Project

General

Profile

Actions

Bug #8713

open
VJ OD

firewall: multi-state or stateless keywords not supported

Bug #8713: firewall: multi-state or stateless keywords not supported

Added by Victor Julien 22 days ago. Updated 22 days ago.

Status:
Triaged
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Various keywords are not linked to a specific hook/state. E.g. http2.frametype or tls.version. However currently they are hooked into a specific state, limiting their use.

There should probably be a new buffer type that is not registered at a specific progress value, but instead it should allow hooking into all progress values.

A rule like accept:hook http2:stream:request_started .. http2.frametype:DATA; should insert a AppInspectEngine that hooks it to hook http2:stream:request_started.


Related issues 2 (2 open0 closed)

Related to Suricata - Bug #8256: detect: http.headers does not work on trailers when it is not fast_patternIn ReviewPhilippe AntoineActions
Related to Suricata - Feature #8386: firewall: support HTTP2 hook states for per-frame accept/drop decisionsResolvedVictor JulienActions

LS Updated by Lukas Sismis 22 days ago Actions #1

  • Status changed from New to Triaged
  • Assignee set to OISF Dev
  • Target version changed from TBD to 9.0.0-beta1

VJ Updated by Victor Julien 19 days ago Actions #2

  • Related to Bug #8256: detect: http.headers does not work on trailers when it is not fast_pattern added

VJ Updated by Victor Julien 16 days ago Actions #3

  • Related to Feature #8386: firewall: support HTTP2 hook states for per-frame accept/drop decisions added
Actions

Also available in: PDF Atom