Project

General

Profile

Actions

Task #2757

open

improve protocol detection

Added by Victor Julien almost 6 years ago. Updated 5 months ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Currently protocol detection is a mix of port independent pattern based matching and port depended 'probing parsers'. This has served reasonably well, but also has serious limitations. Protocols that are similar in structure (e.g. smtp, ftp and irc) are not well supported.

The goal of the improvement is to fix these limitations.


Files

sshsmb.pcap (1.84 KB) sshsmb.pcap Philippe Antoine, 07/28/2020 09:24 AM

Related issues 10 (6 open4 closed)

Related to Suricata - Feature #273: IRC protocol detection supportNewCommunity TicketActions
Related to Suricata - Feature #511: Port indepedent protocol identification (nDPI)NewCommunity TicketActions
Related to Suricata - Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Related to Suricata - Bug #2978: IRC traffic parsed by FTPIn ProgressPhilippe AntoineActions
Related to Suricata - Feature #2713: protocol detection w/o protocol parsingClosedPierre ChifflierActions
Related to Suricata - Task #3392: Tracking: protocol detection evasionsNewPhilippe AntoineActions
Related to Suricata - Feature #1125: smtp: improve protocol detectionClosedPhilippe AntoineActions
Related to Suricata - Feature #6366: pop3 protocol detectionClosedPhilippe AntoineActions
Related to Suricata - Bug #2886: IMAP protocol detection is incompleteClosedMahmoud MaatuqActions
Related to Suricata - Bug #6591: protodetect: ftp parsed as smtpNewOISF DevActions
Actions

Also available in: Atom PDF