suricata
decode-template.c
Go to the documentation of this file.
1 /* Copyright (C) 2015-2018 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \ingroup decode
20  *
21  * @{
22  */
23 
24 
25 /**
26  * \file
27  *
28  * \author XXX Your Name <your@email.com>
29  *
30  * Decodes XXX describe the protocol
31  */
32 
33 #include "suricata-common.h"
34 #include "suricata.h"
35 #include "decode.h"
36 #include "decode-events.h"
37 #include "decode-template.h"
38 
39 /**
40  * \brief Function to decode TEMPLATE packets
41  * \param tv thread vars
42  * \param dtv decoder thread vars
43  * \param p packet
44  * \param pkt raw packet data
45  * \param len length in bytes of pkt array
46  * \retval TM_ECODE_OK or TM_ECODE_FAILED on serious error
47  */
48 
50  const uint8_t *pkt, uint32_t len)
51 {
52  /* TODO add counter for your type of packet to DecodeThreadVars,
53  * and register it in DecodeRegisterPerfCounters */
54  //StatsIncr(tv, dtv->counter_template);
55 
56  /* Validation: make sure that the input data is big enough to hold
57  * the header */
58  if (len < sizeof(TemplateHdr)) {
59  /* in case of errors, we set events. Events are defined in
60  * decode-events.h, and are then exposed to the detection
61  * engine through detect-engine-events.h */
62  //ENGINE_SET_EVENT(p,TEMPLATE_HEADER_TOO_SMALL);
63  return TM_ECODE_FAILED;
64  }
65  /* Each packet keeps a count of decoded layers
66  * This function increases it and returns false
67  * if we have too many decoded layers, such as
68  * ethernet/MPLS/ethernet/MPLS... which may
69  * lead to stack overflow by a too deep recursion
70  */
71  if (!PacketIncreaseCheckLayers(p)) {
72  return TM_ECODE_FAILED;
73  }
74 
75  /* Now we can access the header */
76  const TemplateHdr *hdr = (const TemplateHdr *)pkt;
77 
78  /* lets assume we have UDP encapsulated */
79  if (hdr->proto == 17) {
80  /* we need to pass on the pkt and it's length minus the current
81  * header */
82  size_t hdr_len = sizeof(TemplateHdr);
83 
84  /* in this example it's clear that hdr_len can't be bigger than
85  * 'len', but in more complex cases checking that we can't underflow
86  * len is very important
87  if (hdr_len >= len) {
88  ENGINE_SET_EVENT(p,TEMPLATE_MALFORMED_HDRLEN);
89  return TM_ECODE_FAILED;
90  }
91  */
92 
93  /* invoke the next decoder on the remainder of the data */
94  return DecodeUDP(tv, dtv, p, (uint8_t *)pkt + hdr_len, len - hdr_len);
95  } else {
96  //ENGINE_SET_EVENT(p,TEMPLATE_UNSUPPORTED_PROTOCOL);
97  return TM_ECODE_FAILED;
98  }
99 
100  return TM_ECODE_OK;
101 }
102 
103 /**
104  * @}
105  */
len
uint8_t len
Definition: app-layer-dnp3.h:2
DecodeUDP
int DecodeUDP(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint16_t len)
Definition: decode-udp.c:75
TM_ECODE_FAILED
@ TM_ECODE_FAILED
Definition: tm-threads-common.h:81
TM_ECODE_OK
@ TM_ECODE_OK
Definition: tm-threads-common.h:80
decode.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:58
DecodeTEMPLATE
int DecodeTEMPLATE(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Function to decode TEMPLATE packets.
Definition: decode-template.c:49
Packet_
Definition: decode.h:415
decode-events.h
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:30
suricata-common.h
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:29
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:639
suricata.h
decode-template.h