suricata
detect-bytemath.c
Go to the documentation of this file.
1 /* Copyright (C) 2020-2026 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Jeff Lucovsky <jeff@lucovsky.org>
22  */
23 
24 /*
25  * Refer to the Snort manual, section 3.5.34 for details.
26  */
27 
28 #include "suricata-common.h"
29 #include "threads.h"
30 #include "decode.h"
31 
32 #include "rust.h"
33 #include "app-layer-parser.h"
34 #include "app-layer-protos.h"
35 
36 #include "detect.h"
37 #include "detect-parse.h"
38 #include "detect-engine.h"
39 #include "detect-engine-buffer.h"
40 #include "detect-engine-mpm.h"
41 #include "detect-engine-state.h"
42 #include "detect-engine-build.h"
43 
44 #include "detect-content.h"
45 #include "detect-pcre.h"
46 #include "detect-byte.h"
47 #include "detect-bytemath.h"
48 
49 #include "flow.h"
50 #include "flow-var.h"
51 #include "flow-util.h"
52 
53 #include "util-byte.h"
54 #include "util-debug.h"
55 #include "util-unittest-helper.h"
56 #include "util-spm.h"
57 
58 static int DetectByteMathSetup(DetectEngineCtx *, Signature *, const char *);
59 #ifdef UNITTESTS
60 #define DETECT_BYTEMATH_ENDIAN_DEFAULT (uint8_t) BigEndian
61 #define DETECT_BYTEMATH_BASE_DEFAULT (uint8_t) BaseDec
62 
63 static void DetectByteMathRegisterTests(void);
64 #endif
65 static void DetectByteMathFree(DetectEngineCtx *, void *);
66 
67 /**
68  * \brief Registers the keyword handlers for the "byte_math" keyword.
69  */
71 {
72  sigmatch_table[DETECT_BYTEMATH].name = "byte_math";
74  sigmatch_table[DETECT_BYTEMATH].Setup = DetectByteMathSetup;
75  sigmatch_table[DETECT_BYTEMATH].Free = DetectByteMathFree;
76  sigmatch_table[DETECT_BYTEMATH].desc = "used to perform mathematical operations on byte values";
77  sigmatch_table[DETECT_BYTEMATH].url = "/rules/payload-keywords.html#byte-math";
78 #ifdef UNITTESTS
79  sigmatch_table[DETECT_BYTEMATH].RegisterTests = DetectByteMathRegisterTests;
80 #endif
81 }
82 
83 static inline bool DetectByteMathValidateNbytesOnly(const DetectByteMathData *data, int32_t nbytes)
84 {
85  return nbytes >= 1 &&
86  (((data->flags & DETECT_BYTEMATH_FLAG_STRING) && nbytes <= 10) || (nbytes <= 4));
87 }
88 
89 int DetectByteMathDoMatch(DetectEngineThreadCtx *det_ctx, const DetectByteMathData *data,
90  const Signature *s, const uint8_t *payload, const uint32_t payload_len, uint8_t nbytes,
91  uint64_t rvalue, uint64_t *value, uint8_t endian)
92 {
93  if (payload_len == 0) {
94  return 0;
95  }
96 
97  if (!DetectByteMathValidateNbytesOnly(data, nbytes)) {
98  return 0;
99  }
100 
101  const uint8_t *ptr;
102  int32_t len;
103  uint64_t val;
104  int extbytes;
105 
106  /* Calculate the ptr value for the byte-math op and length remaining in
107  * the packet from that point.
108  */
109  if (data->flags & DETECT_BYTEMATH_FLAG_RELATIVE) {
110  SCLogDebug("relative, working with det_ctx->buffer_offset %" PRIu32 ", "
111  "data->offset %" PRIi32 "",
112  det_ctx->buffer_offset, data->offset);
113 
114  ptr = payload + det_ctx->buffer_offset;
115  len = payload_len - det_ctx->buffer_offset;
116 
117  ptr += data->offset;
118  len -= data->offset;
119 
120  /* No match if there is no relative base */
121  if (len <= 0) {
122  return 0;
123  }
124  } else {
125  SCLogDebug("absolute, data->offset %" PRIi32 "", data->offset);
126 
127  ptr = payload + data->offset;
128  len = payload_len - data->offset;
129  }
130 
131  /* Validate that the to-be-extracted is within the packet */
132  if (ptr < payload || nbytes > len) {
133  SCLogDebug("Data not within payload pkt=%p, ptr=%p, len=%" PRIu32 ", nbytes=%d", payload,
134  ptr, len, nbytes);
135  return 0;
136  }
137 
138  /* Extract the byte data */
139  if (data->flags & DETECT_BYTEMATH_FLAG_STRING) {
140  extbytes = ByteExtractStringUint64(&val, data->base, nbytes, (const char *)ptr);
141  if (extbytes <= 0) {
142  if (val == 0) {
143  SCLogDebug("No Numeric value");
144  return 0;
145  } else {
146  SCLogDebug("error extracting %d bytes of string data: %d", nbytes, extbytes);
147  return -1;
148  }
149  }
150  } else {
151  ByteEndian bme = endian;
152  int endianness = (bme == BigEndian) ? BYTE_BIG_ENDIAN : BYTE_LITTLE_ENDIAN;
153  extbytes = ByteExtractUint64(&val, endianness, nbytes, ptr);
154  if (extbytes != nbytes) {
155  SCLogDebug("error extracting %d bytes of numeric data: %d", nbytes, extbytes);
156  return 0;
157  }
158  }
159 
160  DEBUG_VALIDATE_BUG_ON(extbytes > len);
161 
162  ptr += extbytes;
163 
164  switch (data->oper) {
165  case OperatorNone:
166  break;
167  case Addition:
168  val += rvalue;
169  break;
170  case Subtraction:
171  val -= rvalue;
172  break;
173  case Division:
174  if (rvalue == 0) {
175  SCLogDebug("avoiding division by zero");
176  return 0;
177  }
178  val /= rvalue;
179  break;
180  case Multiplication:
181  val *= rvalue;
182  break;
183  case LeftShift:
184  if (rvalue < 64) {
185  val <<= rvalue;
186  } else {
187  val = 0;
188  }
189  break;
190  case RightShift:
191  if (rvalue < 64) {
192  val >>= rvalue;
193  } else {
194  val = 0;
195  }
196  break;
197  }
198 
199  det_ctx->buffer_offset = (uint32_t)(ptr - payload);
200 
201  if (data->flags & DETECT_BYTEMATH_FLAG_BITMASK) {
202  val &= data->bitmask_val;
203  if (val && data->bitmask_shift_count) {
204  val = val >> data->bitmask_shift_count;
205  }
206  }
207 
208  *value = val;
209  return 1;
210 }
211 
212 /**
213  * \internal
214  * \brief Used to parse byte_math arg.
