Project

General

Profile

Actions

Task #5893

open

tracking: deep file awareness and inspection

Added by Victor Julien almost 2 years ago. Updated almost 2 years ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It's come up several times that it would be helpful for Suricata to understand file types better for classification and deeper analysis.

Currently Suricata for the most part treats files as binary blobs. The only deeper inspection is through file.magic, which has several issues limiting it's usefulness.

Making Suricata more aware of files and their content and structure will be a significant project.

The goal of this ticket is to track the various ideas that are related to this broad topic.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #5872: file structure awareness - precise identification of fields in file structsNewCommunity TicketActions
Related to Suricata - Feature #5894: file: file classification keywordFeedbackVictor JulienActions
Actions #1

Updated by Victor Julien almost 2 years ago

  • Description updated (diff)
Actions #2

Updated by Victor Julien almost 2 years ago

  • Related to Feature #5872: file structure awareness - precise identification of fields in file structs added
Actions #3

Updated by Victor Julien almost 2 years ago

  • Related to Feature #5894: file: file classification keyword added
Actions

Also available in: Atom PDF