Project

General

Profile

Actions

Feature #4099

closed
VJ VJ

app-layer: allow direct rule keyword registration

Feature #4099: app-layer: allow direct rule keyword registration

Added by Victor Julien over 5 years ago. Updated 10 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Related issues 3 (2 open1 closed)

Related to Suricata - Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Related to Suricata - Optimization #3304: generic way to register buffers for logging and detectionNewOISF DevActions
Related to Suricata - Task #4683: detect: remove sigmatch_table in favor of a dynamic storage optionClosedPhilippe AntoineActions

VJ Updated by Victor Julien over 5 years ago Actions #1

  • Related to Task #4097: Suricon 2020 brainstorm added

VJ Updated by Victor Julien over 4 years ago Actions #2

  • Target version changed from 7.0.0-beta1 to 8.0.0-beta1

PA Updated by Philippe Antoine over 2 years ago Actions #3

I do not understand what is expected here... Can you add more details ?

VJ Updated by Victor Julien almost 2 years ago Actions #4

  • Related to Optimization #3304: generic way to register buffers for logging and detection added

VJ Updated by Victor Julien almost 2 years ago Actions #5

  • Related to Task #4683: detect: remove sigmatch_table in favor of a dynamic storage option added

VJ Updated by Victor Julien over 1 year ago Actions #6

I think it is about what you made possible here https://github.com/OISF/suricata/pull/11291/commits/0726feff8c9caa317c60fbb211a400fe297971af, but then with the last step of not having to call this registration function from SigTableSetup but from the app-layer parsers registration logic. Perhaps this is already possible? Seems virtually the same as "detect plugins".

VJ Updated by Victor Julien over 1 year ago Actions #7

  • Subject changed from allow rule keyword registration from app-layer to app-layer: allow direct rule keyword registration

SB Updated by Shivani Bhardwaj about 1 year ago Actions #8

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1

PA Updated by Philippe Antoine 10 months ago Actions #9

Is this not done by SNMP now (see commit d24a3eb5f6a58551ca9db71fa41c5961712883f3 )

JI Updated by Jason Ish 10 months ago Actions #10

  • Status changed from Assigned to Closed

Closing. 8.0 has examples of this happening:
- The SNMP parser built-in to Suricata does dynamic registration of keywords
- The NDPI plugin does dynamic registration of keywords.

Actions

Also available in: PDF Atom