215  *
216  * \param arg The argument to parse.
217  * \param rvalue May be NULL. When non-null, will contain the variable
218  * name of rvalue (iff rvalue is not a scalar value)
219  *
220  * \retval bmd On success an instance containing the parsed data.
221  * On failure, NULL.
222  */
223 static DetectByteMathData *DetectByteMathParse(
224  DetectEngineCtx *de_ctx, const char *arg, char **nbytes, char **rvalue)
225 {
226  DetectByteMathData *bmd;
227  if ((bmd = SCByteMathParse(arg)) == NULL) {
228  SCLogError("invalid bytemath values");
229  return NULL;
230  }
231 
232  if (bmd->nbytes_str) {
233  if (nbytes == NULL) {
234  SCLogError("byte_math supplied with "
235  "var name for nbytes. \"nbytes\" argument supplied to "
236  "this function must be non-NULL");
237  goto error;
238  }
239  *nbytes = SCStrdup(bmd->nbytes_str);
240  if (*nbytes == NULL) {
241  goto error;
242  }
243  }
244 
245  if (bmd->rvalue_str) {
246  if (rvalue == NULL) {
247  SCLogError("byte_math supplied with "
248  "var name for rvalue. \"rvalue\" argument supplied to "
249  "this function must be non-NULL");
250  goto error;
251  }
252  *rvalue = SCStrdup(bmd->rvalue_str);
253  if (*rvalue == NULL) {
254  goto error;
255  }
256  }
257 
258  if (bmd->flags & DETECT_BYTEMATH_FLAG_BITMASK) {
259  if (bmd->bitmask_val) {
260  uint32_t bmask = bmd->bitmask_val;
261  while (!(bmask & 0x1)){
262  bmask = bmask >> 1;
263  bmd->bitmask_shift_count++;
264  }
265  }
266  }
267 
268  return bmd;
269 
270  error:
271  if (bmd != NULL)
272  DetectByteMathFree(de_ctx, bmd);
273  return NULL;
274 }
275 
276 /**
277  * \brief The setup function for the byte_math keyword for a signature.
278  *
279  * \param de_ctx Pointer to the detection engine context.
280  * \param s Pointer to signature for the current Signature being parsed
281  * from the rules.
282  * \param arg Pointer to the string holding the keyword value.
283  *
284  * \retval 0 On success.
285  * \retval -1 On failure.
286  */
287 static int DetectByteMathSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg)
288 {
289  SigMatch *prev_pm = NULL;
290  DetectByteMathData *data;
291  char *rvalue = NULL;
292  char *nbytes = NULL;
293  int ret = -1;
294 
295  data = DetectByteMathParse(de_ctx, arg, &nbytes, &rvalue);
296  if (data == NULL)
297  goto error;
298 
299  int sm_list;
300  if (s->init_data->list != DETECT_SM_LIST_NOTSET) {
301  if (DetectBufferGetActiveList(de_ctx, s) == -1)
302  goto error;
303 
304  sm_list = s->init_data->list;
305 
306  if (data->flags & DETECT_BYTEMATH_FLAG_RELATIVE) {
308  if (!prev_pm) {
309  SCLogError("relative specified without "
310  "previous pattern match");
311  goto error;
312  }
313  }
314  } else if (data->endian == EndianDCE) {
315  if (data->flags & DETECT_BYTEMATH_FLAG_RELATIVE) {
318  if (prev_pm == NULL) {
319  sm_list = DETECT_SM_LIST_PMATCH;
320  } else {
321  sm_list = SigMatchListSMBelongsTo(s, prev_pm);
322  if (sm_list < 0)
323  goto error;
324  }
325  } else {
326  sm_list = DETECT_SM_LIST_PMATCH;
327  }
328 
330  goto error;
331 
332  } else if (data->flags & DETECT_BYTEMATH_FLAG_RELATIVE) {
335  if (prev_pm == NULL) {
336  sm_list = DETECT_SM_LIST_PMATCH;
337  } else {
338  sm_list = SigMatchListSMBelongsTo(s, prev_pm);
339  if (sm_list < 0)
340  goto error;
341  }
342 
343  } else {
344  sm_list = DETECT_SM_LIST_PMATCH;
345  }
346 
347  if (data->endian == EndianDCE) {
349  goto error;
350 
351  if ((data->flags & DETECT_BYTEMATH_FLAG_STRING) || (data->base == BaseDec) ||
352  (data->base == BaseHex) || (data->base == BaseOct)) {
353  SCLogError("Invalid option. "
354  "A bytemath keyword with dce holds other invalid modifiers.");
355  goto error;
356  }
357  }
358 
359  if (nbytes != NULL) {
360  DetectByteIndexType index;
361  if (!DetectByteRetrieveSMVar(nbytes, s, sm_list, &index)) {
362  SCLogError("unknown byte_ keyword var seen in byte_math - %s", nbytes);
363  goto error;
364  }
365  data->nbytes = index;
366  data->flags |= DETECT_BYTEMATH_FLAG_NBYTES_VAR;
367  SCFree(nbytes);
368  nbytes = NULL;
369  }
370 
371  if (rvalue != NULL) {
372  DetectByteIndexType index;
373  if (!DetectByteRetrieveSMVar(rvalue, s, sm_list, &index)) {
374  SCLogError("unknown byte_ keyword var seen in byte_math - %s", rvalue);
375  goto error;
376  }
377  data->rvalue = index;
378  data->flags |= DETECT_BYTEMATH_FLAG_RVALUE_VAR;
379  SCFree(rvalue);
380  rvalue = NULL;
381  }
382 
383  SigMatch *prev_bmd_sm = DetectGetLastSMByListId(s, sm_list,
384  DETECT_BYTEMATH, -1);
385  if (prev_bmd_sm == NULL) {
386  data->local_id = 0;
387  } else {
388  data->local_id = ((DetectByteMathData *)prev_bmd_sm->ctx)->local_id + 1;
389  }
390  if (data->local_id > de_ctx->byte_extract_max_local_id) {
391  de_ctx->byte_extract_max_local_id = data->local_id;
392  }
393 
394  if (SCSigMatchAppendSMToList(de_ctx, s, DETECT_BYTEMATH, (SigMatchCtx *)data, sm_list) ==
395  NULL) {
396  goto error;
397  }
398 
399  if (!(data->flags & DETECT_BYTEMATH_FLAG_RELATIVE))
400  goto okay;
401 
402  if (prev_pm == NULL)
403  goto okay;
404 
405  if (prev_pm->type == DETECT_CONTENT) {
406  DetectContentData *cd = (DetectContentData *)prev_pm->ctx;
408  } else if (prev_pm->type == DETECT_PCRE) {
409  DetectPcreData *pd = (DetectPcreData *)prev_pm->ctx;
411  }
412 
413  okay:
414  return 0;
415 
416  error:
417  if (rvalue)
418  SCFree(rvalue);
419  if (nbytes)
420  SCFree(nbytes);
421  DetectByteMathFree(de_ctx, data);
422  return ret;
423 }
424 
425 /**
426  * \brief Used to free instances of DetectByteMathractData.
