Project

General

Profile

Actions

Feature #4587

closed

dhcp: vendor class indentifier support

Added by Jason Ortiz over 2 years ago. Updated 8 months ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:
Beginner, Good First Issue, Protocol, Rust

Description

DHCP Option 60 (vendor class identifier) is a very useful field in using DHCP Inform packets to identify various devices on a network. If Suricata could log this option it would open many opportunities for creating alerts for or identifying specific things on the network. I am not sure what level of effort would be required to log this option as I just joined the community so any help would be greatly appreciated!

Actions #1

Updated by Jason Ish over 2 years ago

  • Status changed from New to Assigned
  • Assignee set to Jason Ish
Actions #2

Updated by Victor Julien about 1 year ago

  • Status changed from Assigned to New
  • Assignee changed from Jason Ish to Community Ticket
  • Target version set to TBD
  • Label Beginner, Good First Issue, Protocol, Rust added
Actions #3

Updated by Yatin Kanetkar 8 months ago

  • Assignee changed from Community Ticket to Yatin Kanetkar
Actions #4

Updated by Yatin Kanetkar 8 months ago

  • Status changed from New to In Progress
Actions #5

Updated by Jason Ish 8 months ago

  • Status changed from In Progress to In Review

This is a useful addition, I'd like to recommend it for 7.0.1 and a 6.0.x backport.

Actions #6

Updated by Philippe Antoine 8 months ago

  • Target version changed from TBD to 7.0.1

Setting target version to 7.0.1 to decide if we want it now or later ;-)

PR is https://github.com/OISF/suricata/pull/9397

Actions #7

Updated by Victor Julien 8 months ago

  • Subject changed from DHCP Option Parsing to dhcp: vendor class indentifier support
Actions #8

Updated by Philippe Antoine 8 months ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF