Project

General

Profile

Actions

Feature #727

closed

Explore the support for negated alprotos in sigs.

Added by Anoop Saldanha over 11 years ago. Updated over 10 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Explore the support for the use of negated alprotos in sigs -

alert !alproto ...

Actions #1

Updated by Victor Julien about 11 years ago

  • Status changed from New to Assigned
  • Target version set to 2.0rc2

I think I would prefer to have this as a regular rule keyword. Esp since then you would be able to do something like:

alert tcp .... (alproto:!ftp; alproto:!http;)

Actions #2

Updated by Anoop Saldanha about 11 years ago

Yeah, sounds good.

Maybe app-layer-protocol, since we have app-layer-event?

Actions #3

Updated by Victor Julien about 11 years ago

Sure.

Actions #5

Updated by Victor Julien over 10 years ago

  • Target version changed from 2.0rc2 to 2.0beta2
Actions

Also available in: Atom PDF