Actions
Task #5050
openFeature #4174: tracking: app-layer frame inspection support
rules/frames: settle on rule syntax
Effort:
Difficulty:
Label:
Description
Currently frames are accessed through a frames
keyword. We could also allow using the frame names directly in rules, like alert sip ... (request_line; content:"REGISTER"; ...)
. This needs more thought about how it ties in to other rule syntax.
See also https://github.com/OISF/suricata/pull/6915/commits/ae71c5813fd77d22a5e03b71b1012d670b13b698
Updated by Juliana Fajardini Reichow over 2 years ago
- Related to Task #5181: detect/engine-analyzer: add rule analyzer warnings about rules that could use the frame keyword/semantics/feature added
Updated by Juliana Fajardini Reichow over 2 years ago
- Related to Documentation #4705: userguide: add sections about frame support added
Updated by Victor Julien about 2 years ago
- Target version changed from 7.0.0-beta1 to 8.0.0-beta1
Actions