Project

General

Profile

Actions

Optimization #5180

closed

stream/tcp: flag 1st seen pkt w stream established

Added by Juliana Fajardini Reichow about 4 years ago. Updated 12 days ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Considering that an alert could be discarded from the packet queue due to queue size limitations, we must consider how signatures with the `drop` action are still taken into account, even if the respective alert is dropped.

I guess... thought must also be given with regards to how do we indicate what is going on with said traffic, even if the alert isn't kept. Debug log? Specific stats counter?


Subtasks 1 (0 open1 closed)

Optimization #8299: stream/tcp: flag 1st seen pkt w stream established (8.0.x backport)ClosedPhilippe AntoineActions

Related issues 2 (0 open2 closed)

Related to Suricata - Optimization #5178: detect/alert: improve packet alert queue handlingRejectedJuliana Fajardini ReichowActions
Related to Suricata - Security #8021: eve/alert: heap buffer overflow on verdictClosedVictor JulienActions
Actions #1

Updated by Juliana Fajardini Reichow about 4 years ago

Actions #2

Updated by Juliana Fajardini Reichow about 4 years ago

  • Subject changed from detect/alert: make sure that signature with `drop` action are respected, even if the alert is discarded to detect/alert: make sure that signatures with `drop` action are respected, even if the alert is discarded
Actions #3

Updated by Juliana Fajardini Reichow almost 4 years ago

  • Status changed from New to In Progress
Actions #4

Updated by Juliana Fajardini Reichow almost 4 years ago

  • Status changed from In Progress to Assigned

Will stop current work on this issue because we will try to follow the approach for #4943.

Actions #5

Updated by Juliana Fajardini Reichow almost 4 years ago

  • Target version changed from TBD to 7.0.0-beta1
Actions #6

Updated by Juliana Fajardini Reichow almost 4 years ago

  • Status changed from Assigned to In Progress
Actions #7

Updated by Juliana Fajardini Reichow almost 4 years ago

Back to working on this.

Draft PR for appreciation and improvements: https://github.com/OISF/suricata/pull/7469

Actions #8

Updated by Victor Julien over 3 years ago

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1
Actions #9

Updated by Juliana Fajardini Reichow about 3 years ago

  • Tracker changed from Task to Optimization
Actions #10

Updated by Juliana Fajardini Reichow about 3 years ago

  • Target version changed from 7.0.0-rc1 to 7.0.0-rc2
Actions #11

Updated by Juliana Fajardini Reichow almost 3 years ago

  • Target version changed from 7.0.0-rc2 to 8.0.0-beta1
Actions #12

Updated by Victor Julien 12 months ago

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1
Actions #13

Updated by Victor Julien 9 months ago

  • Priority changed from Normal to High
  • Target version changed from 8.0.0-rc1 to 8.0.1
Actions #14

Updated by Juliana Fajardini Reichow 6 months ago

  • Target version changed from 8.0.1 to 8.0.2
Actions #15

Updated by Victor Julien 6 months ago

  • Target version changed from 8.0.2 to 9.0.0-beta1
Actions #16

Updated by Juliana Fajardini Reichow 5 months ago

  • Related to Security #8021: eve/alert: heap buffer overflow on verdict added
Actions #17

Updated by Juliana Fajardini Reichow about 2 months ago

Another PR for review: https://github.com/OISF/suricata/pull/14677
this covers the first probable bug that we've noticed while investigating this issue.

Actions #18

Updated by Juliana Fajardini Reichow 26 days ago

  • Status changed from In Progress to Resolved
  • Label Needs backport to 8.0 added
Actions #19

Updated by OISF Ticketbot 26 days ago

  • Subtask #8299 added
Actions #20

Updated by OISF Ticketbot 26 days ago

  • Label deleted (Needs backport to 8.0)
Actions #21

Updated by Victor Julien 16 days ago

  • Status changed from Resolved to Closed
Actions #22

Updated by Juliana Fajardini Reichow 12 days ago

  • Subject changed from detect/alert: make sure that signatures with `drop` action are respected, even if the alert is discarded to stream/tcp: flag 1st seen pkt w stream established

changing ticket subject to make it more aligned with the work done, and more changelog-compatible.

Actions

Also available in: Atom PDF