Project

General

Profile

Actions

Bug #8266

open

detect: erroneous alerts due to inconsistency between applayer and stream

Added by Shivani Bhardwaj 5 days ago. Updated 2 days ago.

Status:
In Progress
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
high
Label:

Description

In cases like https://github.com/OISF/suricata/pull/14649#issuecomment-3800282224 applayer can progress faster than stream, this can lead to inconsistent alerts and maybe more issues [TODO] (still being researched).


Related issues 1 (1 open0 closed)

Blocks Suricata - Task #7863: smb: trigger raw stream inspectionAssignedShivani BhardwajActions
Actions

Also available in: Atom PDF