Go to the documentation of this file.
60 uint8_t
flags,
void *alstate,
void *tx, uint64_t tx_id);
61 static int g_applayer_state_list_id = 0;
67 "match on events generated by the App Layer Parsers and the protocol detection engine";
73 DetectEngineAptStateInspect, NULL);
75 DetectEngineAptStateInspect, NULL);
82 uint8_t
flags,
void *alstate,
void *tx, uint64_t tx_id)
86 const uint8_t tx_progress =
95 if (data->
mode == -1) {
96 SCLogDebug(
"sid:%u tx_progress %u < keyword progress %u ?", s->
id, tx_progress,
98 if (tx_progress < data->progress) {
101 }
else if (data->
mode == 1) {
102 SCLogDebug(
"sid:%u tx_progress %u > keyword progress %u ?", s->
id, tx_progress,
127 SCLogDebug(
"DETECT_ENGINE_INSPECT_SIG_MATCH");
132 SCLogDebug(
"DETECT_ENGINE_INSPECT_SIG_CANT_MATCH");
135 SCLogDebug(
"DETECT_ENGINE_INSPECT_SIG_NO_MATCH");
146 .t.app.alproto = alproto,
147 .t.app.app_progress = progress,
160 if (strlen(arg) > 0) {
164 }
else if (arg[0] ==
'>') {
174 IPPROTO_TCP , s->
alproto, h, STREAM_TOSERVER);
175 if (progress_ts >= 0) {
180 IPPROTO_TCP , s->
alproto, h, STREAM_TOCLIENT);
181 if (progress_tc < 0) {
192 uint8_t dir_flag = STREAM_TOSERVER;
194 const int progress_ts =
196 if (progress_ts >= 0) {
198 progress = progress_ts;
201 IPPROTO_TCP , s->
alproto, h, STREAM_TOCLIENT);
202 if (progress_tc < 0) {
206 progress = progress_tc;
207 dir_flag = STREAM_TOCLIENT;
210 const uint8_t direction = dir_flag;
214 if (mode > 0 && progress >= end_state) {
215 SCLogError(
"app-layer-state: state '%s' is not below the completion state for mode '>'", h);
219 if (mode < 0 && progress == 0) {
220 SCLogError(
"app-layer-state: state '%s' is the starting state, it can never match for "
230 data->
mode = (int8_t)mode;
233 g_applayer_state_list_id) == NULL) {
SigTableElmt * sigmatch_table
void(* Free)(DetectEngineCtx *, void *)
struct SignatureHook_::@87::@88 app
uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction)
union SignatureHook_::@87 t
main detection engine ctx
int AppLayerParserGetStateIdByName(uint8_t ipproto, AppProto alproto, const char *name, const uint8_t direction)
#define SIG_FLAG_TOCLIENT
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
#define KEYWORD_PROFILING_START
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
#define SIG_FLAG_APPLAYER
int DetectBufferTypeGetByName(const char *name)
#define KEYWORD_PROFILING_END(ctx, type, m)
@ SIGNATURE_HOOK_TYPE_APP
#define SIG_FLAG_TOSERVER
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
#define DETECT_ENGINE_INSPECT_SIG_MATCH
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
SignatureInitData * init_data
Data structures and function prototypes for keeping state for the detection engine.
#define DETECT_ENGINE_INSPECT_SIG_CANT_MATCH
struct DetectAppLayerStateData_ DetectAppLayerStateData
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
void DetectAppLayerStateRegister(void)
enum SignatureHookType type
#define DETECT_ENGINE_INSPECT_SIG_NO_MATCH
#define SCLogError(...)
Macro used to log ERROR messages.
uint8_t AppLayerParserGetTxEndState(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the end state (progress) for a transaction.
AppProto alproto
application level protocol