427  *
428  * \param ptr Instance of DetectByteMathData to be freed.
429  */
430 static void DetectByteMathFree(DetectEngineCtx *de_ctx, void *ptr)
431 {
432  SCByteMathFree(ptr);
433 }
434 
435 /**
436  * \brief Lookup the SigMatch for a named byte_math variable.
437  *
438  * \param arg The name of the byte_math variable to lookup.
439  * \param s Pointer the signature to look in.
440  *
441  * \retval A pointer to the SigMatch if found, otherwise NULL.
442  */
443 SigMatch *DetectByteMathRetrieveSMVar(const char *arg, int sm_list, const Signature *s)
444 {
445  for (uint32_t x = 0; x < s->init_data->buffer_index; x++) {
446  SigMatch *sm = s->init_data->buffers[x].head;
447  while (sm != NULL) {
448  if (sm->type == DETECT_BYTEMATH) {
449  const DetectByteMathData *bmd = (const DetectByteMathData *)sm->ctx;
450  if (strcmp(bmd->result, arg) == 0) {
451  SCLogDebug("Retrieved SM for \"%s\"", arg);
452  return sm;
453  }
454  }
455  sm = sm->next;
456  }
457  }
458 
459  for (int list = 0; list < DETECT_SM_LIST_MAX; list++) {
460  SigMatch *sm = s->init_data->smlists[list];
461  while (sm != NULL) {
462  // Make sure that the linked buffers ore on the same list
463  if (sm->type == DETECT_BYTEMATH && (sm_list == -1 || sm_list == list)) {
464  const DetectByteMathData *bmd = (const DetectByteMathData *)sm->ctx;
465  if (strcmp(bmd->result, arg) == 0) {
466  SCLogDebug("Retrieved SM for \"%s\"", arg);
467  return sm;
468  }
469  }
470  sm = sm->next;
471  }
472  }
473 
474  return NULL;
475 }
476 
477 /*************************************Unittests********************************/
478 #ifdef UNITTESTS
479 #include "detect-engine-alert.h"
480 
481 static int DetectByteMathParseTest01(void)
482 {
483 
484  DetectByteMathData *bmd = DetectByteMathParse(NULL,
485  "bytes 4, offset 2, oper +,"
486  "rvalue 10, result bar",
487  NULL, NULL);
488  FAIL_IF(bmd == NULL);
489 
490  FAIL_IF_NOT(bmd->nbytes == 4);
491  FAIL_IF_NOT(bmd->offset == 2);
492  FAIL_IF_NOT(bmd->oper == Addition);
493  FAIL_IF_NOT(bmd->rvalue == 10);
494  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
497 
498  DetectByteMathFree(NULL, bmd);
499 
500  PASS;
501 }
502 
503 static int DetectByteMathParseTest02(void)
504 {
505  /* bytes value invalid */
506  DetectByteMathData *bmd = DetectByteMathParse(NULL,
507  "bytes 257, offset 2, oper +, "
508  "rvalue 39, result bar",
509  NULL, NULL);
510 
511  FAIL_IF_NOT(bmd == NULL);
512 
513  PASS;
514 }
515 
516 static int DetectByteMathParseTest03(void)
517 {
518  /* bytes value invalid */
519  DetectByteMathData *bmd = DetectByteMathParse(NULL,
520  "bytes 11, offset 2, oper +, "
521  "rvalue 39, result bar",
522  NULL, NULL);
523  FAIL_IF_NOT(bmd == NULL);
524 
525  PASS;
526 }
527 
528 static int DetectByteMathParseTest04(void)
529 {
530  /* offset value invalid */
531  DetectByteMathData *bmd = DetectByteMathParse(NULL,
532  "bytes 4, offset 70000, oper +,"
533  " rvalue 39, result bar",
534  NULL, NULL);
535 
536  FAIL_IF_NOT(bmd == NULL);
537 
538  PASS;
539 }
540 
541 static int DetectByteMathParseTest05(void)
542 {
543  /* oper value invalid */
544  DetectByteMathData *bmd = DetectByteMathParse(NULL,
545  "bytes 11, offset 16, oper &,"
546  "rvalue 39, result bar",
547  NULL, NULL);
548  FAIL_IF_NOT(bmd == NULL);
549 
550  PASS;
551 }
552 
553 static int DetectByteMathParseTest06(void)
554 {
555  uint8_t flags = DETECT_BYTEMATH_FLAG_RELATIVE;
556  char *rvalue = NULL;
557 
558  DetectByteMathData *bmd = DetectByteMathParse(NULL,
559  "bytes 4, offset 0, oper +,"
560  "rvalue 248, result var, relative",
561  NULL, &rvalue);
562 
563  FAIL_IF(bmd == NULL);
564  FAIL_IF_NOT(bmd->nbytes == 4);
565  FAIL_IF_NOT(bmd->offset == 0);
566  FAIL_IF_NOT(bmd->oper == Addition);
567  FAIL_IF_NOT(bmd->rvalue == 248);
568  FAIL_IF_NOT(strcmp(bmd->result, "var") == 0);
569  FAIL_IF_NOT(bmd->flags == flags);
572 
573  DetectByteMathFree(NULL, bmd);
574 
575  PASS;
576 }
577 
578 static int DetectByteMathParseTest07(void)
579 {
580  char *rvalue = NULL;
581 
582  DetectByteMathData *bmd = DetectByteMathParse(NULL,
583  "bytes 4, offset 2, oper +,"
584  "rvalue foo, result bar",
585  NULL, &rvalue);
586  FAIL_IF_NOT(rvalue);
587  FAIL_IF_NOT(bmd->nbytes == 4);
588  FAIL_IF_NOT(bmd->offset == 2);
589  FAIL_IF_NOT(bmd->oper == Addition);
590  FAIL_IF_NOT(strcmp(rvalue, "foo") == 0);
591  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
594 
595  DetectByteMathFree(NULL, bmd);
596 
597  SCFree(rvalue);
598 
599  PASS;
600 }
601 
602 static int DetectByteMathParseTest08(void)
603 {
604  /* ensure Parse checks the pointer value when rvalue is a var */
605  DetectByteMathData *bmd = DetectByteMathParse(NULL,
606  "bytes 4, offset 2, oper +,"
607  "rvalue foo, result bar",
