suricata
detect-classtype.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2020 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
22  * \author Victor Julien <victor@inliniac.net>
23  *
24  * Implements classtype keyword.
25  */
26 
27 #include "suricata-common.h"
28 #include "decode.h"
29 
30 #include "detect.h"
31 #include "detect-parse.h"
32 #include "detect-engine.h"
33 #include "detect-classtype.h"
35 #include "util-error.h"
36 #include "util-debug.h"
37 
38 #define PARSE_REGEX "^\\s*([a-zA-Z][a-zA-Z0-9-_]*)\\s*$"
39 
40 static DetectParseRegex parse_regex;
41 
42 static int DetectClasstypeSetup(DetectEngineCtx *, Signature *, const char *);
43 #ifdef UNITTESTS
44 static void DetectClasstypeRegisterTests(void);
45 #endif
46 
47 /**
48  * \brief Registers the handler functions for the "Classtype" keyword.
49  */
51 {
52  sigmatch_table[DETECT_CLASSTYPE].name = "classtype";
53  sigmatch_table[DETECT_CLASSTYPE].desc = "information about the classification of rules and alerts";
54  sigmatch_table[DETECT_CLASSTYPE].url = "/rules/meta.html#classtype";
55  sigmatch_table[DETECT_CLASSTYPE].Setup = DetectClasstypeSetup;
56 #ifdef UNITTESTS
57  sigmatch_table[DETECT_CLASSTYPE].RegisterTests = DetectClasstypeRegisterTests;
58 #endif
59  DetectSetupParseRegexes(PARSE_REGEX, &parse_regex);
60 }
61 
62 /**
63  * \brief Parses the raw string supplied with the "Classtype" keyword.
64  *
65  * \param Pointer to the string to be parsed.
66  *
67  * \retval bool success or failure.
68  */
69 static int DetectClasstypeParseRawString(const char *rawstr, char *out, size_t outsize)
70 {
71  size_t pcre2len;
72 
73  const size_t esize = CLASSTYPE_NAME_MAX_LEN + 8;
74  char e[esize];
75  pcre2_match_data *match = NULL;
76 
77  int ret = DetectParsePcreExec(&parse_regex, &match, rawstr, 0, 0);
78  if (ret < 0) {
79  SCLogError("Invalid Classtype in Signature");
80  goto error;
81  }
82 
83  pcre2len = esize;
84  ret = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)e, &pcre2len);
85  if (ret < 0) {
86  SCLogError("pcre2_substring_copy_bynumber failed");
87  goto error;
88  }
89 
90  if (strlen(e) >= CLASSTYPE_NAME_MAX_LEN) {
91  SCLogError("classtype '%s' is too big: max %d", rawstr, CLASSTYPE_NAME_MAX_LEN - 1);
92  goto error;
93  }
94  (void)strlcpy(out, e, outsize);
95 
96  pcre2_match_data_free(match);
97  return 0;
98 
99 error:
100  if (match) {
101  pcre2_match_data_free(match);
102  }
103  return -1;
104 }
105 
106 /**
107  * \brief The setup function that would be called when the Signature parsing
108  * module encounters the "Classtype" keyword.
109  *
110  * \param de_ctx Pointer to the Detection Engine Context.
111  * \param s Pointer the current Signature instance that is being parsed.
112  * \param rawstr Pointer to the argument supplied to the classtype keyword.
113  *
114  * \retval 0 On success
115  * \retval -1 On failure
116  */
117 static int DetectClasstypeSetup(DetectEngineCtx *de_ctx, Signature *s, const char *rawstr)
118 {
119  char parsed_ct_name[CLASSTYPE_NAME_MAX_LEN] = "";
120 
121  if ((s->class_id > 0) || (s->class_msg != NULL)) {
123  SCLogError("duplicated 'classtype' "
124  "keyword detected.");
125  return -1;
126  } else {
127  SCLogWarning("duplicated 'classtype' "
128  "keyword detected. Using instance with highest priority");
129  }
130  }
131 
132  if (DetectClasstypeParseRawString(rawstr, parsed_ct_name, sizeof(parsed_ct_name)) < 0) {
133  SCLogError("invalid value for classtype keyword: "
134  "\"%s\"",
135  rawstr);
136  return -1;
137  }
138 
139  bool real_ct = true;
140  SCClassConfClasstype *ct = SCClassConfGetClasstype(parsed_ct_name, de_ctx);
141  if (ct == NULL) {
143  SCLogError("unknown classtype '%s'", parsed_ct_name);
144  return -1;
145  }
146 
147  if (s->id > 0) {
148  SCLogWarning("signature sid:%u uses "
149  "unknown classtype: \"%s\", using default priority %d. "
150  "This message won't be shown again for this classtype",
151  s->id, parsed_ct_name, DETECT_DEFAULT_PRIO);
152  } else if (de_ctx->rule_file != NULL) {
153  SCLogWarning("signature at %s:%u uses "
154  "unknown classtype: \"%s\", using default priority %d. "
155  "This message won't be shown again for this classtype",
156  de_ctx->rule_file, de_ctx->rule_line, parsed_ct_name, DETECT_DEFAULT_PRIO);
157  } else {
158  SCLogWarning("unknown classtype: \"%s\", "
159  "using default priority %d. "
160  "This message won't be shown again for this classtype",
161  parsed_ct_name, DETECT_DEFAULT_PRIO);
162  }
163 
164  char str[256];
165  snprintf(str, sizeof(str),
166  "config classification: %s,Unknown Classtype,%d\n",
167  parsed_ct_name, DETECT_DEFAULT_PRIO);
168 
169  if (SCClassConfAddClasstype(de_ctx, str, 0) < 0)
170  return -1;
171  ct = SCClassConfGetClasstype(parsed_ct_name, de_ctx);
172  if (ct == NULL)
173  return -1;
174  real_ct = false;
175  }
176 
177  /* set prio only if not already explicitly set by 'priority' keyword.
