suricata
detect-dsize.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Implements the dsize keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-parse.h"
32 #include "detect-engine-build.h"
33 
34 #include "flow-var.h"
35 
36 #include "detect-content.h"
37 #include "detect-dsize.h"
38 
39 #include "util-debug.h"
40 #include "util-byte.h"
41 
42 #include "pkt-var.h"
43 #include "host.h"
44 #include "util-profiling.h"
45 
46 static int DetectDsizeMatch (DetectEngineThreadCtx *, Packet *,
47  const Signature *, const SigMatchCtx *);
48 static int DetectDsizeSetup (DetectEngineCtx *, Signature *s, const char *str);
49 #ifdef UNITTESTS
50 static void DsizeRegisterTests(void);
51 #endif
52 static void DetectDsizeFree(DetectEngineCtx *, void *);
53 
54 static int PrefilterSetupDsize(DetectEngineCtx *de_ctx, SigGroupHead *sgh);
55 static bool PrefilterDsizeIsPrefilterable(const Signature *s);
56 
57 /**
58  * \brief Registration function for dsize: keyword
59  */
61 {
62  sigmatch_table[DETECT_DSIZE].name = "dsize";
63  sigmatch_table[DETECT_DSIZE].desc = "match on the size of the packet payload";
64  sigmatch_table[DETECT_DSIZE].url = "/rules/payload-keywords.html#dsize";
65  sigmatch_table[DETECT_DSIZE].Match = DetectDsizeMatch;
66  sigmatch_table[DETECT_DSIZE].Setup = DetectDsizeSetup;
67  sigmatch_table[DETECT_DSIZE].Free = DetectDsizeFree;
69 #ifdef UNITTESTS
70  sigmatch_table[DETECT_DSIZE].RegisterTests = DsizeRegisterTests;
71 #endif
72  sigmatch_table[DETECT_DSIZE].SupportsPrefilter = PrefilterDsizeIsPrefilterable;
73  sigmatch_table[DETECT_DSIZE].SetupPrefilter = PrefilterSetupDsize;
74 }
75 
76 /**
77  * \internal
78  * \brief This function is used to match flags on a packet with those passed via dsize:
79  *
80  * \param t pointer to thread vars
81  * \param det_ctx pointer to the pattern matcher thread
82  * \param p pointer to the current packet
83  * \param s pointer to the Signature
84  * \param m pointer to the sigmatch
85  *
86  * \retval 0 no match
87  * \retval 1 match
88  */
89 static int DetectDsizeMatch (DetectEngineThreadCtx *det_ctx, Packet *p,
90  const Signature *s, const SigMatchCtx *ctx)
91 {
92  SCEnter();
93  int ret = 0;
94 
96 
97  const DetectU16Data *dd = (const DetectU16Data *)ctx;
98 
99  SCLogDebug("p->payload_len %"PRIu16"", p->payload_len);
100 
101  ret = DetectU16Match(p->payload_len, dd);
102 
103  SCReturnInt(ret);
104 }
105 
106 /**
107  * \internal
108  * \brief this function is used to add the parsed dsize into the current signature
109  *
110  * \param de_ctx pointer to the Detection Engine Context
111  * \param s pointer to the Current Signature
112  * \param rawstr pointer to the user provided flags options
113  *
114  * \retval 0 on Success
115  * \retval -1 on Failure
116  */
117 static int DetectDsizeSetup (DetectEngineCtx *de_ctx, Signature *s, const char *rawstr)
118 {
119  DetectU16Data *dd = NULL;
120 
122  SCLogError("Can't use 2 or more dsizes in "
123  "the same sig. Invalidating signature.");
124  return -1;
125  }
126 
127  SCLogDebug("\'%s\'", rawstr);
128 
129  dd = DetectU16Parse(rawstr);
130  if (dd == NULL) {
131  SCLogError("Parsing \'%s\' failed", rawstr);
132  return -1;
133  }
134 
135  /* Okay so far so good, lets get this into a SigMatch
136  * and put it in the Signature. */
139  if (sm == NULL) {
140  SCDetectU16Free(dd);
141  return -1;
142  }
143 
144  SCLogDebug("dd->arg1 %" PRIu16 ", dd->arg2 %" PRIu16 ", dd->mode %" PRIu8 "", dd->arg1,
145  dd->arg2, dd->mode);
