Project

General

Profile

Actions

Feature #5674

open

Support layered protocols

Added by Philippe Antoine about 2 years ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Like DCERPC can be directly over UDP, or over SMB


Related issues 2 (1 open1 closed)

Related to Suricata - Task #5488: Suricon 2022 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #5773: Support DNS over HTTPS (DoH)ClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine about 2 years ago

  • Related to Task #5488: Suricon 2022 brainstorm added
Actions #2

Updated by Philippe Antoine about 2 years ago

Like web socket, COTP...

Actions #3

Updated by Philippe Antoine about 1 year ago

Actions #4

Updated by Philippe Antoine about 1 year ago

Idea to do this : create a synthetic sub flow, so that each flow has its own app-layer

Actions #5

Updated by Philippe Antoine about 1 year ago

Philippe Antoine wrote in #note-4:

Idea to do this : create a synthetic sub flow, so that each flow has its own app-layer

People may get confused if two flows get logged (one synthetic and a real one) with different app-layers

Actions

Also available in: Atom PDF