608  NULL, NULL);
609  FAIL_IF_NOT(bmd == NULL);
610 
611  PASS;
612 }
613 
614 static int DetectByteMathParseTest09(void)
615 {
616  uint8_t flags = DETECT_BYTEMATH_FLAG_RELATIVE;
617 
618  DetectByteMathData *bmd = DetectByteMathParse(NULL,
619  "bytes 4, offset 2, oper +,"
620  "rvalue 39, result bar, relative",
621  NULL, NULL);
622  FAIL_IF(bmd == NULL);
623 
624  FAIL_IF_NOT(bmd->nbytes == 4);
625  FAIL_IF_NOT(bmd->offset == 2);
626  FAIL_IF_NOT(bmd->oper == Addition);
627  FAIL_IF_NOT(bmd->rvalue == 39);
628  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
629  FAIL_IF_NOT(bmd->flags == flags);
632 
633  DetectByteMathFree(NULL, bmd);
634 
635  PASS;
636 }
637 
638 static int DetectByteMathParseTest10(void)
639 {
640  uint8_t flags = DETECT_BYTEMATH_FLAG_ENDIAN;
641 
642  DetectByteMathData *bmd = DetectByteMathParse(NULL,
643  "bytes 4, offset 2, oper +,"
644  "rvalue 39, result bar, endian"
645  " big",
646  NULL, NULL);
647 
648  FAIL_IF(bmd == NULL);
649  FAIL_IF_NOT(bmd->nbytes == 4);
650  FAIL_IF_NOT(bmd->offset == 2);
651  FAIL_IF_NOT(bmd->oper == Addition);
652  FAIL_IF_NOT(bmd->rvalue == 39);
653  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
654  FAIL_IF_NOT(bmd->flags == flags);
655  FAIL_IF_NOT(bmd->endian == BigEndian);
657 
658  DetectByteMathFree(NULL, bmd);
659 
660  PASS;
661 }
662 
663 static int DetectByteMathParseTest11(void)
664 {
665  uint8_t flags = DETECT_BYTEMATH_FLAG_ENDIAN;
666 
667  DetectByteMathData *bmd = DetectByteMathParse(NULL,
668  "bytes 4, offset 2, oper +, "
669  "rvalue 39, result bar, dce",
670  NULL, NULL);
671 
672  FAIL_IF(bmd == NULL);
673  FAIL_IF_NOT(bmd->nbytes == 4);
674  FAIL_IF_NOT(bmd->offset == 2);
675  FAIL_IF_NOT(bmd->oper == Addition);
676  FAIL_IF_NOT(bmd->rvalue == 39);
677  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
678  FAIL_IF_NOT(bmd->flags == flags);
679  FAIL_IF_NOT(bmd->endian == EndianDCE);
681 
682  DetectByteMathFree(NULL, bmd);
683 
684  PASS;
685 }
686 
687 static int DetectByteMathParseTest12(void)
688 {
689  uint8_t flags = DETECT_BYTEMATH_FLAG_RELATIVE | DETECT_BYTEMATH_FLAG_STRING;
690 
691  DetectByteMathData *bmd = DetectByteMathParse(NULL,
692  "bytes 4, offset 2, oper +,"
693  "rvalue 39, result bar, "
694  "relative, string dec",
695  NULL, NULL);
696 
697  FAIL_IF(bmd == NULL);
698  FAIL_IF_NOT(bmd->nbytes == 4);
699  FAIL_IF_NOT(bmd->offset == 2);
700  FAIL_IF_NOT(bmd->oper == Addition);
701  FAIL_IF_NOT(bmd->rvalue == 39);
702  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
703  FAIL_IF_NOT(bmd->flags == flags);
704  FAIL_IF_NOT(bmd->endian == BigEndian);
705  FAIL_IF_NOT(bmd->base == BaseDec);
706 
707  DetectByteMathFree(NULL, bmd);
708 
709  PASS;
710 }
711 
712 static int DetectByteMathParseTest13(void)
713 {
714  uint8_t flags = DETECT_BYTEMATH_FLAG_STRING |
715  DETECT_BYTEMATH_FLAG_RELATIVE |
716  DETECT_BYTEMATH_FLAG_BITMASK;
717 
718  DetectByteMathData *bmd = DetectByteMathParse(NULL,
719  "bytes 4, offset 2, oper +, "
720  "rvalue 39, result bar, "
721  "relative, string dec, bitmask "
722  "0x8f40",
723  NULL, NULL);
724 
725  FAIL_IF(bmd == NULL);
726  FAIL_IF_NOT(bmd->nbytes == 4);
727  FAIL_IF_NOT(bmd->offset == 2);
728  FAIL_IF_NOT(bmd->oper == Addition);
729  FAIL_IF_NOT(bmd->rvalue == 39);
730  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
731  FAIL_IF_NOT(bmd->bitmask_val == 0x8f40);
732  FAIL_IF_NOT(bmd->bitmask_shift_count == 6);
733  FAIL_IF_NOT(bmd->flags == flags);
734  FAIL_IF_NOT(bmd->endian == BigEndian);
735  FAIL_IF_NOT(bmd->base == BaseDec);
736 
737  DetectByteMathFree(NULL, bmd);
738 
739  PASS;
740 }
741 
742 
743 static int DetectByteMathParseTest14(void)
744 {
745  /* incomplete */
746  DetectByteMathData *bmd = DetectByteMathParse(NULL,
747  "bytes 4, offset 2, oper +,"
748  "rvalue foo",
749  NULL, NULL);
750 
751  FAIL_IF_NOT(bmd == NULL);
752 
753  PASS;
754 }
755 
756 static int DetectByteMathParseTest15(void)
757 {
758 
759  /* incomplete */
760  DetectByteMathData *bmd = DetectByteMathParse(NULL,
761  "bytes 4, offset 2, oper +, "
762  "result bar",
763  NULL, NULL);
764 
765  FAIL_IF_NOT(bmd == NULL);
766 
767  PASS;
768 }
769 
770 static int DetectByteMathParseTest16(void)
771 {
772  uint8_t flags = DETECT_BYTEMATH_FLAG_STRING | DETECT_BYTEMATH_FLAG_RELATIVE |
773  DETECT_BYTEMATH_FLAG_BITMASK;
774 
775  DetectByteMathData *bmd = DetectByteMathParse(NULL,
776  "bytes 4, offset -2, oper +, "
777  "rvalue 39, result bar, "
778  "relative, string dec, bitmask "
779  "0x8f40",
780  NULL, NULL);
781 
782  FAIL_IF(bmd == NULL);
783  FAIL_IF_NOT(bmd->nbytes == 4);
784  FAIL_IF_NOT(bmd->offset == -2);
785  FAIL_IF_NOT(bmd->oper == Addition);
786  FAIL_IF_NOT(bmd->rvalue == 39);
787  FAIL_IF_NOT(strcmp(bmd->result, "bar") == 0);
