[Oisf-users] Suricata 1.4 http keywords in rule options, how does matching occur for http_header?

Anoop Saldanha anoopsaldanha at gmail.com
Thu Jan 24 08:11:16 UTC 2013


On Thu, Jan 24, 2013 at 1:37 PM, Peter Manev <petermanev at gmail.com> wrote:
>
>> However, any of the techniques mentioned above isn't a foolproof way
>> to match on the host header.  The right way would be to provide a new
>> keyword called "http_host".
>>
> Anoop or Vincent would you please put in feature request for that?
>

We should probably consult users/rule-writers if such a keyword would
be useful to them?

-- 
Anoop Saldanha



More information about the Oisf-users mailing list