Project

General

Profile

Actions

Feature #7313

open
PA JL

transforms: have option on how to handle failure

Feature #7313: transforms: have option on how to handle failure

Added by Philippe Antoine over 1 year ago. Updated 10 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Transforms like base64, pcrexform or urldecode may somehow fail.

Current default is to passthrough
But we could have an option to these keywords to behave differently, like return a NULL or 0-length buffer instead of the original one.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #7114: from_base64: allow matching on decode errorIn ReviewJeff LucovskyActions
Related to Suricata - Feature #8470: detect/transform: Create anomaly log on transform failureNewActions
Actions

Also available in: PDF Atom