Project

General

Profile

Actions

Bug #5076

open

keyword content does not work over reassembled TCP

Added by Philippe Antoine 8 months ago. Updated 5 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Using rule
alert ip any any -> any any (content:"HTTP/2.loc"; sid:11;)

on attached pcap

with stream.reassembly.toserver-chunk-size=25

does not trigger an alert

It does trigger the alert without the setting.

I fear we might have an evasion if I split the packets over the default value of 2560...


Subtasks 2 (1 open1 closed)

Bug #5110: keyword content does not work over reassembled TCP (6.0.x backport)AssignedShivani BhardwajActions
Bug #5111: keyword content does not work over reassembled TCP (5.0.x backport)RejectedActions

Related issues 1 (1 open0 closed)

Related to Documentation #2470: Suricata does not always alert on traffic with content that matches rulesFeedbackEric UrbanActions
Actions #2

Updated by Philippe Antoine 8 months ago

This was found during investigation of #4858

Actions #5

Updated by Jeff Lucovsky 8 months ago

  • Copied to Bug #5110: keyword content does not work over reassembled TCP (6.0.x backport) added
Actions #6

Updated by Jeff Lucovsky 8 months ago

  • Copied to Bug #5111: keyword content does not work over reassembled TCP (5.0.x backport) added
Actions #7

Updated by Philippe Antoine 3 months ago

From talk with Victor, this is a known limitation, where the chunk size is supposed to be a bit random to protect against evasion attempts.

The solution may be to use hyperscan as a streaming engine (instead of running it on different chunks/blocks)

Actions #8

Updated by Victor Julien 3 months ago

  • Label deleted (Needs backport)
Actions #9

Updated by Philippe Antoine 3 months ago

  • Related to Documentation #2470: Suricata does not always alert on traffic with content that matches rules added
Actions #10

Updated by Victor Julien 9 days ago

  • Target version changed from 7.0rc1 to 8.0beta1
Actions

Also available in: Atom PDF