Actions
Task #7742
openftp: trigger raw stream inspection
Effort:
Difficulty:
high
Label:
Description
For application layer protocols over TCP that have transactions, we need to trigger stream inspection once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).
FTP is likely the only missing protocol with this change because the raw inspection changes triggered IRC alerts. ref: https://github.com/OISF/suricata/pull/13303#issuecomment-2911424769
Updated by Shivani Bhardwaj 15 days ago
- Blocked by Bug #2978: IRC traffic parsed by FTP added
Updated by Shivani Bhardwaj 15 days ago
- Related to Task #7026: app-protos: trigger raw stream inspection added
Updated by Shivani Bhardwaj 15 days ago
- Related to Bug #7004: app-layer: wrong tx may be logged for stream rules added
Updated by Shivani Bhardwaj 15 days ago
- Copied to Task #7743: http: trigger raw stream inspection added
Updated by Shivani Bhardwaj 15 days ago
- Copied to deleted (Task #7743: http: trigger raw stream inspection)
Actions