suricata
detect-byte-extract.h File Reference
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Data Structures

struct  DetectByteExtractData_
 Holds data related to byte_extract keyword. More...
 

Macros

#define DETECT_BYTE_EXTRACT_FLAG_RELATIVE   0x01
 
#define DETECT_BYTE_EXTRACT_FLAG_MULTIPLIER   0x02
 
#define DETECT_BYTE_EXTRACT_FLAG_STRING   0x04
 
#define DETECT_BYTE_EXTRACT_FLAG_ALIGN   0x08
 
#define DETECT_BYTE_EXTRACT_FLAG_ENDIAN   0x10
 
#define DETECT_BYTE_EXTRACT_ENDIAN_NONE   0
 
#define DETECT_BYTE_EXTRACT_ENDIAN_BIG   1
 
#define DETECT_BYTE_EXTRACT_ENDIAN_LITTLE   2
 
#define DETECT_BYTE_EXTRACT_ENDIAN_DCE   3
 

Typedefs

typedef struct DetectByteExtractData_ DetectByteExtractData
 Holds data related to byte_extract keyword. More...
 

Functions

void DetectByteExtractRegister (void)
 Registers the keyword handlers for the "byte_extract" keyword. More...
 
SigMatchDetectByteExtractRetrieveSMVar (const char *, const Signature *)
 Lookup the SigMatch for a named byte_extract variable. More...
 
int DetectByteExtractDoMatch (DetectEngineThreadCtx *, const SigMatchData *, const Signature *, const uint8_t *, uint16_t, uint64_t *, uint8_t)
 

Detailed Description

Macro Definition Documentation

◆ DETECT_BYTE_EXTRACT_ENDIAN_BIG

#define DETECT_BYTE_EXTRACT_ENDIAN_BIG   1

Definition at line 36 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_ENDIAN_DCE

#define DETECT_BYTE_EXTRACT_ENDIAN_DCE   3

Definition at line 38 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_ENDIAN_LITTLE

#define DETECT_BYTE_EXTRACT_ENDIAN_LITTLE   2

Definition at line 37 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_ENDIAN_NONE

#define DETECT_BYTE_EXTRACT_ENDIAN_NONE   0

Definition at line 35 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_FLAG_ALIGN

#define DETECT_BYTE_EXTRACT_FLAG_ALIGN   0x08

Definition at line 31 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_FLAG_ENDIAN

#define DETECT_BYTE_EXTRACT_FLAG_ENDIAN   0x10

Definition at line 32 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_FLAG_MULTIPLIER

#define DETECT_BYTE_EXTRACT_FLAG_MULTIPLIER   0x02

Definition at line 29 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_FLAG_RELATIVE

#define DETECT_BYTE_EXTRACT_FLAG_RELATIVE   0x01

Definition at line 28 of file detect-byte-extract.h.

◆ DETECT_BYTE_EXTRACT_FLAG_STRING

#define DETECT_BYTE_EXTRACT_FLAG_STRING   0x04

Definition at line 30 of file detect-byte-extract.h.

Typedef Documentation

◆ DetectByteExtractData

Holds data related to byte_extract keyword.

Function Documentation

◆ DetectByteExtractDoMatch()

◆ DetectByteExtractRegister()

void DetectByteExtractRegister ( void  )

Registers the keyword handlers for the "byte_extract" keyword.

Definition at line 99 of file detect-byte-extract.c.

References SigTableElmt_::desc, DETECT_BYTE_EXTRACT, DOC_URL, DOC_VERSION, SigTableElmt_::Match, SigTableElmt_::name, SigTableElmt_::Setup, sigmatch_table, and SigTableElmt_::url.

Referenced by SigTableSetup().

Here is the caller graph for this function:

◆ DetectByteExtractRetrieveSMVar()

SigMatch* DetectByteExtractRetrieveSMVar ( const char *  arg,
const Signature s 
)

Lookup the SigMatch for a named byte_extract variable.

Parameters
argThe name of the byte_extract variable to lookup.
sPointer the signature to look in.
Return values
Apointer to the SigMatch if found, otherwise NULL.

Definition at line 645 of file detect-byte-extract.c.

References Signature_::init_data, and SignatureInitData_::smlists_array_size.