Project

General

Profile

Actions

Bug #7521

open

detect/ip-only: false positive alerts on pseudo packets ending a one direction flow

Added by Victor Julien 29 days ago. Updated 4 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

If a single direction flow leads to a flow timeout packet in the opposite direction, IP-only inspection is done on that pseudo packet as if it is a real packet, leading to false positive alerts.


Subtasks 1 (1 open0 closed)

Bug #7522: detect/ip-only: false positive alerts on pseudo packets ending a one direction flow (7.0.x backport)AssignedVictor JulienActions
Actions #1

Updated by OISF Ticketbot 29 days ago

  • Subtask #7522 added
Actions #2

Updated by OISF Ticketbot 29 days ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Victor Julien 29 days ago

  • Status changed from In Progress to In Review
Actions #4

Updated by Victor Julien 4 days ago

  • Status changed from In Review to Resolved
Actions

Also available in: Atom PDF