Project

General

Profile

Actions

Feature #4241

closed
JI JF

Protocol support: PostgreSQL (pgsql)

Feature #4241: Protocol support: PostgreSQL (pgsql)

Added by Jason Ish over 5 years ago. Updated almost 4 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:
Protocol

Description

Add support for the PostgreSQL protocol. Not only will this add support for PostgreSQL but other databases that use the PostgreSQL wire format like CockroachDB, and I believe there are others.

The protocol is documented here: https://www.postgresql.org/docs/13/protocol.html

Initial basics should include support for:
- connection username and database
- queries

Thought should be given to what could be normalized in terms of detection keywords and logging with other database protocols, such as MySQL.


Subtasks 1 (0 open1 closed)

Optimization #4991: pgsql: convert parser to nom7 functionsClosedPierre ChifflierActions

Related issues 2 (2 open0 closed)

Related to Suricata - Feature #4566: pgsql: add subprotocol-statesIn ProgressJuliana Fajardini ReichowActions
Related to Suricata - Feature #4986: pgsql: support framesIn ProgressJuliana Fajardini ReichowActions

VJ Updated by Victor Julien over 5 years ago Actions #1

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
  • Target version set to 7.0.0-beta1

JF Updated by Juliana Fajardini Reichow almost 5 years ago Actions #2

  • Status changed from Assigned to In Progress

JF Updated by Juliana Fajardini Reichow over 4 years ago Actions #3

JF Updated by Juliana Fajardini Reichow over 4 years ago Actions #4

  • Priority changed from Normal to High

JF Updated by Juliana Fajardini Reichow about 4 years ago Actions #5

  • Subject changed from Protocol support: PostgreSQL to Protocol support: PostgreSQL (pgsql)
  • Status changed from In Progress to In Review

JF Updated by Juliana Fajardini Reichow about 4 years ago Actions #6

VJ Updated by Victor Julien almost 4 years ago Actions #8

  • Status changed from In Review to Closed
Actions

Also available in: PDF Atom