Project

General

Profile

Actions

Task #7742

closed
SB SB

ftp: trigger raw stream inspection

Task #7742: ftp: trigger raw stream inspection

Added by Shivani Bhardwaj 10 months ago. Updated 9 days ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
medium
Label:

Description

For application layer protocols over TCP that have transactions, we need to trigger stream inspection once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).

FTP is likely the only missing protocol with this change because the raw inspection changes triggered IRC alerts. ref: https://github.com/OISF/suricata/pull/13303#issuecomment-2911424769


Related issues 3 (0 open3 closed)

Related to Suricata - Task #7026: app-protos: trigger raw stream inspectionClosedShivani BhardwajActions
Related to Suricata - Bug #7004: app-layer: wrong tx may be logged for stream rulesClosedShivani BhardwajActions
Blocked by Suricata - Bug #2978: IRC traffic parsed by FTPClosedPhilippe AntoineActions

SB Updated by Shivani Bhardwaj 10 months ago Actions #1

  • Blocked by Bug #2978: IRC traffic parsed by FTP added

SB Updated by Shivani Bhardwaj 10 months ago Actions #2

  • Related to Task #7026: app-protos: trigger raw stream inspection added

SB Updated by Shivani Bhardwaj 10 months ago Actions #3

  • Related to Bug #7004: app-layer: wrong tx may be logged for stream rules added

SB Updated by Shivani Bhardwaj 10 months ago Actions #4

  • Copied to Task #7743: http: trigger raw stream inspection added

SB Updated by Shivani Bhardwaj 10 months ago Actions #5

  • Copied to deleted (Task #7743: http: trigger raw stream inspection)

SB Updated by Shivani Bhardwaj 4 months ago Actions #6

  • Status changed from New to In Progress

SB Updated by Shivani Bhardwaj 4 months ago Actions #7

  • Status changed from In Progress to Assigned

SB Updated by Shivani Bhardwaj 3 months ago Actions #8

  • Difficulty changed from high to medium

SB Updated by Shivani Bhardwaj 14 days ago Actions #9

  • Status changed from Assigned to In Review

VJ Updated by Victor Julien 14 days ago Actions #10

PR link missing?

VJ Updated by Victor Julien 14 days ago Actions #11

https://github.com/OISF/suricata/pull/15114 is the correct link, I think.

SB Updated by Shivani Bhardwaj 9 days ago Actions #12

  • Status changed from In Review to Closed
Actions

Also available in: PDF Atom