Project

General

Profile

Actions

Bug #3400

closed

smb: post-GAP file tx handling

Added by Victor Julien over 4 years ago. Updated about 4 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

As #3399 but for file transactions.

File transactions are handled separately, as they can deal with GAPs to some extend. However if we don't see records belonging to a file transaction after a GAP, it may never get closed.

Idea now is to give these transactions a timestamp after a GAP, and then remove them after a timeout.


Related issues 5 (1 open4 closed)

Related to Suricata - Bug #3399: smb: post-GAP some transactions never closeClosedVictor JulienActions
Related to Suricata - Bug #3375: Tracking: file tracking/inspection performance issuesNewVictor JulienActions
Related to Suricata - Bug #3425: nfs: post-GAP file tx handlingClosedVictor JulienActions
Related to Suricata - Bug #3699: smb: post-GAP file handlingClosedVictor JulienActions
Copied to Suricata - Bug #3452: smb: post-GAP file tx handling (4.1.x)ClosedVictor JulienActions
Actions #1

Updated by Victor Julien over 4 years ago

  • Related to Bug #3399: smb: post-GAP some transactions never close added
Actions #2

Updated by Victor Julien over 4 years ago

  • Related to Bug #3375: Tracking: file tracking/inspection performance issues added
Actions #3

Updated by Victor Julien over 4 years ago

  • Related to Bug #3425: nfs: post-GAP file tx handling added
Actions #4

Updated by Victor Julien about 4 years ago

  • Priority changed from Normal to High
Actions #5

Updated by Victor Julien about 4 years ago

  • Copied to Bug #3452: smb: post-GAP file tx handling (4.1.x) added
Actions #6

Updated by Victor Julien about 4 years ago

  • Status changed from Assigned to Closed
  • Label deleted (Needs backport)
Actions #7

Updated by Victor Julien almost 4 years ago

  • Related to Bug #3699: smb: post-GAP file handling added
Actions

Also available in: Atom PDF