788  FAIL_IF_NOT(bmd->bitmask_val == 0x8f40);
789  FAIL_IF_NOT(bmd->bitmask_shift_count == 6);
790  FAIL_IF_NOT(bmd->flags == flags);
791  FAIL_IF_NOT(bmd->endian == BigEndian);
792  FAIL_IF_NOT(bmd->base == BaseDec);
793 
794  DetectByteMathFree(NULL, bmd);
795 
796  PASS;
797 }
798 
799 static int DetectByteMathPacket01(void)
800 {
801  uint8_t buf[] = { 0x38, 0x35, 0x6d, 0x00, 0x00, 0x01,
802  0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
803  0x00, 0x00, 0x6d, 0x00, 0x01, 0x00 };
804  Flow f;
805  void *dns_state = NULL;
806  Packet *p = NULL;
807  Signature *s = NULL;
808  ThreadVars tv;
809  DetectEngineThreadCtx *det_ctx = NULL;
811 
812  memset(&tv, 0, sizeof(ThreadVars));
814  memset(&f, 0, sizeof(Flow));
815 
816  p = UTHBuildPacketReal(buf, sizeof(buf), IPPROTO_UDP,
817  "192.168.1.5", "192.168.1.1",
818  41424, 53);
819  FAIL_IF_NULL(p);
820 
821  FLOW_INITIALIZE(&f);
822  f.flags |= FLOW_IPV4;
823  f.proto = IPPROTO_UDP;
825 
826  p->flow = &f;
827  p->flags |= PKT_HAS_FLOW;
830 
833 
835  de_ctx->flags |= DE_QUIET;
836 
837  /*
838  * byte_extract: Extract 1 byte from offset 0 --> 0x0038
839  * byte_math: Extract 1 byte from offset 2 (0x35)
840  * Add 0x35 + 0x38 = 109 (0x6d)
841  * byte_test: Compare 2 bytes at offset 13 bytes from last
842  * match and compare with 0x6d
843  */
844  s = DetectEngineAppendSig(de_ctx, "alert udp any any -> any any "
845  "(byte_extract: 1, 0, extracted_val, relative;"
846  "byte_math: bytes 1, offset 1, oper +, rvalue extracted_val, result var;"
847  "byte_test: 2, =, var, 13;"
848  "msg:\"Byte extract and byte math with byte test verification\";"
849  "sid:1;)");
850  FAIL_IF_NULL(s);
851 
852  /* this rule should not alert */
853  s = DetectEngineAppendSig(de_ctx, "alert udp any any -> any any "
854  "(byte_extract: 1, 0, extracted_val, relative;"
855  "byte_math: bytes 1, offset 1, oper +, rvalue extracted_val, result var;"
856  "byte_test: 2, !=, var, 13;"
857  "msg:\"Byte extract and byte math with byte test verification\";"
858  "sid:2;)");
859  FAIL_IF_NULL(s);
860 
861  /*
862  * this rule should alert:
863  * compares offset 15 with var ... 1 (offset 15) < 0x6d (var)
864  */
865  s = DetectEngineAppendSig(de_ctx, "alert udp any any -> any any "
866  "(byte_extract: 1, 0, extracted_val, relative;"
867  "byte_math: bytes 1, offset 1, oper +, rvalue extracted_val, result var;"
868  "byte_test: 2, <, var, 15;"
869  "msg:\"Byte extract and byte math with byte test verification\";"
870  "sid:3;)");
871  FAIL_IF_NULL(s);
872 
874  DetectEngineThreadCtxInit(&tv, (void *)de_ctx, (void *)&det_ctx);
875  FAIL_IF_NULL(det_ctx);
876 
877  int r = AppLayerParserParse(NULL, alp_tctx, &f, ALPROTO_DNS,
878  STREAM_TOSERVER, buf, sizeof(buf));
879  FAIL_IF_NOT(r == 0);
880 
881  dns_state = f.alstate;
882  FAIL_IF_NULL(dns_state);
883 
884  /* do detect */
885  SigMatchSignatures(&tv, de_ctx, det_ctx, p);
886 
887  /* ensure sids 1 & 3 alerted */
891 
893  DetectEngineThreadCtxDeinit(&tv, det_ctx);
895 
896  FLOW_DESTROY(&f);
897  UTHFreePacket(p);
899  PASS;
900 }
901 
902 static int DetectByteMathPacket02(void)
903 {
904  uint8_t buf[] = { 0x38, 0x35, 0x6d, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
905  0x00, 0x70, 0x00, 0x01, 0x00 };
906  Flow f;
907  void *dns_state = NULL;
908  Packet *p = NULL;
909  Signature *s = NULL;
910  ThreadVars tv;
911  DetectEngineThreadCtx *det_ctx = NULL;
913 
914  memset(&tv, 0, sizeof(ThreadVars));
916  memset(&f, 0, sizeof(Flow));
917 
918  p = UTHBuildPacketReal(buf, sizeof(buf), IPPROTO_UDP, "192.168.1.5", "192.168.1.1", 41424, 53);
919  FAIL_IF_NULL(p);
920 
921  FLOW_INITIALIZE(&f);
922  f.flags |= FLOW_IPV4;
923  f.proto = IPPROTO_UDP;
925 
926  p->flow = &f;
927  p->flags |= PKT_HAS_FLOW;
930 
933 
935  de_ctx->flags |= DE_QUIET;
936 
937  /*
938  * byte_extract: Extract 1 byte from offset 0 --> 0x38
939  * byte_math: Extract 1 byte from offset -1 (0x38)
940  * Add 0x38 + 0x38 = 112 (0x70)
941  * byte_test: Compare 2 bytes at offset 13 bytes from last
942  * match and compare with 0x70
943  */
945  "alert udp any any -> any any "
946  "(byte_extract: 1, 0, extracted_val, relative;"
947  "byte_math: bytes 1, offset -1, oper +, rvalue extracted_val, result var, relative;"
948  "byte_test: 2, =, var, 13;"
949  "msg:\"Byte extract and byte math with byte test verification\";"
950  "sid:1;)");
951  FAIL_IF_NULL(s);
952 
953  /* this rule should not alert */
955  "alert udp any any -> any any "
956  "(byte_extract: 1, 0, extracted_val, relative;"
957  "byte_math: bytes 1, offset -1, oper +, rvalue extracted_val, result var, relative;"
958  "byte_test: 2, !=, var, 13;"
959  "msg:\"Byte extract and byte math with byte test verification\";"
960  "sid:2;)");
961  FAIL_IF_NULL(s);
962 
