You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/rules
DIALLO David 5a0409959f App-layer: Add Modbus protocol parser
Decode Modbus request and response messages, and extracts
MODBUS Application Protocol header and the code function.

In case of read/write function, extracts message contents
(read/write address, quantity, count, data to write).

Links request and response messages in a transaction according to
Transaction Identifier (transaction management based on DNS source code).

MODBUS Messaging on TCP/IP Implementation Guide V1.0b
(http://www.modbus.org/docs/Modbus_Messaging_Implementation_Guide_V1_0b.pdf)
MODBUS Application Protocol Specification V1.1b3
(http://www.modbus.org/docs/Modbus_Application_Protocol_V1_1b3.pdf)

Based on DNS source code.

Signed-off-by: David DIALLO <diallo@et.esia.fr>
10 years ago
..
Makefile.am App-layer: Add Modbus protocol parser 10 years ago
decoder-events.rules Fix MPLS decoder rules. 11 years ago
dns-events.rules
files.rules SMTP MIME Email Message decoder 10 years ago
http-events.rules
modbus-events.rules App-layer: Add Modbus protocol parser 10 years ago
smtp-events.rules SMTP MIME Email Message decoder 10 years ago
stream-events.rules stream: detect and filter out bad window updates 11 years ago
tls-events.rules