Project

General

Profile

Actions

Task #6858

open

Task #2693: tracking: libsuricata

libsuricata: hook for flow expectation creation

Added by Victor Julien about 1 month ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

A use case came up for having different sensors see different parts of the traffic, where one might see the ftp control channel and the other the data channel. For such use case it would be good to have a hook that can be used by the library API as well as by plugins to hook into the Flow "expectation" setup, so that this expectation can then be communicated to other sensors somehow.

No data to display

Actions

Also available in: Atom PDF