Skip to content

Commit

Permalink
tests: add stream_size prefilter tests
Browse files Browse the repository at this point in the history
  • Loading branch information
victorjulien committed Jun 18, 2024
1 parent 4309798 commit ea37490
Show file tree
Hide file tree
Showing 6 changed files with 39 additions and 0 deletions.
3 changes: 3 additions & 0 deletions tests/streamsize-keyword-02-prefilter/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Description

Test stream_size keyword as prefilter.
1 change: 1 addition & 0 deletions tests/streamsize-keyword-02-prefilter/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
alert tcp any any -> any any (flow:established,to_server; stream_size:server,<,1111; prefilter; content: "EICAR"; sid:1234;)
15 changes: 15 additions & 0 deletions tests/streamsize-keyword-02-prefilter/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
pcap: ../smb-eicar-file/input.pcap

requires:
min-version: 7

# disables checksum verification
args:
- -k none

checks:
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 1234
4 changes: 4 additions & 0 deletions tests/streamsize-keyword-03-prefilter-pseudo/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Description

Test stream_size keyword as prefilter on timeout packet

2 changes: 2 additions & 0 deletions tests/streamsize-keyword-03-prefilter-pseudo/test.rules
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
alert tls any any -> any any (msg:"SERVER HELLO DATA - to_client"; flow:established,to_client; tls.random; content:"|54 b8 f7 73|"; bsize:>1; stream_size:server,>,1111; prefilter; sid:1234;)

14 changes: 14 additions & 0 deletions tests/streamsize-keyword-03-prefilter-pseudo/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
pcap: ../tls/tls-random-6989/input.pcap

requires:
min-version: 8

args:
- -k none

checks:
- filter:
count: 1
match:
event_type: alert
alert.signature_id: 1234

0 comments on commit ea37490

Please sign in to comment.