From: Philippe Antoine Date: Wed, 1 Jun 2022 12:26:55 +0000 (+0200) Subject: Adds test about stream_size keyword X-Git-Tag: suricata-5.0.10~19 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e3b28dd1ee238bcbdda95facd825df4cb061f69f;p=thirdparty%2Fsuricata-verify.git Adds test about stream_size keyword --- diff --git a/tests/streamsize-keyword/README.md b/tests/streamsize-keyword/README.md new file mode 100644 index 000000000..a742cd7a4 --- /dev/null +++ b/tests/streamsize-keyword/README.md @@ -0,0 +1,7 @@ +# Description + +Test stream_size keyword + +# PCAP + +The pcap is the same as smb-eicar-file test with the eicar file in it diff --git a/tests/streamsize-keyword/input.pcap b/tests/streamsize-keyword/input.pcap new file mode 100644 index 000000000..e97b433c4 Binary files /dev/null and b/tests/streamsize-keyword/input.pcap differ diff --git a/tests/streamsize-keyword/test.rules b/tests/streamsize-keyword/test.rules new file mode 100644 index 000000000..bfaa44186 --- /dev/null +++ b/tests/streamsize-keyword/test.rules @@ -0,0 +1 @@ +alert tcp any any -> any any (flow:established,to_server; stream_size:server,<,1111; content: "EICAR"; sid:1234;) diff --git a/tests/streamsize-keyword/test.yaml b/tests/streamsize-keyword/test.yaml new file mode 100644 index 000000000..19401dd88 --- /dev/null +++ b/tests/streamsize-keyword/test.yaml @@ -0,0 +1,10 @@ +# disables checksum verification +args: +- -k none + +checks: + - filter: + count: 1 + match: + event_type: alert + alert.signature_id: 1234