Project

General

Profile

Actions

Feature #4102

closed

plugins: support creating app-layer parser, logger and detect

Added by Jason Ish over 4 years ago. Updated 11 days ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

The idea is that full support for an application protocol can be added as a plugin. This includes the parser, the logger and any detection keywords related to this protocol.

It might be possible to break this down into sub-tasks, but tracking as an entire feature as that is the goal.


Subtasks 6 (0 open6 closed)

Documentation #7149: devguide: document adding a app-layer pluginClosedPhilippe AntoineActions
Documentation #7150: devguide: document adding a logging pluginClosedPhilippe AntoineActions
Task #7151: plugins: add template app-layer pluginClosedPhilippe AntoineActions
Task #7152: plugins: add template logger pluginClosedPhilippe AntoineActions
Documentation #7153: devguide: document adding a detection pluginClosedPhilippe AntoineActions
Task #7154: plugins: add template detection pluginClosedPhilippe AntoineActions

Related issues 3 (2 open1 closed)

Related to Suricata - Task #4101: tracking: pluginsIn ProgressJason IshActions
Related to Suricata - Task #5053: app-layer: dynamic alproto IDsClosedPhilippe AntoineActions
Blocks Suricata - Story #7148: extensibility: pluginsNewVictor JulienActions
Actions

Also available in: Atom PDF