs: post-GAP file handling added

VJ Updated by Victor Julien almost 5 years ago Actions #16

  • Related to Task #4444: files: store files in transactions instead of per flow state added

PA Updated by Philippe Antoine almost 3 years ago Actions #17

  • Target version set to 7.0.0

@Victor Julien every linked issue is closed, can this old tracking get closed as well ?

VJ Updated by Victor Julien almost 3 years ago Actions #18

  • Target version changed from 7.0.0 to 7.0.1

VJ Updated by Victor Julien over 2 years ago Actions #19

  • Related to Task #6217: research: increased tcp.overlap after file data changes added

VJ Updated by Victor Julien over 2 years ago Actions #20

  • Target version changed from 7.0.1 to 8.0.0-beta1

VJ Updated by Victor Julien about 1 year ago Actions #21

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1

SB Updated by Shivani Bhardwaj about 1 year ago Actions #22

  • Subject changed from Tracking: file tracking/inspection performance issues to tracking: file tracking/inspection performance issues
  • Target version changed from 8.0.0-rc1 to 9.0.0-beta1

The only open related ticket is targeted for 9.0.0-beta1. Retargetting this tracking ticket too.

VJ Updated by Victor Julien 6 months ago Actions #23

  • Status changed from New to Assigned
Actions

Also available in: PDF Atom