Project

General

Profile

Actions

Feature #5665

open

rules: bidirectional transaction matching

Added by Philippe Antoine over 1 year ago. Updated about 2 months ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

As a HTTP1 rule with uri and response code


Related issues 5 (5 open0 closed)

Related to Suricata - Task #5488: Suricon 2022 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #2280: http: rules that match both request and responseAssignedVictor JulienActions
Related to Suricata - Feature #4321: http2: Support link between packets in the same stream NewActions
Related to Suricata - Task #6443: Suricon 2023 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #5664: "Scope" bits should have an expirationAssignedShivani BhardwajActions
Actions #1

Updated by Philippe Antoine over 1 year ago

  • Related to Task #5488: Suricon 2022 brainstorm added
Actions #2

Updated by Victor Julien over 1 year ago

  • Related to Feature #2280: http: rules that match both request and response added
Actions #3

Updated by Victor Julien over 1 year ago

  • Subject changed from Bidirectional transaction matching to rules: bidirectional transaction matching
Actions #4

Updated by Philippe Antoine 6 months ago

  • Related to Feature #4321: http2: Support link between packets in the same stream added
Actions #5

Updated by Philippe Antoine 6 months ago

  • Related to Task #6443: Suricon 2023 brainstorm added
Actions #6

Updated by Philippe Antoine 6 months ago

  • Related to Feature #5664: "Scope" bits should have an expiration added
Actions #7

Updated by Philippe Antoine 6 months ago

Difficulty is file.data buffer is streamed and not retained.

Most keywords like http.uri should be easier...

Actions #8

Updated by Philippe Antoine 3 months ago

  • Assignee changed from OISF Dev to Philippe Antoine

Trying thinking about it

Actions #9

Updated by Philippe Antoine 3 months ago

  • Status changed from New to In Progress
Actions #10

Updated by Philippe Antoine 3 months ago

  • Target version changed from TBD to 8.0.0-beta1
Actions #11

Updated by Philippe Antoine 3 months ago

  • Status changed from In Progress to In Review
Actions #12

Updated by Philippe Antoine 3 months ago

  • Status changed from In Review to In Progress

Today's status : https://github.com/OISF/suricata/pull/10252
Try to lift off the limitations

Actions #13

Updated by Philippe Antoine about 2 months ago

  • Status changed from In Progress to In Review

https://github.com/OISF/suricata/pull/10506

POC is good enough...
Rounds of reviews to expect...
And the feature for delaying prefiltering on the toclient direction... may come with this ticket or a next one...

Actions

Also available in: Atom PDF