Project

General

Profile

Actions

Optimization #5047

closed
VJ OD

sip: implement pattern based protocol detection

Optimization #5047: sip: implement pattern based protocol detection

Added by Victor Julien about 4 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Beginner

Description

SIP looks a lot like HTTP, so we can use HTTP like protocol detection to match SIP independent of port and fall back to the existing probing parser logic if that fails.


Related issues 1 (0 open1 closed)

Related to Suricata - Feature #3351: sip: parse traffic over tcpClosedGiuseppe LongoActions

VJ Updated by Victor Julien about 4 years ago Actions #1

PA Updated by Philippe Antoine almost 3 years ago Actions #2

I wonder if probing parser makes sense at all if we have pattern matching for protocol detection

VJ Updated by Victor Julien almost 3 years ago Actions #3

Based on my SIP knowledge I think pattern only should be enough.

PA Updated by Philippe Antoine almost 3 years ago Actions #4

  • Assignee set to OISF Dev
  • Target version set to 8.0.0-beta1

PA Updated by Philippe Antoine over 2 years ago Actions #5

  • Label Beginner added

GL Updated by Giuseppe Longo almost 2 years ago Actions #7

  • Status changed from In Progress to Closed
Actions

Also available in: PDF Atom