suricata
detect-app-layer-state.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2025 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <vjulien@oisf.net>
22  */
23 
24 #include "suricata-common.h"
25 #include "threads.h"
26 #include "decode.h"
27 
28 #include "app-layer.h"
29 #include "app-layer-protos.h"
30 #include "app-layer-parser.h"
31 #include "app-layer-smtp.h"
32 #include "detect.h"
33 #include "detect-parse.h"
34 #include "detect-engine.h"
35 #include "detect-engine-state.h"
36 #include "detect-engine-build.h"
37 #include "detect-app-layer-state.h"
38 
39 #include "flow.h"
40 #include "flow-var.h"
41 #include "flow-util.h"
42 
43 #include "decode-events.h"
44 #include "util-byte.h"
45 #include "util-debug.h"
46 #include "util-enum.h"
47 #include "util-profiling.h"
48 #include "util-unittest-helper.h"
49 #include "stream-tcp-util.h"
50 
51 typedef struct DetectAppLayerStateData_ {
52  uint8_t progress;
53  int8_t mode;
55 
56 static int DetectAppLayerStateSetup(DetectEngineCtx *, Signature *, const char *);
57 static void DetectAppLayerStateFree(DetectEngineCtx *, void *);
58 static uint8_t DetectEngineAptStateInspect(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx,
59  const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f,
60  uint8_t flags, void *alstate, void *tx, uint64_t tx_id);
61 static int g_applayer_state_list_id = 0;
62 
64 {
65  sigmatch_table[DETECT_APP_LAYER_STATE].name = "app-layer-state";
67  "match on events generated by the App Layer Parsers and the protocol detection engine";
68  sigmatch_table[DETECT_APP_LAYER_STATE].url = "/rules/app-layer.html#app-layer-event";
69  sigmatch_table[DETECT_APP_LAYER_STATE].Setup = DetectAppLayerStateSetup;
70  sigmatch_table[DETECT_APP_LAYER_STATE].Free = DetectAppLayerStateFree;
71 
73  DetectEngineAptStateInspect, NULL);
75  DetectEngineAptStateInspect, NULL);
76 
77  g_applayer_state_list_id = DetectBufferTypeGetByName("app-layer-state");
78 }
79 
80 static uint8_t DetectEngineAptStateInspect(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx,
81  const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f,
82  uint8_t flags, void *alstate, void *tx, uint64_t tx_id)
83 {
84  int r = 0;
85  const AppProto alproto = f->alproto;
86  const uint8_t tx_progress =
87  (uint8_t)AppLayerParserGetStateProgress(f->proto, alproto, tx, flags);
88 
89  const SigMatchData *smd = engine->smd;
90  while (1) {
91  const DetectAppLayerStateData *data = (const DetectAppLayerStateData *)smd->ctx;
93 
94  bool match = false;
95  if (data->mode == -1) {
96  SCLogDebug("sid:%u tx_progress %u < keyword progress %u ?", s->id, tx_progress,
97  data->progress);
98  if (tx_progress < data->progress) {
99  match = true;
100  }
101  } else if (data->mode == 1) {
102  SCLogDebug("sid:%u tx_progress %u > keyword progress %u ?", s->id, tx_progress,
103  data->progress);
104  if (tx_progress > data->progress) {
105  match = true;
106  }
107  } else {
108  BUG_ON(1);
109  }
110 
111  if (match) {
112  KEYWORD_PROFILING_END(det_ctx, smd->type, 1);
113 
114  if (smd->is_last)
115  break;
116  smd++;
117  continue;
118  }
119 
120  KEYWORD_PROFILING_END(det_ctx, smd->type, 0);
121  goto end;
122  }
123  r = 1;
124 
125 end:
126  if (r == 1) {
127  SCLogDebug("DETECT_ENGINE_INSPECT_SIG_MATCH");
129  } else {
130  const uint8_t tx_end_state = AppLayerParserGetTxEndState(f->proto, alproto, tx, flags);
131  if (AppLayerParserGetStateProgress(f->proto, alproto, tx, flags) == tx_end_state) {
132  SCLogDebug("DETECT_ENGINE_INSPECT_SIG_CANT_MATCH");
134  } else {
135  SCLogDebug("DETECT_ENGINE_INSPECT_SIG_NO_MATCH");
137  }
138  }
139 }
140 
141 // TODO dedup with detect-parse.c
142 static SignatureHook SetAppHook(const AppProto alproto, uint8_t progress)
143 {
144  SignatureHook h = {
146  .t.app.alproto = alproto,
