corelight / corelight/community-id-spec

Include additional flow properties in ID

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
197
Forks
26
PR merge metrics
No merged PRs in 30d

Description

The Community ID could include features beyond the flow tuple, such as the presence of particular file transfers in the flow. This could aid in disambiguation of flows with otherwise colliding IDs, but narrows applicability to monitors that are able to track at this level of inspection.

This is a feature suggestion from SuriCon 2018.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by reviewing the Community ID specification and its flow tuple, then determine how file-transfer presence would be represented and which monitors could support it. Done would require an agreed, documented extension with clarified applicability and disambiguation behavior.

Written by the indexing model from the issue text.

Assessment

Domain
networking, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.