Project

General

Profile

Actions

Optimization #7026

open

app-protos: trigger raw stream reassembly

Added by Juliana Fajardini Reichow 6 months ago. Updated 2 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

For application layer protocols over TCP that have transactions, we may need to trigger stream reassembly once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).


Subtasks 5 (0 open5 closed)

Bug #7000: pgsql: trigger raw stream reassemblyClosedJuliana Fajardini ReichowActions
Bug #7001: pgsql: trigger raw stream reassembly (7.0.x backport)ClosedJuliana Fajardini ReichowActions
Optimization #7018: dns/tcp: allow triggering raw stream reassemblyClosedJuliana Fajardini ReichowActions
Optimization #7075: dns/tcp: allow triggering raw stream reassembly (7.0.x backport)ClosedJuliana Fajardini ReichowActions
Optimization #7076: pgsql: trigger raw stream reassembly when tx completedRejectedJuliana Fajardini ReichowActions

Related issues 1 (1 open0 closed)

Related to Suricata - Bug #7004: app-layer: wrong tx may be logged for stream rulesIn ProgressJuliana Fajardini ReichowActions
Actions #1

Updated by OISF Ticketbot 6 months ago

  • Subtask #7027 added
Actions #2

Updated by OISF Ticketbot 6 months ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Juliana Fajardini Reichow 6 months ago

  • Private changed from No to Yes
Actions #4

Updated by Juliana Fajardini Reichow 6 months ago

  • Subtask #7018 added
Actions #5

Updated by Juliana Fajardini Reichow 6 months ago

Enip: should wait for https://github.com/OISF/suricata/pull/10901 to be merged.

Actions #6

Updated by Juliana Fajardini Reichow 6 months ago

  • Tracker changed from Bug to Optimization
  • Affected Versions deleted (7.0.5, git master)
Actions #7

Updated by Juliana Fajardini Reichow 6 months ago

  • Private changed from Yes to No
Actions #8

Updated by Juliana Fajardini Reichow 6 months ago

  • Subtask #7000 added
Actions #9

Updated by Juliana Fajardini Reichow 6 months ago

  • Subtask #7076 added
Actions #11

Updated by Juliana Fajardini Reichow 2 months ago

  • Related to Bug #7004: app-layer: wrong tx may be logged for stream rules added
Actions

Also available in: Atom PDF