StamusNetworks / SELKS

A Suricata based IDS/IPS/NSM distro
https://www.stamus-networks.com/open-source/#selks
GNU General Public License v3.0
1.48k stars 285 forks source link

Non IP Variables #62

Closed SigPloiter closed 7 years ago

SigPloiter commented 7 years ago

am working on a project to setup an IDS for telcom Signalling traffic, and i was wondering if the engine would perfectly detect those packets if i added them in app-layer protocol directive, or is there any tuning i need to do .

The protocols inscop: GTP, Diameter, SS7(MAP,CAMEL)

thanks

pevma commented 7 years ago

Currently not the protocols you mention above. You can however amend the code for those. Please note it should be in line with GPLv2.