Project

General

Profile

Actions

Bug #3400

closed

smb: post-GAP file tx handling

Added by Victor Julien over 4 years ago. Updated about 4 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

As #3399 but for file transactions.

File transactions are handled separately, as they can deal with GAPs to some extend. However if we don't see records belonging to a file transaction after a GAP, it may never get closed.

Idea now is to give these transactions a timestamp after a GAP, and then remove them after a timeout.


Related issues 5 (1 open4 closed)

Related to Suricata - Bug #3399: smb: post-GAP some transactions never closeClosedVictor JulienActions
Related to Suricata - Bug #3375: Tracking: file tracking/inspection performance issuesNewVictor JulienActions
Related to Suricata - Bug #3425: nfs: post-GAP file tx handlingClosedVictor JulienActions
Related to Suricata - Bug #3699: smb: post-GAP file handlingClosedVictor JulienActions
Copied to Suricata - Bug #3452: smb: post-GAP file tx handling (4.1.x)ClosedVictor JulienActions
Actions

Also available in: Atom PDF