suricata icon indicating copy to clipboard operation
suricata copied to clipboard

Ssh frames 5734 v2

Open catenacyber opened this issue 1 year ago • 1 comments

Link to ticket: https://redmine.openinfosecfoundation.org/issues/ https://redmine.openinfosecfoundation.org/issues/5734

Describe changes:

  • ssh: add frames support (for clear-text records after banner)
  • detect: run frames detection on packet disabling app-layer because next packets are encrypted

SV_BRANCH=https://github.com/OISF/suricata-verify/pull/1932

#11340 with clear PR history

catenacyber avatar Jun 27 '24 08:06 catenacyber

Information: QA ran without warnings.

Pipeline 21265

suricata-qa avatar Jun 27 '24 10:06 suricata-qa

Continued in https://github.com/OISF/suricata/pull/11415

catenacyber avatar Jul 04 '24 07:07 catenacyber