178  * update classtype in sig, but only if it is 'real' (not undefined)
179  * update sigs classtype if its prio is lower (but not undefined)
180  */
181 
182  bool update_ct = false;
184  /* don't touch Signature::prio */
185  update_ct = true;
186  } else if (s->prio == -1) {
187  s->prio = ct->priority;
188  update_ct = true;
189  } else {
190  if (ct->priority < s->prio) {
191  s->prio = ct->priority;
192  update_ct = true;
193  }
194  }
195 
196  if (real_ct && update_ct) {
197  s->class_id = ct->classtype_id;
198  s->class_msg = ct->classtype_desc;
199  }
200  return 0;
201 }
202 
203 #ifdef UNITTESTS
204 
205 /**
206  * \test undefined classtype
207  */
208 static int DetectClasstypeTest01(void)
209 {
212 
215  FAIL_IF_NULL(fd);
217  Signature *s = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
218  "(msg:\"Classtype test\"; "
219  "Classtype:not_available; sid:1;)");
220  FAIL_IF_NULL(s);
221  FAIL_IF_NOT(s->prio == 3);
222 
225  PASS;
226 }
227 
228 /**
229  * \test Check that both valid and invalid classtypes in a rule are handled
230  * properly, with rules containing invalid classtypes being rejected
231  * and the ones containing valid classtypes parsed and returned.
232  */
233 static int DetectClasstypeTest02(void)
234 {
237 
240  FAIL_IF_NULL(fd);
242 
243  Signature *sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
244  "(Classtype:bad-unknown; sid:1;)");
245  FAIL_IF_NULL(sig);
246 
247  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
248  "(Classtype:not-there; sid:2;)");
249  FAIL_IF_NULL(sig);
250 
251  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
252  "(Classtype:Bad-UnkNown; sid:3;)");
253  FAIL_IF_NULL(sig);
254 
255  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
256  "(Classtype:nothing-wrong; sid:4;)");
257  FAIL_IF_NULL(sig);
258 
259  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
260  "(Classtype:attempted_dos; Classtype:bad-unknown; sid:5;)");
261  FAIL_IF_NULL(sig);
262  FAIL_IF_NOT(sig->prio == 2);
263 
264  /* duplicate test */
265  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
266  "(Classtype:nothing-wrong; Classtype:Bad-UnkNown; sid:6;)");
267  FAIL_IF_NULL(sig);
268  FAIL_IF_NOT(sig->prio == 2);
269 
272  PASS;
273 }
274 
275 /**
276  * \test Check that the signatures are assigned priority based on classtype they
277  * are given.
278  */
279 static int DetectClasstypeTest03(void)
280 {
283 
286  FAIL_IF_NULL(fd);
288 
289  Signature *sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
290  "(msg:\"Classtype test\"; Classtype:bad-unknown; priority:1; sid:1;)");
291  FAIL_IF_NULL(sig);
292  FAIL_IF_NOT(sig->prio == 1);
293 
294  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
295  "(msg:\"Classtype test\"; Classtype:unKnoWn; "
296  "priority:3; sid:2;)");
297  FAIL_IF_NULL(sig);
298  FAIL_IF_NOT(sig->prio == 3);
299 
300  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any (msg:\"Classtype test\"; "
301  "Classtype:nothing-wrong; priority:1; sid:3;)");
302  FAIL_IF_NOT(sig->prio == 1);
303 
304  sig = DetectEngineAppendSig(de_ctx, "alert tcp any any -> any any "
305  "(msg:\"Classtype test\"; Classtype:bad-unknown; Classtype:undefined; "
306  "priority:5; sid:4;)");
307  FAIL_IF_NULL(sig);
308  FAIL_IF_NOT(sig->prio == 5);
309 
312  PASS;
313 }
314 
315 /**
316  * \brief This function registers unit tests for Classification Config API.
