Actions
Optimization #7026
openapp-protos: trigger raw stream reassembly
Effort:
Difficulty:
Label:
Description
For application layer protocols over TCP that have transactions, we may need to trigger stream reassembly once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).
Updated by Juliana Fajardini Reichow 6 months ago
- Private changed from No to Yes
Updated by Juliana Fajardini Reichow 6 months ago
Enip: should wait for https://github.com/OISF/suricata/pull/10901 to be merged.
Updated by Juliana Fajardini Reichow 6 months ago
- Tracker changed from Bug to Optimization
- Affected Versions deleted (
7.0.5, git master)
Updated by Juliana Fajardini Reichow 6 months ago
- Private changed from Yes to No
Updated by Juliana Fajardini Reichow 6 months ago
ENIP merged: https://github.com/OISF/suricata/pull/11184
Updated by Juliana Fajardini Reichow 2 months ago
- Related to Bug #7004: app-layer: wrong tx may be logged for stream rules added
Actions