Go to the documentation of this file.
38 #define PARSE_REGEX "^\\s*([a-zA-Z][a-zA-Z0-9-_]*)\\s*$"
44 static void DetectClasstypeRegisterTests(
void);
69 static int DetectClasstypeParseRawString(
const char *rawstr,
char *out,
size_t outsize)
75 pcre2_match_data *match = NULL;
84 ret = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)e, &pcre2len);
86 SCLogError(
"pcre2_substring_copy_bynumber failed");
96 pcre2_match_data_free(match);
101 pcre2_match_data_free(match);
124 "keyword detected.");
128 "keyword detected. Using instance with highest priority");
132 if (DetectClasstypeParseRawString(rawstr, parsed_ct_name,
sizeof(parsed_ct_name)) < 0) {
133 SCLogError(
"invalid value for classtype keyword: "
143 SCLogError(
"unknown classtype '%s'", parsed_ct_name);
149 "unknown classtype: \"%s\", using default priority %d. "
150 "This message won't be shown again for this classtype",
154 "unknown classtype: \"%s\", using default priority %d. "
155 "This message won't be shown again for this classtype",
159 "using default priority %d. "
160 "This message won't be shown again for this classtype",
165 snprintf(
str,
sizeof(
str),
166 "config classification: %s,Unknown Classtype,%d\n",
182 bool update_ct =
false;
186 }
else if (s->
prio == -1) {
196 if (real_ct && update_ct) {
208 static int DetectClasstypeTest01(
void)
218 "(msg:\"Classtype test\"; "
219 "Classtype:not_available; sid:1;)");
233 static int DetectClasstypeTest02(
void)
244 "(Classtype:bad-unknown; sid:1;)");
248 "(Classtype:not-there; sid:2;)");
252 "(Classtype:Bad-UnkNown; sid:3;)");
256 "(Classtype:nothing-wrong; sid:4;)");
260 "(Classtype:attempted_dos; Classtype:bad-unknown; sid:5;)");
266 "(Classtype:nothing-wrong; Classtype:Bad-UnkNown; sid:6;)");
279 static int DetectClasstypeTest03(
void)
290 "(msg:\"Classtype test\"; Classtype:bad-unknown; priority:1; sid:1;)");
295 "(msg:\"Classtype test\"; Classtype:unKnoWn; "
296 "priority:3; sid:2;)");
301 "Classtype:nothing-wrong; priority:1; sid:3;)");
305 "(msg:\"Classtype test\"; Classtype:bad-unknown; Classtype:undefined; "
306 "priority:5; sid:4;)");
318 static void DetectClasstypeRegisterTests(
void)
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
SigTableElmt * sigmatch_table
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
#define SIG_FLAG_INIT_PRIO_EXPLICIT
main detection engine ctx
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
size_t strlcpy(char *dst, const char *src, size_t siz)
#define PASS
Pass the test.
Container for a Classtype from the Classification.config file.
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
int SCClassConfAddClasstype(DetectEngineCtx *de_ctx, char *rawstr, uint16_t index)
Parses a line from the classification file and adds it to Classtype hash table in DetectEngineCtx,...
bool SigMatchStrictEnabled(const enum DetectKeywordId id)
#define SCLogWarning(...)
Macro used to log WARNING messages.
SCClassConfClasstype * SCClassConfGetClasstype(const char *ct_name, DetectEngineCtx *de_ctx)
Gets the classtype from the corresponding hash table stored in the Detection Engine Context's class c...
SignatureInitData * init_data
#define SCLogError(...)
Macro used to log ERROR messages.
#define CLASSTYPE_NAME_MAX_LEN
DetectEngineCtx * DetectEngineCtxInit(void)
FILE * SCClassConfGenerateValidDummyClassConfigFD01(void)
Creates a dummy classification file, with all valid Classtypes, for testing purposes.
#define DETECT_DEFAULT_PRIO
void DetectClasstypeRegister(void)
Registers the handler functions for the "Classtype" keyword.
bool SCClassConfLoadClassificationConfigFile(DetectEngineCtx *de_ctx, FILE *fd)
Loads the Classtype info from the classification.config file.
void(* RegisterTests)(void)
void SCClassConfDeInitContext(DetectEngineCtx *de_ctx)
Releases resources used by the Classification Config API.