317  */
318 static void DetectClasstypeRegisterTests(void)
319 {
320  UtRegisterTest("DetectClasstypeTest01", DetectClasstypeTest01);
321  UtRegisterTest("DetectClasstypeTest02", DetectClasstypeTest02);
322  UtRegisterTest("DetectClasstypeTest03", DetectClasstypeTest03);
323 }
324 #endif /* UNITTESTS */
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
DetectParseRegex
Definition: detect-parse.h:94
SigTableElmt_::name
const char * name
Definition: detect.h:1542
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
detect-classtype.h
SIG_FLAG_INIT_PRIO_EXPLICIT
#define SIG_FLAG_INIT_PRIO_EXPLICIT
Definition: detect.h:302
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
SignatureInitData_::init_flags
uint32_t init_flags
Definition: detect.h:625
DetectParsePcreExec
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
Definition: detect-parse.c:4019
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
strlcpy
size_t strlcpy(char *dst, const char *src, size_t siz)
Definition: util-strlcpyu.c:43
decode.h
Signature_::class_id
uint16_t class_id
Definition: detect.h:723
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
util-error.h
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
SCClassConfClasstype_
Container for a Classtype from the Classification.config file.
Definition: util-classification-config.h:33
DetectSetupParseRegexes
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
Definition: detect-parse.c:4145
detect.h
SCClassConfClasstype_::classtype_id
uint16_t classtype_id
Definition: util-classification-config.h:35
SCClassConfAddClasstype
int SCClassConfAddClasstype(DetectEngineCtx *de_ctx, char *rawstr, uint16_t index)
Parses a line from the classification file and adds it to Classtype hash table in DetectEngineCtx,...
Definition: util-classification-config.c:233
SigMatchStrictEnabled
bool SigMatchStrictEnabled(const enum DetectKeywordId id)
Definition: detect-parse.c:372
SCLogWarning
#define SCLogWarning(...)
Macro used to log WARNING messages.
Definition: util-debug.h:262
SCClassConfGetClasstype
SCClassConfClasstype * SCClassConfGetClasstype(const char *ct_name, DetectEngineCtx *de_ctx)
Gets the classtype from the corresponding hash table stored in the Detection Engine Context's class c...
Definition: util-classification-config.c:556
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:775
Signature_::class_msg
char * class_msg
Definition: detect.h:767
DetectEngineCtx_::rule_file
const char * rule_file
Definition: detect.h:1094
suricata-common.h
util-classification-config.h
Signature_::prio
int prio
Definition: detect.h:744
SCClassConfClasstype_::priority
int priority
Definition: util-classification-config.h:38
DETECT_CLASSTYPE
@ DETECT_CLASSTYPE
Definition: detect-engine-register.h:31
str
#define str(s)
Definition: suricata-common.h:313
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
PARSE_REGEX
#define PARSE_REGEX
Definition: detect-classtype.c:38
Signature_::id
uint32_t id
Definition: detect.h:741
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
CLASSTYPE_NAME_MAX_LEN
#define CLASSTYPE_NAME_MAX_LEN
Definition: util-classification-config.h:27
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
SCClassConfClasstype_::classtype_desc
char * classtype_desc
Definition: util-classification-config.h:45
SCClassConfGenerateValidDummyClassConfigFD01
FILE * SCClassConfGenerateValidDummyClassConfigFD01(void)
Creates a dummy classification file, with all valid Classtypes, for testing purposes.
Definition: util-classification-config.c:586
DETECT_DEFAULT_PRIO
#define DETECT_DEFAULT_PRIO
Definition: detect.h:53
DetectEngineCtx_::rule_line
int rule_line
Definition: detect.h:1093
DetectClasstypeRegister
void DetectClasstypeRegister(void)
Registers the handler functions for the "Classtype" keyword.
Definition: detect-classtype.c:50
SCClassConfLoadClassificationConfigFile
bool SCClassConfLoadClassificationConfigFile(DetectEngineCtx *de_ctx, FILE *fd)
Loads the Classtype info from the classification.config file.
Definition: util-classification-config.c:519
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
SCClassConfDeInitContext
void SCClassConfDeInitContext(DetectEngineCtx *de_ctx)
Releases resources used by the Classification Config API.
Definition: util-classification-config.c:190