Project

General

Profile

Actions

Feature #4770

open
VJ CT

eve: specialized output for ML on packet sizes and similar properties

Feature #4770: eve: specialized output for ML on packet sizes and similar properties

Added by Victor Julien over 4 years ago. Updated almost 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Following Johan Mazel's Suricon 2021 talk on detecting protocols inside various encrypted (VPN) protocols, he mentioned that it would be helpful if Suricata would output some of the features the models use.

To be updated based on the paper/slides to include the actual features.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #4762: Suricon 2021 brainstormAssignedVictor JulienActions

VJ Updated by Victor Julien over 4 years ago Actions #1

  • Related to Task #4762: Suricon 2021 brainstorm added

PA Updated by Philippe Antoine almost 2 years ago Actions #2

  • Assignee set to Community Ticket
  • Target version set to TBD
Actions

Also available in: PDF Atom