Feature #4174
open
tracking: app-layer frame inspection support
Added by Victor Julien almost 4 years ago.
Updated 2 months ago.
Description
Effort to make it possible to avoid raw tcp data inspection. Many rules looking for application records make assumptions about pdu's aligning with packets.
Rules should be able to do something like alert ftp ... (frame:ftp.command; content:"USER"; ... )
.
Frames should be defined by the app-layer parsers.
- Related to Task #4097: Suricon 2020 brainstorm added
- Status changed from Assigned to In Progress
- Related to Task #4871: tracking: implement frames for all parsers added
- Subject changed from tracking: app_record / pdu inspection support to tracking: app-layer frame inspection support
- Description updated (diff)
- Related to Task #4772: tracking: parity between fields logged and fields available for detection added
- Target version changed from 7.0.0-beta1 to 7.0.0-rc1
- Target version changed from 7.0.0-rc1 to 8.0.0-beta1
Also available in: Atom
PDF