Actions
Feature #4174
open
VJ
VJ
tracking: app-layer frame inspection support
Feature #4174:
tracking: app-layer frame inspection support
Effort:
Difficulty:
Label:
Description
Effort to make it possible to avoid raw tcp data inspection. Many rules looking for application records make assumptions about pdu's aligning with packets.
Rules should be able to do something like alert ftp ... (frame:ftp.command; content:"USER"; ... ).
Frames should be defined by the app-layer parsers.
VJ Updated by Victor Julien over 5 years ago
- Related to Task #4097: Suricon 2020 brainstorm added
VJ Updated by Victor Julien over 4 years ago
- Related to Documentation #4697: devguide: document app-layer frame support added
VJ Updated by Victor Julien over 4 years ago
- Status changed from Assigned to In Progress
VJ Updated by Victor Julien over 4 years ago
- Related to Task #4871: tracking: implement frames for all parsers added
VJ Updated by Victor Julien over 4 years ago
- Subject changed from tracking: app_record / pdu inspection support to tracking: app-layer frame inspection support
- Description updated (diff)
VJ Updated by Victor Julien almost 4 years ago
- Related to Task #4772: tracking: parity between fields logged and fields available for detection added
VJ Updated by Victor Julien over 3 years ago
- Target version changed from 7.0.0-beta1 to 7.0.0-rc1
VJ Updated by Victor Julien over 3 years ago
- Target version changed from 7.0.0-rc1 to 8.0.0-beta1
VJ Updated by Victor Julien about 1 year ago
- Target version changed from 8.0.0-beta1 to 9.0.0-beta1
Actions