Project

General

Profile

Actions

Feature #7801

open
JL JL

rules: support multi-buffer byte variables

Feature #7801: rules: support multi-buffer byte variables

Added by Jeff Lucovsky 10 months ago. Updated about 1 month ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Issue 1412 described a situation with multiple buffers and byte variables.

Results are indeterminate and may cause issues when this occurs. Since there are existing rules that do this, it was decided for Suricata 8 that such usage will be
- Flagged as an error when --strict-rule-keywords is used
- Flagged with a warning message but permitted otherwise.

This ticket aims to resolve the indeterminate nature of the situation (see 1412) and provide full support for multi-buffer byte variables.


Related issues 3 (3 open0 closed)

Related to Suricata - Bug #1412: byte_test checks before byte_extract happens in some casesIn ReviewJeff LucovskyActions
Related to Suricata - Bug #7197: detect/flowvars: persist if the inspection happens on multiple packetsAssignedOISF DevActions
Related to Suricata - Bug #8458: detect/variable: warn if rules try to use byte vars before they're extractedNewActions

JL Updated by Jeff Lucovsky 10 months ago Actions #1

  • Related to Bug #1412: byte_test checks before byte_extract happens in some cases added

PA Updated by Philippe Antoine about 1 month ago Actions #2

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Jeff Lucovsky

VJ Updated by Victor Julien about 1 month ago Actions #3

  • Subject changed from Support multi-buffer byte variables to rules: support multi-buffer byte variables

PA Updated by Philippe Antoine 21 days ago Actions #4

  • Related to Bug #7197: detect/flowvars: persist if the inspection happens on multiple packets added

JL Updated by Jeff Lucovsky 19 days ago Actions #5

  • Related to Bug #8458: detect/variable: warn if rules try to use byte vars before they're extracted added
Actions

Also available in: PDF Atom