963  /*
964  * this rule should alert:
965  * compares offset 15 with var ... 1 (offset 15) < 0x70 (var)
966  */
968  "alert udp any any -> any any "
969  "(byte_extract: 1, 0, extracted_val, relative;"
970  "byte_math: bytes 1, offset -1, oper +, rvalue extracted_val, result var, relative;"
971  "byte_test: 2, <, var, 15;"
972  "msg:\"Byte extract and byte math with byte test verification\";"
973  "sid:3;)");
974  FAIL_IF_NULL(s);
975 
977  DetectEngineThreadCtxInit(&tv, (void *)de_ctx, (void *)&det_ctx);
978  FAIL_IF_NULL(det_ctx);
979 
980  int r = AppLayerParserParse(NULL, alp_tctx, &f, ALPROTO_DNS, STREAM_TOSERVER, buf, sizeof(buf));
981  FAIL_IF_NOT(r == 0);
982 
983  dns_state = f.alstate;
984  FAIL_IF_NULL(dns_state);
985 
986  /* do detect */
987  SigMatchSignatures(&tv, de_ctx, det_ctx, p);
988 
989  /* ensure sids 1 & 3 alerted */
993 
995  DetectEngineThreadCtxDeinit(&tv, det_ctx);
997 
998  FLOW_DESTROY(&f);
999  UTHFreePacket(p);
1000 
1002  PASS;
1003 }
1004 
1005 /**
1006  * \test A payload-supplied shift count of 64 or more yields 0 instead of
1007  * shifting a uint64_t by its own width.
1008  */
1009 static int DetectByteMathPacket03(void)
1010 {
1011  /* byte 0 is the shift count (64), byte 1 the value shifted, byte 2 the
1012  * expected result */
1013  uint8_t buf[] = { 0x40, 0xff, 0x00 };
1014 
1015  Packet *p = UTHBuildPacket(buf, sizeof(buf), IPPROTO_UDP);
1016  FAIL_IF_NULL(p);
1017 
1018  /* 0xff >> 64 is 0 */
1019  FAIL_IF_NOT(UTHPacketMatchSig(p, "alert udp any any -> any any "
1020  "(byte_extract: 1, 0, shift;"
1021  "byte_math: bytes 1, offset 1, oper >>, rvalue shift, result "
1022  "var;"
1023  "byte_test: 1, =, var, 2;"
1024  "sid:1;)"));
1025  UTHFreePacket(p);
1026 
1027  PASS;
1028 }
1029 
1030 /**
1031  * \test A literal shift count of 64 or more is rejected at parse time.
1032  */
1033 static int DetectByteMathParseTest17(void)
1034 {
1035  DetectByteMathData *bmd = DetectByteMathParse(
1036  NULL, "bytes 4, offset 2, oper >>, rvalue 64, result foo", NULL, NULL);
1037  FAIL_IF_NOT_NULL(bmd);
1038 
1039  bmd = DetectByteMathParse(
1040  NULL, "bytes 4, offset 2, oper <<, rvalue 64, result foo", NULL, NULL);
1041  FAIL_IF_NOT_NULL(bmd);
1042 
1043  bmd = DetectByteMathParse(
1044  NULL, "bytes 4, offset 2, oper >>, rvalue 63, result foo", NULL, NULL);
1045  FAIL_IF_NULL(bmd);
1046  DetectByteMathFree(NULL, bmd);
1047 
1048  PASS;
1049 }
1050 
1051 static int DetectByteMathContext01(void)
1052 {
1053  DetectEngineCtx *de_ctx = NULL;
1054  Signature *s = NULL;
1055  SigMatch *sm = NULL;
1056  DetectContentData *cd = NULL;
1057  DetectByteMathData *bmd = NULL;
1058 
1060  FAIL_IF(de_ctx == NULL);
1061 
1062  de_ctx->flags |= DE_QUIET;
1063  s = de_ctx->sig_list = SigInit(de_ctx, "alert tcp any any -> any any "
1064  "(msg:\"Testing bytemath_body\"; "
1065  "content:\"|00 04 93 F3|\"; "
1066  "content:\"|00 00 00 07|\"; distance:4; within:4;"
1067  "byte_math:bytes 4, offset 0, oper +, rvalue "
1068  "248, result var, relative; sid:1;)");
1069 
1070  FAIL_IF(de_ctx->sig_list == NULL);
1071 
1073 
1075  FAIL_IF(sm->type != DETECT_CONTENT);
1076  cd = (DetectContentData *)sm->ctx;
1079  FAIL_IF(cd->content_len != 4);
1080 
1081  sm = sm->next;
1082  FAIL_IF(sm->type != DETECT_CONTENT);
1083  sm = sm->next;
1084  FAIL_IF(sm->type != DETECT_BYTEMATH);
1085 
1086  FAIL_IF(sm->ctx == NULL);
1087 
1088  bmd = (DetectByteMathData *)sm->ctx;
1089  FAIL_IF_NOT(bmd->nbytes == 4);
1090  FAIL_IF_NOT(bmd->offset == 0);
1091  FAIL_IF_NOT(bmd->rvalue == 248);
1092  FAIL_IF_NOT(strcmp(bmd->result, "var") == 0);
1093  FAIL_IF_NOT(bmd->flags == DETECT_BYTEMATH_FLAG_RELATIVE);
1094  FAIL_IF_NOT(bmd->endian == BigEndian);
1095  FAIL_IF_NOT(bmd->oper == Addition);
1096  FAIL_IF_NOT(bmd->base == BaseDec);
1097 
1099 
1100  PASS;
1101 }
1102 
1103 static void DetectByteMathRegisterTests(void)
1104 {
1105  UtRegisterTest("DetectByteMathParseTest01", DetectByteMathParseTest01);
1106  UtRegisterTest("DetectByteMathParseTest02", DetectByteMathParseTest02);
1107  UtRegisterTest("DetectByteMathParseTest03", DetectByteMathParseTest03);
1108  UtRegisterTest("DetectByteMathParseTest04", DetectByteMathParseTest04);
1109  UtRegisterTest("DetectByteMathParseTest05", DetectByteMathParseTest05);
1110  UtRegisterTest("DetectByteMathParseTest06", DetectByteMathParseTest06);
1111  UtRegisterTest("DetectByteMathParseTest07", DetectByteMathParseTest07);
1112  UtRegisterTest("DetectByteMathParseTest08", DetectByteMathParseTest08);
1113  UtRegisterTest("DetectByteMathParseTest09", DetectByteMathParseTest09);
1114  UtRegisterTest("DetectByteMathParseTest10", DetectByteMathParseTest10);
1115  UtRegisterTest("DetectByteMathParseTest11", DetectByteMathParseTest11);
