Skip to content

modbus-keywords: test modbus per-value keywords - #3260

Open
akekulip wants to merge 2 commits into
OISF:masterfrom
akekulip:modbus-keywords-8131-v1
Open

akekulip wants to merge 2 commits into
OISF:masterfrom
akekulip:modbus-keywords-8131-v1

Conversation

@akekulip

Copy link
Copy Markdown

Tests for the modbus per-value detection keywords added in OISF/suricata#15960.

  • modbus-keywords: reuses the modbus test pcap; covers the new keywords with negation, range and direction-pinned cases
  • modbus-keywords-write: synthetic pcap (generator included) with multiple-write, mask-write and single-write transactions; checks that modbus.write.quantity matches the quantity echoed in multiple-write responses and that modbus.write.value does not

Ticket: https://redmine.openinfosecfoundation.org/issues/8131

Cover modbus.unit_id, modbus.transaction_id, modbus.protocol_id,
modbus.function, modbus.subfunction, modbus.exception_code,
modbus.read.address, modbus.read.quantity, modbus.write.address,
modbus.write.quantity and modbus.write.value, with negation, range
and direction-pinned cases.

modbus-keywords reuses the modbus test pcap. modbus-keywords-write
uses a synthetic pcap (generator included) with multiple-write,
mask-write and single-write transactions, checking that
modbus.write.quantity matches the quantity echoed in multiple-write
responses and that modbus.write.value does not.

Ticket: #8131.
Cover the code names accepted by modbus.function, modbus.subfunction
and modbus.exception_code alongside the numeric values they stand for.

Every name is paired with the numeric rule it should behave like, so
each pair is expected to alert the same number of times. The pairs
also cover lower and upper case spellings and a negated name.

Reuses the modbus test pcap.

Ticket: #8131.
@akekulip
akekulip force-pushed the modbus-keywords-8131-v1 branch from e776f48 to a02929a Compare September 21, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

requires suricata pr Depends on a PR in Suricata

Development

Successfully merging this pull request may close these issues.

2 participants