detect-dsize.c File Reference
#include "suricata-common.h"
#include "decode.h"
#include "detect.h"
#include "detect-parse.h"
#include "detect-engine-prefilter-common.h"
#include "flow-var.h"
#include "detect-content.h"
#include "detect-dsize.h"
#include "util-unittest.h"
#include "util-debug.h"
#include "util-byte.h"
#include "pkt-var.h"
#include "host.h"
#include "util-profiling.h"
#include "detect-engine.h"
#define PARSE_REGEX   "^\\s*(<|>|!)?\\s*([0-9]{1,5})\\s*(?:(<>)\\s*([0-9]{1,5}))?\\s*$"


void DetectDsizeRegister (void)
 Registration function for dsize: keyword. More...
int SigParseGetMaxDsize (const Signature *s)
 get max dsize "depth" More...
void SigParseSetDsizePair (Signature *s)
 set prefilter dsize pair More...
void SigParseApplyDsizeToContent (Signature *s)
 Apply dsize as depth to content matches in the rule. More...

Detailed Description

Victor Julien

Implements the dsize keyword

Definition in file detect-dsize.c.

Macro Definition Documentation


#define PARSE_REGEX   "^\\s*(<|>|!)?\\s*([0-9]{1,5})\\s*(?:(<>)\\s*([0-9]{1,5}))?\\s*$"


Definition at line 50 of file detect-dsize.c.

Function Documentation

◆ DetectDsizeRegister()

void DetectDsizeRegister ( void  )

Registration function for dsize: keyword.

Definition at line 66 of file detect-dsize.c.

References SigTableElmt_::desc, DETECT_DSIZE, SigTableElmt_::Match, SigTableElmt_::name, sigmatch_table, and SigTableElmt_::url.

Referenced by SigTableSetup().

◆ SigParseApplyDsizeToContent()

void SigParseApplyDsizeToContent ( Signature s)

◆ SigParseGetMaxDsize()

int SigParseGetMaxDsize ( const Signature s)

get max dsize "depth"

ssignature to get dsize value from
Return values
depthor negative value

Definition at line 391 of file detect-dsize.c.

References SigMatch_::ctx, DETECTDSIZE_EQ, DETECTDSIZE_GT, DETECTDSIZE_LT, DETECTDSIZE_NE, DETECTDSIZE_RA, DetectDsizeData_::dsize, DetectDsizeData_::dsize2, SignatureInitData_::dsize_sm, Signature_::flags, Signature_::init_data, DetectDsizeData_::mode, SCReturnInt, and SIG_FLAG_DSIZE.

Referenced by DetectContentPMATCHValidateCallback(), and SigParseApplyDsizeToContent().

◆ SigParseSetDsizePair()

void SigParseSetDsizePair ( Signature s)