suricata
app-layer-register.h
Go to the documentation of this file.
1 /* Copyright (C) 2017 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Pierre Chifflier <chifflier@wzdftpd.net>
22  */
23 
24 #ifndef __APP_LAYER_REGISTER_H__
25 #define __APP_LAYER_REGISTER_H__
26 
27 typedef struct AppLayerParser {
28  const char *name;
29  const char *default_port;
30  int ip_proto;
31 
34 
35  uint16_t min_depth;
36  uint16_t max_depth;
37 
38  void *(*StateAlloc)(void);
39  void (*StateFree)(void *);
40 
43 
44  uint64_t (*StateGetTxCnt)(void *alstate);
45  void *(*StateGetTx)(void *alstate, uint64_t tx_id);
46  void (*StateTransactionFree)(void *, uint64_t);
47 
48  int (*StateGetProgressCompletionStatus)(uint8_t direction);
49  int (*StateGetProgress)(void *alstate, uint8_t direction);
50 
51  uint32_t (*StateGetTxLogged)(void *alstate, void *tx);
52  void (*StateSetTxLogged)(void *alstate, void *tx, uint32_t logger);
53 
54  DetectEngineState *(*GetTxDetectState)(void *tx);
55  int (*SetTxDetectState)(void *tx, DetectEngineState *);
56 
57  AppLayerDecoderEvents *(*StateGetEvents)(void *);
58  int (*StateGetEventInfo)(const char *event_name,
59  int *event_id, AppLayerEventType *event_type);
60  int (*StateGetEventInfoById)(int event_id, const char **event_name,
61  AppLayerEventType *event_type);
62 
63  void *(*LocalStorageAlloc)(void);
64  void (*LocalStorageFree)(void *);
65 
66  uint64_t (*GetTxMpmIDs)(void *tx);
67  int (*SetTxMpmIDs)(void *tx, uint64_t);
68 
69  FileContainer *(*StateGetFiles)(void *, uint8_t);
70 
71  AppLayerGetTxIterTuple (*GetTxIterator)(const uint8_t ipproto,
72  const AppProto alproto, void *alstate, uint64_t min_tx_id,
73  uint64_t max_tx_id, AppLayerGetTxIterState *istate);
74 
75  void (*SetTxDetectFlags)(void *, uint8_t, uint64_t);
76  uint64_t (*GetTxDetectFlags)(void *, uint8_t);
78 
79 /**
80  * \brief App layer protocol detection function.
81  *
82  * \param parser The parser declaration structure.
83  * \param enable_default A boolean to indicate if default port configuration should be used if none given
84  *
85  * \retval The AppProto constant if successful. On error, this function never returns.
86  */
87 AppProto AppLayerRegisterProtocolDetection(const struct AppLayerParser *parser, int enable_default);
88 
89 /**
90  * \brief App layer protocol registration function.
91  *
92  * \param parser The parser declaration structure.
93  * \param alproto The application layer protocol identifier.
94  *
95  * \retval 0 if successful. On error, this function never returns.
96  */
97 int AppLayerRegisterParser(const struct AppLayerParser *p, AppProto alproto);
98 
99 #endif /* __APP_LAYER_REGISTER_H__ */
AppLayerParser::StateGetEventInfo
int(* StateGetEventInfo)(const char *event_name, int *event_id, AppLayerEventType *event_type)
Definition: app-layer-register.h:58
AppLayerParser::StateSetTxLogged
void(* StateSetTxLogged)(void *alstate, void *tx, uint32_t logger)
Definition: app-layer-register.h:52
FileContainer_
Definition: util-file.h:100
AppLayerParser::SetTxMpmIDs
int(* SetTxMpmIDs)(void *tx, uint64_t)
Definition: app-layer-register.h:67
DetectEngineState_
Definition: detect-engine-state.h:92
AppLayerParser::default_port
const char * default_port
Definition: app-layer-register.h:29
AppLayerParser::max_depth
uint16_t max_depth
Definition: app-layer-register.h:36
AppLayerParser
struct AppLayerParser AppLayerParser
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:71
AppLayerParserFPtr
AppLayerResult(* AppLayerParserFPtr)(Flow *f, void *protocol_state, AppLayerParserState *pstate, const uint8_t *buf, uint32_t buf_len, void *local_storage, const uint8_t flags)
Prototype for parsing functions.
Definition: app-layer-parser.h:109
AppLayerEventType
enum AppLayerEventType_ AppLayerEventType
AppLayerParser::ProbeTS
ProbingParserFPtr ProbeTS
Definition: app-layer-register.h:32
AppLayerParser::ParseTS
AppLayerParserFPtr ParseTS
Definition: app-layer-register.h:41
AppLayerDecoderEvents_
Data structure to store app layer decoder events.
Definition: app-layer-events.h:34
AppLayerParser::StateFree
void(* StateFree)(void *)
Definition: app-layer-register.h:39
AppLayerParser::StateGetProgress
int(* StateGetProgress)(void *alstate, uint8_t direction)
Definition: app-layer-register.h:49
AppLayerParser
Definition: app-layer-register.h:27
AppLayerParser::StateGetProgressCompletionStatus
int(* StateGetProgressCompletionStatus)(uint8_t direction)
Definition: app-layer-register.h:48
AppLayerParser::StateTransactionFree
void(* StateTransactionFree)(void *, uint64_t)
Definition: app-layer-register.h:46
AppLayerParser::min_depth
uint16_t min_depth
Definition: app-layer-register.h:35
AppLayerParser::ip_proto
int ip_proto
Definition: app-layer-register.h:30
AppLayerParser::ProbeTC
ProbingParserFPtr ProbeTC
Definition: app-layer-register.h:33
AppLayerParser::GetTxMpmIDs
uint64_t(* GetTxMpmIDs)(void *tx)
Definition: app-layer-register.h:66
AppLayerParser::GetTxDetectFlags
uint64_t(* GetTxDetectFlags)(void *, uint8_t)
Definition: app-layer-register.h:76
AppLayerParser::LocalStorageFree
void(* LocalStorageFree)(void *)
Definition: app-layer-register.h:64
AppLayerGetTxIterState
Definition: app-layer-parser.h:114
AppLayerParser::StateGetEventInfoById
int(* StateGetEventInfoById)(int event_id, const char **event_name, AppLayerEventType *event_type)
Definition: app-layer-register.h:60
ProbingParserFPtr
AppProto(* ProbingParserFPtr)(Flow *f, uint8_t dir, const uint8_t *input, uint32_t input_len, uint8_t *rdir)
Definition: app-layer-detect-proto.h:30
AppLayerRegisterParser
int AppLayerRegisterParser(const struct AppLayerParser *p, AppProto alproto)
App layer protocol registration function.
Definition: app-layer-register.c:93
AppLayerRegisterProtocolDetection
AppProto AppLayerRegisterProtocolDetection(const struct AppLayerParser *parser, int enable_default)
App layer protocol detection function.
Definition: app-layer-register.c:37
AppLayerParser::name
const char * name
Definition: app-layer-register.h:28
AppLayerParser::ParseTC
AppLayerParserFPtr ParseTC
Definition: app-layer-register.h:42
AppLayerParser::StateGetTxCnt
uint64_t(* StateGetTxCnt)(void *alstate)
Definition: app-layer-register.h:44
AppLayerParser::SetTxDetectState
int(* SetTxDetectState)(void *tx, DetectEngineState *)
Definition: app-layer-register.h:55
AppLayerParser::StateGetTxLogged
uint32_t(* StateGetTxLogged)(void *alstate, void *tx)
Definition: app-layer-register.h:51
AppLayerParser::GetTxIterator
AppLayerGetTxIterTuple(* GetTxIterator)(const uint8_t ipproto, const AppProto alproto, void *alstate, uint64_t min_tx_id, uint64_t max_tx_id, AppLayerGetTxIterState *istate)
Definition: app-layer-register.h:71
AppLayerParser::SetTxDetectFlags
void(* SetTxDetectFlags)(void *, uint8_t, uint64_t)
Definition: app-layer-register.h:75