You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Starting from 08 August 2017 ET is adding new metadata to its rules, (as stated herre).
This is a big help for developers and analists, but there are some problem with the rule parser: if there are more than 1 metadata tag in the raw rule only the last will be kept by the parser. This because the code does not assume that anyone would use more than 1 metadata tag in each rule (code here).
As stated in SNORT rule manual and in Suricata sources, metadata are ignored by IDS/IPS engine. Also examples states that a writer can use more than one metadata tag.
The right behaviour would be to append any new metadata list to the existing one.
The text was updated successfully, but these errors were encountered:
Starting from 08 August 2017 ET is adding new
metadata
to its rules, (as stated herre).This is a big help for developers and analists, but there are some problem with the rule parser: if there are more than 1
metadata
tag in the raw rule only the last will be kept by the parser. This because the code does not assume that anyone would use more than 1metadata
tag in each rule (code here).However some rule now has 2
metadata
tags, ie:This rule has these metadata:
As stated in SNORT rule manual and in Suricata sources,
metadata
are ignored by IDS/IPS engine. Also examples states that a writer can use more than onemetadata
tag.The right behaviour would be to append any new
metadata
list to the existing one.The text was updated successfully, but these errors were encountered: