Project

General

Profile

Actions

Task #8123

open

Task #4763: tracking: Suricon brainstorms

Suricon 2025 Brainstorm

Added by Juliana Fajardini Reichow 25 days ago. Updated 23 days ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Related issues 22 (22 open0 closed)

Related to Suricata - Feature #6831: rules: support extraction of bytes of non-numeric valuesNewVictor JulienActions
Related to Suricata - Feature #2487: rules: buffers for field/value pairs in http.uri and http.client_bodyAssignedPhilippe AntoineActions
Related to Suricata - Feature #2301: netflow: dump records at intervalFeedbackJason IshActions
Related to Suricata - Feature #473: pcap log: alert log with packet indexesNewCommunity TicketActions
Related to Suricata - Feature #7401: yaml: add schemaAssignedJason IshActions
Related to Suricata - Feature #3316: unix-socket: support dumping flow tableFeedbackCommunity TicketActions
Related to Suricata - Feature #8124: datasets: support subnets NewOISF DevActions
Related to Suricata - Optimization #8125: profiling: help investigating memory consumptionNewOISF DevActions
Related to Suricata - Feature #8130: http: http.uri should normalize the + into space as per RFC 1886AssignedPhilippe AntoineActions
Related to Suricata - Feature #8128: rules/transform: add json_decode transformNewOISF DevActions
Related to Suricata - Feature #4840: stats: distinguish between observational stats and performance statsNewOISF DevActions
Related to Suricata - Task #8131: modbus: add detection keywords to match logging valuesNewOISF DevActions
Related to Suricata - Feature #8117: rules: flow.elephant keywordIn ReviewShivani BhardwajActions
Related to Suricata - Task #3299: tracking: Add support for industrial protocolNewCommunity TicketActions
Related to Suricata - Feature #6461: ics protocol: bacnetNewGiuseppe LongoActions
Related to Suricata - Feature #4249: ics protocol: SS7 Protocol SupportAssignedSimon DugasActions
Related to Suricata - Task #4251: protocol: SCTP supportNewOISF DevActions
Related to Suricata - Task #4122: tracking: handle various TLS decrypt headers in proxies and decryption toolsAssignedVictor JulienActions
Related to Suricata - Feature #6462: ics protocol: IEC104 Protocol SupportNewCommunity TicketActions
Related to Suricata - Task #5678: tracking: improve handling of non-IP protocolsNewVictor JulienActions
Related to Suricata - Task #3301: Research: Failover support within the current IPS implementationNewCommunity TicketActions
Related to Suricata - Feature #5705: protocol: Wireguard parserAssignedPierre ChifflierActions
Actions #1

Updated by Juliana Fajardini Reichow 25 days ago

  • Parent task set to #4763
Actions #2

Updated by Juliana Fajardini Reichow 25 days ago

  • Related to Feature #6831: rules: support extraction of bytes of non-numeric values added
Actions #3

Updated by Juliana Fajardini Reichow 25 days ago

  • Related to Feature #2487: rules: buffers for field/value pairs in http.uri and http.client_body added
Actions #4

Updated by Jason Ish 25 days ago

  • Related to Feature #2301: netflow: dump records at interval added
Actions #5

Updated by Juliana Fajardini Reichow 25 days ago

  • Related to Feature #473: pcap log: alert log with packet indexes added
Actions #6

Updated by Juliana Fajardini Reichow 25 days ago

Actions #7

Updated by Jason Ish 25 days ago

  • Related to Feature #3316: unix-socket: support dumping flow table added
Actions #8

Updated by Juliana Fajardini Reichow 25 days ago

  • Tracker changed from Bug to Task
Actions #9

Updated by Juliana Fajardini Reichow 25 days ago

Actions #10

Updated by Juliana Fajardini Reichow 25 days ago

Actions #11

Updated by Philippe Antoine 24 days ago

  • Related to Feature #8130: http: http.uri should normalize the + into space as per RFC 1886 added
Actions #12

Updated by Philippe Antoine 24 days ago

  • Related to Feature #8128: rules/transform: add json_decode transform added
Actions #13

Updated by Juliana Fajardini Reichow 24 days ago

  • Related to Feature #4840: stats: distinguish between observational stats and performance stats added
Actions #14

Updated by Juliana Fajardini Reichow 24 days ago

  • Status changed from New to Assigned
Actions #15

Updated by Philippe Antoine 24 days ago

  • Related to Task #8131: modbus: add detection keywords to match logging values added
Actions #16

Updated by Juliana Fajardini Reichow 23 days ago

Actions #17

Updated by Philippe Antoine 23 days ago

  • Related to Task #3299: tracking: Add support for industrial protocol added
Actions #18

Updated by Jason Ish 23 days ago

Actions #19

Updated by Jason Ish 23 days ago

  • Related to Feature #4249: ics protocol: SS7 Protocol Support added
Actions #20

Updated by Philippe Antoine 23 days ago

  • Related to Task #4251: protocol: SCTP support added
Actions #21

Updated by Philippe Antoine 23 days ago

add more features to the supported protocols for Enhanced application protocol logs, Would be helpful - example - RDP, DHCP,MQTT, SMTP, Websockets, SMBCmd, FTP

Actions #22

Updated by Jason Ish 23 days ago

  • Related to Task #4122: tracking: handle various TLS decrypt headers in proxies and decryption tools added
Actions #23

Updated by Philippe Antoine 23 days ago

  • Related to Feature #6462: ics protocol: IEC104 Protocol Support added
Actions #24

Updated by Philippe Antoine 23 days ago

Would it be possible to have exception policies config options (and more configuration options) updated in real time, without requiring suricata restarts?

like unix-socket

Actions #25

Updated by Philippe Antoine 23 days ago

dataset expiration somehow, maybe it could have a TTL-like thing

Actions #26

Updated by Philippe Antoine 23 days ago

content-logging for ICMP

Actions #27

Updated by Philippe Antoine 23 days ago

  • Related to Task #5678: tracking: improve handling of non-IP protocols added
Actions #28

Updated by Philippe Antoine 23 days ago

More metrics for half-open connections would be useful

Actions #29

Updated by Philippe Antoine 23 days ago

ether.type keyword

Actions #30

Updated by Jason Ish 23 days ago

  • Related to Task #3301: Research: Failover support within the current IPS implementation added
Actions #31

Updated by Philippe Antoine 23 days ago

A preliminary list of configs that would be nice to be able to configure with unix socket.

exception policies.
Address groups (HOME_NET etc)
flow-timeouts settings
logging type configurations
elephant flow configurations

Actions #32

Updated by Philippe Antoine 23 days ago

Recognize RTP (to bypass it) a bit like FTP expectation : SIP to initialize communication and then go to random selected ports (from SIP) for RTP

Actions #33

Updated by Juliana Fajardini Reichow 23 days ago

Actions #34

Updated by Philippe Antoine 23 days ago

xposing smb.status, smb.command fields in the smb preprocessor would help write some better detections for things

Actions

Also available in: Atom PDF