[Bro-Dev] [JIRA] (BIT-815) IPv6 atomic fragment optimizations

Jon Siwek (JIRA) jira at bro-tracker.atlassian.net
Tue Mar 17 07:57:00 PDT 2015

     [ https://bro-tracker.atlassian.net/browse/BIT-815?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Jon Siwek updated BIT-815:
    Fix Version/s:     (was: 2.4)

> IPv6 atomic fragment optimizations
> ----------------------------------
>                 Key: BIT-815
>                 URL: https://bro-tracker.atlassian.net/browse/BIT-815
>             Project: Bro Issue Tracker
>          Issue Type: Problem
>          Components: Bro
>    Affects Versions: git/master
>            Reporter: Jon Siwek
>              Labels: ipv6
>             Fix For: 2.5
>         Attachments: ipv6-nested-atomic-frags.pcap
> The draft at http://tools.ietf.org/html/draft-ietf-6man-ipv6-atomic-fragments-00 should be revisited if it gets published.  According to section 3, atomic fragment headers can just be ignored and "reassembly" skipped.  That also should improve the case where a packet has multiple atomic fragment headers (see attached pcap), because currently Bro doesn't recursively reassemble the inner atomic fragments, it just stops processing the packet and gives the "unknown_protocol_44" weird to indicate there was packet with multiple fragment headers.

This message was sent by Atlassian JIRA

More information about the bro-dev mailing list