Project

General

Profile

Actions

Feature #4770

open

eve: specialized output for ML on packet sizes and similar properties

Added by Victor Julien about 3 years ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Following Johan Mazel's Suricon 2021 talk on detecting protocols inside various encrypted (VPN) protocols, he mentioned that it would be helpful if Suricata would output some of the features the models use.

To be updated based on the paper/slides to include the actual features.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #4762: Suricon 2021 brainstormAssignedVictor JulienActions
Actions

Also available in: Atom PDF