Project

General

Profile

Actions

Feature #5647

closed
VJ SB

Task #5645: tracking: elephant flow detection

rules: mark flow as elephant flow

Feature #5647: rules: mark flow as elephant flow

Added by Victor Julien over 3 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Idea here is that based on #5536, #3271, #5646 you can set a flag in the flow that is then added to eve.flow logs.

SB Updated by Shivani Bhardwaj almost 2 years ago Actions #1

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Shivani Bhardwaj
  • Target version changed from TBD to 8.0.0-beta1

VJ Updated by Victor Julien almost 2 years ago Actions #2

  • Priority changed from Normal to High

SB Updated by Shivani Bhardwaj over 1 year ago ยท Edited Actions #3

Idea here is that based on #5536, #3271, #5646 you can set a flag in the flow that is then added to eve.flow logs.

Q: Why can't we just set a flowbit based on flow bytes count and flow age?

I'm thinking:
1. have a setting in suricata.yaml that indicates the number of bytes and age of the flow after which a flow should be considered elephant flow.
2. allow overriding that setting for specific flows with a rule flag to the flow.bytes.. keyword that marks a flow elephant flow. Syntax could be something like flow.bytes_toserver:>=100000000,elephant incorrect since this does not take the age of the flow into account.
3. log elephant flow counter (unique elephant flows) in eve

Thoughts?

Note: What gets done with such a flow is not in scope of this ticket.

SB Updated by Shivani Bhardwaj over 1 year ago Actions #4

  • Status changed from Assigned to In Review

Initial idea of marking (NOT via rules) done here: https://github.com/OISF/suricata/pull/11645
Still thinking what the rules would look like.

SB Updated by Shivani Bhardwaj about 1 year ago Actions #5

  • Status changed from In Review to Closed

VJ Updated by Victor Julien about 1 year ago Actions #6

  • Priority changed from High to Normal
Actions

Also available in: PDF Atom