Project

General

Profile

Actions

Optimization #4141

closed

Task #4143: tracking: file.data improvements

file.data: inspect File objects for HTTP

Added by Victor Julien about 4 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

file.data for HTTP currently inspects the HtpBody instead of File(s). These will usually contain the same data, except for the multipart case.

Switching to File(s) would make the implementation simpler and make the implementation more correct.

David Wharton and Jae Williams have offered to run test runs for their rule collections to validate that this change won't break anything.


Related issues 3 (2 open1 closed)

Related to Suricata - Task #4097: Suricon 2020 brainstormAssignedVictor JulienActions
Related to Suricata - Bug #5868: filestore: not saving files when filestore enabled by rule matching on file_data (instead saves 0 bytes)ClosedJeff LucovskyActions
Related to Suricata - Task #6217: research: increased tcp.overlap after file data changesNewVictor JulienActions
Actions

Also available in: Atom PDF