Actions
Feature #8139
opendefrag: alert on / reject >=3 layer overlaps
Effort:
Difficulty:
Label:
Description
At Suricon 2025 Lucas Aubard and Johan Mazel presented their research on defrag overlap handling. They found that there are significant issues with >=3 layers of overlap. Their recommendation was to simply alert on that condition.
In IPS/fw modes this should come with a exception policy that defaults to drop.
Details on their research and tooling can be found at https://github.com/ANSSI-FR/pyrolyse
Updated by Victor Julien about 8 hours ago
- Subject changed from defrag: alert on / reject 3+ layer overlaps to defrag: alert on / reject >=3 layer overlaps
Actions