147  .t.app.app_progress = progress,
148  };
149  return h;
150 }
151 
152 static int DetectAppLayerStateSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg)
153 {
154  if (s->alproto == ALPROTO_UNKNOWN) {
155  return -1;
156  }
157 
158  int mode = 0;
159 
160  if (strlen(arg) > 0) {
161  if (arg[0] == '<') {
162  mode = -1;
163  arg++;
164  } else if (arg[0] == '>') {
165  mode = 1;
166  arg++;
167  }
168  }
169 
170  if (mode == 0) {
171  const char *h = arg;
172 
173  const int progress_ts = AppLayerParserGetStateIdByName(
174  IPPROTO_TCP /* TODO */, s->alproto, h, STREAM_TOSERVER);
175  if (progress_ts >= 0) {
176  s->flags |= SIG_FLAG_TOSERVER;
177  s->init_data->hook = SetAppHook(s->alproto, (uint8_t)progress_ts);
178  } else {
179  const int progress_tc = AppLayerParserGetStateIdByName(
180  IPPROTO_TCP /* TODO */, s->alproto, h, STREAM_TOCLIENT);
181  if (progress_tc < 0) {
182  return -1;
183  }
184  s->flags |= SIG_FLAG_TOCLIENT;
185  s->init_data->hook = SetAppHook(s->alproto, (uint8_t)progress_tc);
186  }
187  SCLogDebug("hook %u", s->init_data->hook.t.app.app_progress);
188  return 0;
189  }
190 
191  int progress = 0;
192  uint8_t dir_flag = STREAM_TOSERVER;
193  const char *h = arg;
194  const int progress_ts =
195  AppLayerParserGetStateIdByName(IPPROTO_TCP /* TODO */, s->alproto, h, STREAM_TOSERVER);
196  if (progress_ts >= 0) {
197  s->flags |= SIG_FLAG_TOSERVER;
198  progress = progress_ts;
199  } else {
200  const int progress_tc = AppLayerParserGetStateIdByName(
201  IPPROTO_TCP /* TODO */, s->alproto, h, STREAM_TOCLIENT);
202  if (progress_tc < 0) {
203  return -1;
204  }
205  s->flags |= SIG_FLAG_TOCLIENT;
206  progress = progress_tc;
207  dir_flag = STREAM_TOCLIENT;
208  }
209 
210  const uint8_t direction = dir_flag;
211  const uint8_t end_state = AppLayerParserGetStateProgressCompletionStatus(s->alproto, direction);
212 
213  /* the tx progress can never exceed the completion state */
214  if (mode > 0 && progress >= end_state) {
215  SCLogError("app-layer-state: state '%s' is not below the completion state for mode '>'", h);
216  return -1;
217  }
218  /* the progress can never be below the starting state */
219  if (mode < 0 && progress == 0) {
220  SCLogError("app-layer-state: state '%s' is the starting state, it can never match for "
221  "mode '<'",
222  h);
223  return -1;
224  }
225  DetectAppLayerStateData *data = SCCalloc(1, sizeof(*data));
226  if (data == NULL)
227  return -1;
228 
229  data->progress = (uint8_t)progress;
230  data->mode = (int8_t)mode;
231 
233  g_applayer_state_list_id) == NULL) {
234  SCFree(data);
235  return -1;
236  }
237  s->flags |= SIG_FLAG_APPLAYER;
238 
239  return 0;
240 }
241 
242 static void DetectAppLayerStateFree(DetectEngineCtx *de_ctx, void *ptr)
243 {
244  SCFree(ptr);
245 }
util-byte.h
DetectEngineAppInspectionEngine_
Definition: detect.h:420
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-engine.h
SignatureHook_
Definition: detect.h:583
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
DETECT_APP_LAYER_STATE
@ DETECT_APP_LAYER_STATE
Definition: detect-engine-register.h:207
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
flow-util.h
SigTableElmt_::name
const char * name
Definition: detect.h:1542
Signature_::alproto
AppProto alproto
Definition: detect.h:697
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
SigMatchData_::is_last
bool is_last
Definition: detect.h:371
SignatureHook_::app
struct SignatureHook_::@87::@88 app
Flow_::proto
uint8_t proto
Definition: flow.h:381
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
SigMatchData_::ctx
SigMatchCtx * ctx
Definition: detect.h:372
AppLayerParserGetStateProgressCompletionStatus
uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:1226
SignatureHook_::t
union SignatureHook_::@87 t
threads.h
Flow_
Flow data structure.
Definition: flow.h:359
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
AppLayerParserGetStateIdByName
int AppLayerParserGetStateIdByName(uint8_t ipproto, AppProto alproto, const char *name, const uint8_t direction)
Definition: app-layer-parser.c:1832
SIG_FLAG_TOCLIENT
#define SIG_FLAG_TOCLIENT
Definition: detect.h:275
SigMatchData_
Data needed for Match()
Definition: detect.h:369
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
KEYWORD_PROFILING_START
#define KEYWORD_PROFILING_START
Definition: util-profiling.h:50
SigMatchData_::type
uint16_t type
Definition: detect.h:370
DetectAppLayerInspectEngineRegister
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
Definition: detect-engine.c:275
util-unittest-helper.h
SIG_FLAG_APPLAYER
#define SIG_FLAG_APPLAYER
Definition: detect.h:252
DetectBufferTypeGetByName
int DetectBufferTypeGetByName(const char *name)
Definition: detect-engine.c:1452
KEYWORD_PROFILING_END
#define KEYWORD_PROFILING_END(ctx, type, m)
Definition: util-profiling.h:64
SIGNATURE_HOOK_TYPE_APP
@ SIGNATURE_HOOK_TYPE_APP
Definition: detect.h:558
SIG_FLAG_TOSERVER
#define SIG_FLAG_TOSERVER
Definition: detect.h:274
decode.h
util-debug.h
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
DETECT_ENGINE_INSPECT_SIG_MATCH
#define DETECT_ENGINE_INSPECT_SIG_MATCH
Definition: detect-engine-state.h:41
DetectAppLayerStateData_::progress
uint8_t progress
Definition: detect-app-layer-state.c:52
app-layer-parser.h
SignatureInitData_::hook
SignatureHook hook
Definition: detect.h:604
AppLayerParserGetStateProgress
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
Definition: app-layer-parser.c:1199
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:322
util-profiling.h
Signature_::flags
uint32_t flags
Definition: detect.h:693
detect-engine-build.h
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:775
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
DETECT_ENGINE_INSPECT_SIG_CANT_MATCH
#define DETECT_ENGINE_INSPECT_SIG_CANT_MATCH
Definition: detect-engine-state.h:42
DetectAppLayerStateData
struct DetectAppLayerStateData_ DetectAppLayerStateData
decode-events.h
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
DetectEngineAppInspectionEngine_::smd
SigMatchData * smd
Definition: detect.h:444
DetectAppLayerStateRegister
void DetectAppLayerStateRegister(void)
Definition: detect-app-layer-state.c:63
flags
uint8_t flags
Definition: decode-gre.h:0
suricata-common.h
SignatureHook_::type
enum SignatureHookType type
Definition: detect.h:584
DETECT_ENGINE_INSPECT_SIG_NO_MATCH
#define DETECT_ENGINE_INSPECT_SIG_NO_MATCH
Definition: detect-engine-state.h:40
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
Signature_::id
uint32_t id
Definition: detect.h:741
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
stream-tcp-util.h
AppLayerParserGetTxEndState
uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the end state (progress) for a transaction.
Definition: app-layer-parser.c:1177
ALPROTO_UNKNOWN
@ ALPROTO_UNKNOWN
Definition: app-layer-protos.h:29
app-layer-protos.h
app-layer-smtp.h
detect-app-layer-state.h
flow.h
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:455
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
util-enum.h
flow-var.h
app-layer.h
DetectAppLayerStateData_::mode
int8_t mode
Definition: detect-app-layer-state.c:53
f
Flow f
Definition: fuzz_dataset.c:32
DetectAppLayerStateData_
Definition: detect-app-layer-state.c:51