Project

General

Profile

Actions

Optimization #7026

open

app-protos: trigger raw stream reassembly

Added by Juliana Fajardini Reichow 4 months ago. Updated about 2 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

For application layer protocols over TCP that have transactions, we may need to trigger stream reassembly once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).


Subtasks 5 (3 open2 closed)

Bug #7000: pgsql: partially incorrect tx_id trackingResolvedJuliana Fajardini ReichowActions
Bug #7001: pgsql: partially incorrect tx_id tracking (7.0.x backport)In ProgressJuliana Fajardini ReichowActions
Optimization #7018: dns/tcp: allow triggering raw stream reassemblyClosedJuliana Fajardini ReichowActions
Optimization #7075: dns/tcp: allow triggering raw stream reassembly (7.0.x backport)ClosedJuliana Fajardini ReichowActions
Optimization #7076: pgsql: trigger raw stream reassembly when tx completedIn ProgressJuliana Fajardini ReichowActions
Actions #1

Updated by OISF Ticketbot 4 months ago

  • Subtask #7027 added
Actions #2

Updated by OISF Ticketbot 4 months ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Juliana Fajardini Reichow 4 months ago

  • Private changed from No to Yes
Actions #4

Updated by Juliana Fajardini Reichow 4 months ago

  • Subtask #7018 added
Actions #5

Updated by Juliana Fajardini Reichow 3 months ago

Enip: should wait for https://github.com/OISF/suricata/pull/10901 to be merged.

Actions #6

Updated by Juliana Fajardini Reichow 3 months ago

  • Tracker changed from Bug to Optimization
  • Affected Versions deleted (7.0.5, git master)
Actions #7

Updated by Juliana Fajardini Reichow 3 months ago

  • Private changed from Yes to No
Actions #8

Updated by Juliana Fajardini Reichow 3 months ago

  • Subtask #7000 added
Actions #9

Updated by Juliana Fajardini Reichow 3 months ago

  • Subtask #7076 added
Actions

Also available in: Atom PDF