Project

General

Profile

Actions

Optimization #7304

closed
PA PA

detect: improve support for multi-protocol keywords

Optimization #7304: detect: improve support for multi-protocol keywords

Added by Philippe Antoine over 1 year ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Have a rule like
alert ip any any -> any any (sid: 1; file.data; content: "toto"; ja3.hash; content: "abcdef0123456789abcdef0123456789";)
failing to load

Currently, multi protocol keywords are :
- DCERPC/SMB stuff
- JA3/JA4 for quic/tls
- file keywords
- HTTP/1 HTTP/2 somehow
DoH2 does not have this...


Related issues 1 (0 open1 closed)

Related to Suricata - Task #5053: app-layer: dynamic alproto IDsClosedPhilippe AntoineActions

PA Updated by Philippe Antoine over 1 year ago Actions #1

  • Status changed from New to In Review
  • Target version changed from TBD to 8.0.0-beta1

PA Updated by Philippe Antoine over 1 year ago Actions #2

  • Related to Task #5053: app-layer: dynamic alproto IDs added

PA Updated by Philippe Antoine over 1 year ago Actions #3

I think DCERPC over SMB and DNS over HTTP are the same logically, even if not in Suricata code...

PA Updated by Philippe Antoine about 1 year ago Actions #4

  • Status changed from In Review to Closed

VJ Updated by Victor Julien about 1 year ago Actions #5

  • Subject changed from Better support multi-protocol keywords to detect: improve support for multi-protocol keywords
Actions

Also available in: PDF Atom