Project

General

Profile

Actions

Feature #4102

open

plugins: support creating app-layer parser, logger and detect

Added by Jason Ish over 4 years ago. Updated about 1 month ago.

Status:
In Review
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

The idea is that full support for an application protocol can be added as a plugin. This includes the parser, the logger and any detection keywords related to this protocol.

It might be possible to break this down into sub-tasks, but tracking as an entire feature as that is the goal.


Subtasks 6 (6 open0 closed)

Documentation #7149: devguide: document adding a app-layer pluginIn ReviewPhilippe AntoineActions
Documentation #7150: devguide: document adding a logging pluginIn ReviewPhilippe AntoineActions
Task #7151: plugins: add template app-layer pluginIn ReviewPhilippe AntoineActions
Task #7152: plugins: add template logger pluginIn ReviewPhilippe AntoineActions
Documentation #7153: devguide: document adding a detection pluginIn ReviewPhilippe AntoineActions
Task #7154: plugins: add template detection pluginIn ReviewPhilippe AntoineActions

Related issues 3 (2 open1 closed)

Related to Suricata - Task #4101: tracking: pluginsIn ProgressJason IshActions
Related to Suricata - Task #5053: app-layer: dynamic alproto IDsClosedPhilippe AntoineActions
Blocks Suricata - Story #7148: extensibility: pluginsNewVictor JulienActions
Actions

Also available in: Atom PDF