1116  UtRegisterTest("DetectByteMathParseTest12", DetectByteMathParseTest12);
1117  UtRegisterTest("DetectByteMathParseTest13", DetectByteMathParseTest13);
1118  UtRegisterTest("DetectByteMathParseTest14", DetectByteMathParseTest14);
1119  UtRegisterTest("DetectByteMathParseTest15", DetectByteMathParseTest15);
1120  UtRegisterTest("DetectByteMathParseTest16", DetectByteMathParseTest16);
1121  UtRegisterTest("DetectByteMathParseTest17", DetectByteMathParseTest17);
1122  UtRegisterTest("DetectByteMathPacket01", DetectByteMathPacket01);
1123  UtRegisterTest("DetectByteMathPacket02", DetectByteMathPacket02);
1124  UtRegisterTest("DetectByteMathPacket03", DetectByteMathPacket03);
1125  UtRegisterTest("DetectByteMathContext01", DetectByteMathContext01);
1126 }
1127 #endif /* UNITTESTS */
util-byte.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
DETECT_CONTENT_RELATIVE_NEXT
#define DETECT_CONTENT_RELATIVE_NEXT
Definition: detect-content.h:66
SignatureInitDataBuffer_::head
SigMatch * head
Definition: detect.h:543
detect-content.h
len
uint8_t len
Definition: app-layer-dnp3.h:2
DetectEngineThreadCtx_::buffer_offset
uint32_t buffer_offset
Definition: detect.h:1340
detect-engine.h
DETECT_SM_LIST_PMATCH
@ DETECT_SM_LIST_PMATCH
Definition: detect.h:120
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
SignatureInitData_::smlists
struct SigMatch_ * smlists[DETECT_SM_LIST_MAX]
Definition: detect.h:666
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
ByteExtractUint64
int ByteExtractUint64(uint64_t *res, int e, uint16_t len, const uint8_t *bytes)
Definition: util-byte.c:74
Flow_::flags
uint64_t flags
Definition: flow.h:408
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
PKT_HAS_FLOW
#define PKT_HAS_FLOW
Definition: decode.h:1311
ALPROTO_DCERPC
@ ALPROTO_DCERPC
Definition: app-layer-protos.h:44
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
flow-util.h
ALPROTO_DNS
@ ALPROTO_DNS
Definition: app-layer-protos.h:47
SigTableElmt_::name
const char * name
Definition: detect.h:1542
SignatureInitData_::smlists_tail
struct SigMatch_ * smlists_tail[DETECT_SM_LIST_MAX]
Definition: detect.h:668
DETECT_BYTEJUMP
@ DETECT_BYTEJUMP
Definition: detect-engine-register.h:92
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
DETECT_CONTENT
@ DETECT_CONTENT
Definition: detect-engine-register.h:78
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
Flow_::proto
uint8_t proto
Definition: flow.h:381
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
Packet_::flags
uint32_t flags
Definition: decode.h:562
threads.h
SCDetectGetLastSMFromLists
SigMatch * SCDetectGetLastSMFromLists(const Signature *s,...)
Returns the sm with the largest index (added latest) from the lists passed to us.
Definition: detect-parse.c:600
Flow_
Flow data structure.
Definition: flow.h:359
Flow_::protomap
uint8_t protomap
Definition: flow.h:450
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
AppLayerParserThreadCtxFree
void AppLayerParserThreadCtxFree(AppLayerParserThreadCtx *tctx)
Destroys the app layer parser thread context obtained using AppLayerParserThreadCtxAlloc().
Definition: app-layer-parser.c:364
FLOW_PKT_TOSERVER
#define FLOW_PKT_TOSERVER
Definition: flow.h:236
rust.h
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
UTHPacketMatchSig
int UTHPacketMatchSig(Packet *p, const char *sig)
Definition: util-unittest-helper.c:833
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
mpm_default_matcher
uint8_t mpm_default_matcher
Definition: util-mpm.c:47
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
DetectContentData_
Definition: detect-content.h:93
DetectPcreData_::flags
uint16_t flags
Definition: detect-pcre.h:52
SCDetectSignatureSetAppProto
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
Definition: detect-parse.c:2613
ByteExtractStringUint64
int ByteExtractStringUint64(uint64_t *res, int base, size_t len, const char *str)
Definition: util-byte.c:189
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
Packet_::flowflags
uint8_t flowflags
Definition: decode.h:547
UTHBuildPacketReal
Packet * UTHBuildPacketReal(uint8_t *payload, uint16_t payload_len, uint8_t ipproto, const char *src, const char *dst, uint16_t sport, uint16_t dport)
UTHBuildPacketReal is a function that create tcp/udp packets for unittests specifying ip and port sou...
Definition: util-unittest-helper.c:136
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
detect-pcre.h
DETECT_BYTEMATH_ENDIAN_DEFAULT
#define DETECT_BYTEMATH_ENDIAN_DEFAULT
Definition: detect-bytemath.c:60
FLOW_IPV4
#define FLOW_IPV4
Definition: flow.h:99
DetectByteIndexType
uint8_t DetectByteIndexType
Definition: detect-byte.h:28
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
DetectGetLastSMByListId
SigMatch * DetectGetLastSMByListId(const Signature *s, int list_id,...)
