Project

General

Profile

Actions

Task #5510

open

stream (midstream): investigate - Suri drops flow but still logs second packet of the flow

Added by Juliana Fajardini Reichow almost 2 years ago. Updated 2 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

In IPS mode with stream.midstream=true, if we have a flow that is first seen
in ACK state by Suri and matches against a drop rule, Suri correctly drops the
flow, but still logs an applayer event for the second packet.

Investigated and was able to reproduce this with HTTP and SMB protos. Will add
an SV test to demonstrate.

I noticed this while working on an exception policy for midstream (#5468),
and was able to reproduce on a clean master branch as well.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5802: ips: txs still logged for dropped flowClosedVictor JulienActions
Actions #2

Updated by Juliana Fajardini Reichow over 1 year ago

  • Target version changed from TBD to 8.0.0-beta1
Actions #3

Updated by Juliana Fajardini Reichow over 1 year ago

  • Related to Bug #5802: ips: txs still logged for dropped flow added
Actions #4

Updated by Victor Julien 2 days ago

  • Assignee changed from Juliana Fajardini Reichow to OISF Dev
Actions

Also available in: Atom PDF