StamusNetworks / SELKS

A Suricata based IDS/IPS/NSM distro
https://www.stamus-networks.com/open-source/#selks
GNU General Public License v3.0
1.48k stars 285 forks source link

SELKS/Suricata enhancements - proposals #177

Open michal25 opened 5 years ago

michal25 commented 5 years ago

My first proposals for suricata plugins enhancement - TLS/SSL. At this moment moloch shows only TLS version, negotiated cipher and some certificate data.

My first proposal is to show also the Diffie-Hellman server parameters, named curve, public key, signature algorithm, signature hash algorithm hash, signature hash algorithm signature and signature length.

Screenshot_20190301_122822 signal-Screenshot_20190327_211955 signal-Screenshot_20190327_212101

pevma commented 5 years ago

This sounds like a good feature candidate. Could you please post that feature request on - https://redmine.openinfosecfoundation.org/projects/suricata