Returns the sm with the largest index (added last) from the list passed to us as an id.
Definition: detect-parse.c:694
DetectByteMathRetrieveSMVar
SigMatch * DetectByteMathRetrieveSMVar(const char *arg, int sm_list, const Signature *s)
Lookup the SigMatch for a named byte_math variable.
Definition: detect-bytemath.c:443
FLOW_INITIALIZE
#define FLOW_INITIALIZE(f)
Definition: flow-util.h:38
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
DETECT_CONTENT_DISTANCE
#define DETECT_CONTENT_DISTANCE
Definition: detect-content.h:30
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
alp_tctx
AppLayerParserThreadCtx * alp_tctx
Definition: fuzz_applayerparserparse.c:24
SignatureInitData_::list
int list
Definition: detect.h:645
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
SigMatch_::next
struct SigMatch_ * next
Definition: detect.h:364
DetectEngineCtx_::mpm_matcher
uint8_t mpm_matcher
Definition: detect.h:998
SigInit
Signature * SigInit(DetectEngineCtx *de_ctx, const char *sigstr)
Parses a signature and adds it to the Detection Engine Context.
Definition: detect-parse.c:3618
app-layer-parser.h
SigMatch_::ctx
SigMatchCtx * ctx
Definition: detect.h:363
BYTE_BIG_ENDIAN
#define BYTE_BIG_ENDIAN
Definition: util-byte.h:29
FlowGetProtoMapping
uint8_t FlowGetProtoMapping(uint8_t proto)
Function to map the protocol to the defined FLOW_PROTO_* enumeration.
Definition: flow-util.c:100
Packet_
Definition: decode.h:516
detect-engine-build.h
detect-engine-alert.h
DetectContentData_::flags
uint32_t flags
Definition: detect-content.h:104
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:775
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
detect-byte.h
DetectEngineCtx_::byte_extract_max_local_id
int32_t byte_extract_max_local_id
Definition: detect.h:1077
DETECT_PCRE
@ DETECT_PCRE
Definition: detect-engine-register.h:80
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
AppLayerParserThreadCtxAlloc
AppLayerParserThreadCtx * AppLayerParserThreadCtxAlloc(void)
Gets a new app layer protocol's parser thread context.
Definition: app-layer-parser.c:337
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
DETECT_SM_LIST_NOTSET
#define DETECT_SM_LIST_NOTSET
Definition: detect.h:145
DETECT_BYTETEST
@ DETECT_BYTETEST
Definition: detect-engine-register.h:91
BYTE_LITTLE_ENDIAN
#define BYTE_LITTLE_ENDIAN
Definition: util-byte.h:30
Packet_::flow
struct Flow_ * flow
Definition: decode.h:564
DetectByteMathDoMatch
int DetectByteMathDoMatch(DetectEngineThreadCtx *det_ctx, const DetectByteMathData *data, const Signature *s, const uint8_t *payload, const uint32_t payload_len, uint8_t nbytes, uint64_t rvalue, uint64_t *value, uint8_t endian)
Definition: detect-bytemath.c:89
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
flags
uint8_t flags
Definition: decode-gre.h:0
AppLayerParserParse
int AppLayerParserParse(ThreadVars *tv, AppLayerParserThreadCtx *alp_tctx, Flow *f, AppProto alproto, uint8_t flags, const uint8_t *input, uint32_t input_len)
Definition: app-layer-parser.c:1528
suricata-common.h
SigMatch_::type
uint16_t type
Definition: detect.h:361
DETECT_BYTEMATH_BASE_DEFAULT
#define DETECT_BYTEMATH_BASE_DEFAULT
Definition: detect-bytemath.c:61
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
util-spm.h
detect-engine-buffer.h
SCStrdup
#define SCStrdup(s)
Definition: util-mem.h:56
DetectEngineCtx_::sig_list
Signature * sig_list
Definition: detect.h:1005
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
DetectBytemathRegister
void DetectBytemathRegister(void)
Registers the keyword handlers for the "byte_math" keyword.
Definition: detect-bytemath.c:70
SignatureInitData_::buffers
SignatureInitDataBuffer * buffers
Definition: detect.h:671
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SigMatchListSMBelongsTo
int SigMatchListSMBelongsTo(const Signature *s, const SigMatch *key_sm)
Definition: detect-parse.c:799
SCFree
#define SCFree(p)
Definition: util-mem.h:61
UTHFreePacket
void UTHFreePacket(Packet *p)
UTHFreePacket: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:470
Flow_::alstate
void * alstate
Definition: flow.h:484
DETECT_BYTE_EXTRACT
@ DETECT_BYTE_EXTRACT
Definition: detect-engine-register.h:94
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
SigMatch_
a single match condition for a signature
Definition: detect.h:360
payload_len
uint16_t payload_len
Definition: stream-tcp-private.h:1
DETECT_ISDATAAT
@ DETECT_ISDATAAT
Definition: detect-engine-register.h:102
DETECT_SM_LIST_MAX
@ DETECT_SM_LIST_MAX
Definition: detect.h:136
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
DETECT_PCRE_RELATIVE_NEXT
#define DETECT_PCRE_RELATIVE_NEXT
Definition: detect-pcre.h:34
app-layer-protos.h
DetectPcreData_
Definition: detect-pcre.h:48
DetectContentData_::content_len
uint16_t content_len
Definition: detect-content.h:95
DETECT_BYTEMATH
@ DETECT_BYTEMATH
Definition: detect-engine-register.h:93
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
AppLayerParserThreadCtx_
Definition: app-layer-parser.c:72
DetectByteRetrieveSMVar
bool DetectByteRetrieveSMVar(const char *arg, const Signature *s, int sm_list, DetectByteIndexType *index)
Used to retrieve args from BM.
Definition: detect-byte.c:41
flow.h
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:455
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
DetectBufferGetActiveList
int DetectBufferGetActiveList(DetectEngineCtx *de_ctx, Signature *s)
Definition: detect-engine-buffer.c:109
SignatureInitData_::buffer_index
uint32_t buffer_index
Definition: detect.h:672
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
flow-var.h
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
FLOW_DESTROY
#define FLOW_DESTROY(f)
Definition: flow-util.h:119
DETECT_CONTENT_WITHIN
#define DETECT_CONTENT_WITHIN
Definition: detect-content.h:31
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
detect-bytemath.h
f
Flow f
Definition: fuzz_dataset.c:32