Skip to content

"Gluing" payloads in SecOnion #13690

Closed Locked Answered by spvcxsh1p
spvcxsh1p asked this question in Q&A
Discussion options

You must be logged in to vote

Hello! Thanks for your response, but the problem is slightly different.
I may not have expressed it clearly in my question, but I have already managed to solve part of the problem.

The question probably relates more to the Suricata module, and I shouldn't have referred to the SecOnion documentation.
I assumed that Suricata analyzes each packet individually, however, in addition to checking the payload of each packet individually, Suricata also performs "stream" traffic analysis.
In my example with SMB, I embedded the logic of checking the payload of each packet individually in the rule, because the Create Request in SMB packets is usually small and fits in the payload of a single TCP packet.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@spvcxsh1p
Comment options

Answer selected by spvcxsh1p
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants