corelight / corelight/community-id-spec
Include additional flow properties in ID
- Dominant language
- Python
- Stars
- 197
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
The Community ID could include features beyond the flow tuple, such as the presence of particular file transfers in the flow. This could aid in disambiguation of flows with otherwise colliding IDs, but narrows applicability to monitors that are able to track at this level of inspection.
This is a feature suggestion from SuriCon 2018.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named. Start by reviewing the Community ID specification and its flow tuple, then determine how file-transfer presence would be represented and which monitors could support it. Done would require an agreed, documented extension with clarified applicability and disambiguation behavior.
Written by the indexing model from the issue text.
Assessment
- Domain
- networking, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100