Project

General

Profile

Actions

Task #7743

open
SB SB

http: trigger raw stream inspection

Task #7743: http: trigger raw stream inspection

Added by Shivani Bhardwaj 10 months ago. Updated 10 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
high
Label:

Description

For application layer protocols over TCP that have transactions, we need to trigger stream inspection once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).

The effort done around this resulted in some failing s-v tests. So, it has been skipped for now but should be looked at.


Related issues 3 (1 open2 closed)

Related to Suricata - Bug #7004: app-layer: wrong tx may be logged for stream rulesClosedShivani BhardwajActions
Related to Suricata - Task #7026: app-protos: trigger raw stream inspectionClosedShivani BhardwajActions
Related to Suricata - Optimization #5076: keyword content does not work over reassembled TCPAssignedVictor JulienActions

SB Updated by Shivani Bhardwaj 10 months ago Actions #1

  • Copied from Task #7742: ftp: trigger raw stream inspection added

SB Updated by Shivani Bhardwaj 10 months ago Actions #2

  • Copied from deleted (Task #7742: ftp: trigger raw stream inspection)

SB Updated by Shivani Bhardwaj 10 months ago Actions #3

  • Related to Bug #7004: app-layer: wrong tx may be logged for stream rules added

SB Updated by Shivani Bhardwaj 10 months ago Actions #4

  • Related to Task #7026: app-protos: trigger raw stream inspection added

SB Updated by Shivani Bhardwaj 9 months ago Actions #5

SB Updated by Shivani Bhardwaj 8 months ago Actions #6

  • Copied to Task #7863: smb: trigger raw stream inspection added

SB Updated by Shivani Bhardwaj 20 days ago Actions #7

  • Copied to deleted (Task #7863: smb: trigger raw stream inspection)

SB Updated by Shivani Bhardwaj 10 days ago Actions #8

  • Status changed from New to Assigned
Actions

Also available in: PDF Atom