Project

General

Profile

Actions

Optimization #5047

closed

sip: implement pattern based protocol detection

Added by Victor Julien almost 3 years ago. Updated 7 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Beginner

Description

SIP looks a lot like HTTP, so we can use HTTP like protocol detection to match SIP independent of port and fall back to the existing probing parser logic if that fails.


Related issues 1 (0 open1 closed)

Related to Suricata - Feature #3351: sip: parse traffic over tcpClosedGiuseppe LongoActions
Actions

Also available in: Atom PDF