Project

General

Profile

Actions

Feature #4174

open

tracking: app_record / pdu inspection support

Added by Victor Julien 10 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Effort to make it possible to avoid raw tcp data inspection. Many rules looking for application records make assumptions about pdu's aligning with packets.

Rules should be able to do something like alert ftp ... (record; content:"USER"; ... ).


Related issues

Related to Task #4097: Suricon 2020 brainstormNewVictor JulienActions
Actions #1

Updated by Victor Julien 10 months ago

  • Related to Task #4097: Suricon 2020 brainstorm added
Actions

Also available in: Atom PDF