Project

General

Profile

Actions

Task #7742

open

ftp: trigger raw stream inspection

Added by Shivani Bhardwaj 3 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
high
Label:

Description

For application layer protocols over TCP that have transactions, we need to trigger stream inspection once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).

FTP is likely the only missing protocol with this change because the raw inspection changes triggered IRC alerts. ref: https://github.com/OISF/suricata/pull/13303#issuecomment-2911424769


Related issues 3 (0 open3 closed)

Related to Suricata - Task #7026: app-protos: trigger raw stream inspectionClosedShivani BhardwajActions
Related to Suricata - Bug #7004: app-layer: wrong tx may be logged for stream rulesClosedShivani BhardwajActions
Blocked by Suricata - Bug #2978: IRC traffic parsed by FTPClosedPhilippe AntoineActions
Actions

Also available in: Atom PDF