Project

General

Profile

Actions

Feature #7092

open

frames: support rules with multiple different frames

Added by Philippe Antoine 5 months ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Example

alert enip any any -> any any (msg:"one present frame and one absent"; flow:established,to_server; frame:enip.hdr; bsize:24; frame:enip.cip; bsize: 12; sid:1;)

This behaves the same as

alert enip any any -> any any (msg:"one present frame and one absent"; flow:established,to_server; frame:enip.hdr; bsize:24; sid:1;)

First version could be to refuse to load such a rule
But it would be even better to have it working. Hint : these 2 frames belong to the same transaction


Related issues 1 (1 open0 closed)

Blocks Suricata - Story #7124: rules: improve rule languageNewVictor JulienActions
Actions

Also available in: Atom PDF