146  /* tell the sig it has a dsize to speed up engine init */
148  s->flags |= SIG_FLAG_DSIZE;
149 
150  if (s->init_data->dsize_sm == NULL) {
151  s->init_data->dsize_sm = sm;
152  }
153 
154  return 0;
155 }
156 
157 /**
158  * \internal
159  * \brief this function will free memory associated with DetectU16Data
160  *
161  * \param de pointer to DetectU16Data
162  */
163 void DetectDsizeFree(DetectEngineCtx *de_ctx, void *de_ptr)
164 {
165  SCDetectU16Free(de_ptr);
166 }
167 
168 /* prefilter code */
169 
170 static void
171 PrefilterPacketDsizeMatch(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx)
172 {
173  const PrefilterPacketHeaderCtx *ctx = pectx;
174  if (!PrefilterPacketHeaderExtraMatch(ctx, p))
175  return;
176 
177  const uint16_t dsize = p->payload_len;
178  DetectU16Data du16;
179  du16.mode = ctx->v1.u8[0];
180  du16.arg1 = ctx->v1.u16[1];
181  du16.arg2 = ctx->v1.u16[2];
182 
183  if (DetectU16Match(dsize, &du16)) {
184  SCLogDebug("packet matches dsize %u", dsize);
185  PrefilterAddSids(&det_ctx->pmq, ctx->sigs_array, ctx->sigs_cnt);
186  }
187 }
188 
189 static int PrefilterSetupDsize(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
190 {
192  PrefilterPacketU16Set, PrefilterPacketU16Compare, PrefilterPacketDsizeMatch);
193 }
194 
195 static bool PrefilterDsizeIsPrefilterable(const Signature *s)
196 {
197  return PrefilterIsPrefilterableById(s, DETECT_DSIZE);
198 }
199 
200 /** \brief get max dsize "depth"
201  * \param s signature to get dsize value from
202  * \retval depth or negative value
203  */
204 int SigParseGetMaxDsize(const Signature *s, uint16_t *dsize)
205 {
206  if (s->flags & SIG_FLAG_DSIZE && s->init_data->dsize_sm != NULL) {
207  const DetectU16Data *dd = (const DetectU16Data *)s->init_data->dsize_sm->ctx;
208 
209  switch (dd->mode) {
210  case DETECT_UINT_LT:
211  case DETECT_UINT_EQ:
212  case DETECT_UINT_NE:
213  *dsize = dd->arg1;
214  SCReturnInt(0);
215  case DETECT_UINT_RA:
216  *dsize = dd->arg2;
217  SCReturnInt(0);
218  case DETECT_UINT_GT:
219  default:
220  SCReturnInt(-2);
221  }
222  }
223  SCReturnInt(-1);
224 }
225 
226 /** \brief set prefilter dsize pair
227  * \param s signature to get dsize value from
228  */
230 {
231  if (s->flags & SIG_FLAG_DSIZE && s->init_data->dsize_sm != NULL) {
232  const DetectU16Data *dd = (const DetectU16Data *)s->init_data->dsize_sm->ctx;
233 
234  uint16_t low = 0;
235  uint16_t high = 65535;
236 
237  switch (dd->mode) {
238  case DETECT_UINT_LT:
239  low = 0;
240  high = dd->arg1;
241  break;
242  case DETECT_UINT_LTE:
243  low = 0;
244  high = dd->arg1 + 1;
245  break;
246  case DETECT_UINT_EQ:
247  case DETECT_UINT_NE:
248  low = dd->arg1;
249  high = dd->arg1;
250  break;
251  case DETECT_UINT_RA:
252  low = dd->arg1;
253  high = dd->arg2;
254  break;
255  case DETECT_UINT_GT:
256  low = dd->arg1;
257  high = 65535;
258  break;
259  case DETECT_UINT_GTE:
260  low = dd->arg1 - 1;
261  high = 65535;
262  break;
263  }
264  s->dsize_mode = dd->mode;
265  s->dsize_low = low;
266  s->dsize_high = high;
267 
268  SCLogDebug("low %u, high %u, mode %u", low, high, dd->mode);
269  }
270 }
271 
272 /**
273  * \brief Determine the required dsize for the signature
274  * \param s signature to get dsize value from
275  *
276  * Note that negated content does not contribute to the maximum
277  * required dsize value. However, each negated content's values
278  * must not exceed the dsize value. See SigParseRequiredContentSize.
279  *
280  * \retval -1 Signature doesn't have a dsize keyword
281  * \retval >= 0 Dsize value required to not exclude content matches
282  */
284 {
285  SCEnter();
286 
287  if (!(s->flags & SIG_FLAG_DSIZE)) {
288  SCReturnInt(-1);
289  }
290 
291  uint16_t dsize;
292  if (SigParseGetMaxDsize(s, &dsize) < 0) {
293  /* nothing to do */
294  SCReturnInt(-1);
295  }
296 
297  int total_length, offset;
299  s, dsize, s->init_data->smlists[DETECT_SM_LIST_PMATCH], &total_length, &offset);
300  SCLogDebug("dsize: %d len: %d; offset: %d [%s]", dsize, total_length, offset, s->sig_str);
301 
302  if (total_length > dsize) {
303  SCLogDebug("required_dsize: %d exceeds dsize: %d", total_length, dsize);
304  return total_length;
305  }
306 
307  if ((total_length + offset) > dsize) {
308  SCLogDebug("length + offset: %d exceeds dsize: %d", total_length + offset, dsize);
309  return total_length + offset;
310  }
311 
312  SCReturnInt(-1);
313 }
314 
315 /**
316  * \brief Apply dsize as depth to content matches in the rule
317  * \param s signature to get dsize value from
318  */
320 {
321  SCEnter();
322 
323  if (s->flags & SIG_FLAG_DSIZE) {
325 
326  uint16_t dsize;
327  if (SigParseGetMaxDsize(s, &dsize) < 0) {
328  /* nothing to do */
329  return;
330  }
331 
333  for ( ; sm != NULL; sm = sm->next) {
334  if (sm->type != DETECT_CONTENT) {
335  continue;
336  }
337 
339  if (cd == NULL) {
340  continue;
341  }
342 
343  if (cd->depth == 0 || cd->depth >= dsize) {
345  cd->depth = (uint16_t)dsize;
346  SCLogDebug("updated %u, content %u to have depth %u "
347  "because of dsize.", s->id, cd->id, cd->depth);
348  }
349  }
350  }
351 }
352 
353 /*
354  * ONLY TESTS BELOW THIS COMMENT
355  */
356 
357 #ifdef UNITTESTS
358 #include "util-unittest-helper.h"
359 #include "detect-engine.h"
360 #include "detect-engine-alert.h"
361 #include "packet.h"
362 
363 /**
364  * \test this is a test for a valid dsize value 1
365  *
366  */
367 static int DsizeTestParse01(void)
368 {
369  DetectU16Data *dd = DetectU16Parse("1");
370  FAIL_IF_NULL(dd);
371  FAIL_IF_NOT(dd->arg1 == 1);
372  FAIL_IF_NOT(dd->arg2 == 0);
373 
374  DetectDsizeFree(NULL, dd);
375  PASS;
376 }
377 
378 /**
379  * \test this is a test for a valid dsize value >10
380  *
381  */
382 static int DsizeTestParse02(void)
383 {
384  DetectU16Data *dd = DetectU16Parse(">10");
385  FAIL_IF_NULL(dd);
386  FAIL_IF_NOT(dd->arg1 == 10);
387  FAIL_IF_NOT(dd->mode == DETECT_UINT_GT);
388  DetectDsizeFree(NULL, dd);
389  PASS;
390 }
391 
392 /**
393  * \test this is a test for a valid dsize value <100
394  *
395  */
396 static int DsizeTestParse03(void)
397 {
398  DetectU16Data *dd = DetectU16Parse("<100");
399  FAIL_IF_NULL(dd);
400  FAIL_IF_NOT(dd->arg1 == 100);
401  FAIL_IF_NOT(dd->mode == DETECT_UINT_LT);
402 
403  DetectDsizeFree(NULL, dd);
404  PASS;
405 }
406 
407 /**
408  * \test this is a test for a valid dsize value 1<>3
409  *
410  */
411 static int DsizeTestParse04(void)
412 {
413  DetectU16Data *dd = DetectU16Parse("1<>3");
414  FAIL_IF_NULL(dd);
415  FAIL_IF_NOT(dd->arg1 == 1);
416  FAIL_IF_NOT(dd->arg2 == 3);
417  FAIL_IF_NOT(dd->mode == DETECT_UINT_RA);
418 
419  DetectDsizeFree(NULL, dd);
420  PASS;
421 }
422 
423 /**
424  * \test this is a test for a valid dsize value 1 <> 3
425  *
426  */
427 static int DsizeTestParse05(void)
428 {
429  DetectU16Data *dd = DetectU16Parse(" 1 <> 3 ");
430  FAIL_IF_NULL(dd);
431  FAIL_IF_NOT(dd->arg1 == 1);
432  FAIL_IF_NOT(dd->arg2 == 3);
433  FAIL_IF_NOT(dd->mode == DETECT_UINT_RA);
434 
435  DetectDsizeFree(NULL, dd);
436  PASS;
437 }
438 
439 /**
440  * \test this is test for a valid dsize value > 2
441  *
442  */
443 static int DsizeTestParse06(void)
444 {
445  DetectU16Data *dd = DetectU16Parse("> 2 ");
446  FAIL_IF_NULL(dd);
447  FAIL_IF_NOT(dd->arg1 == 2);
448  FAIL_IF_NOT(dd->mode == DETECT_UINT_GT);
449 
450  DetectDsizeFree(NULL, dd);
451  PASS;
452 }
453 
454 /**
455  * \test test for a valid dsize value < 12
456  *
457  */
458 static int DsizeTestParse07(void)
459 {
460  DetectU16Data *dd = DetectU16Parse("< 12 ");
461  FAIL_IF_NULL(dd);
462  FAIL_IF_NOT(dd->arg1 == 12);
463  FAIL_IF_NOT(dd->mode == DETECT_UINT_LT);
464 
465  DetectDsizeFree(NULL, dd);
466  PASS;
467 }
468 
469 /**
470  * \test test for a valid dsize value 12
471  *
472  */
473 static int DsizeTestParse08(void)
474 {
475  DetectU16Data *dd = DetectU16Parse(" 12 ");
476  FAIL_IF_NULL(dd);
477  FAIL_IF_NOT(dd->arg1 == 12);
478  FAIL_IF_NOT(dd->mode == DETECT_UINT_EQ);
479 
480  DetectDsizeFree(NULL, dd);
481  PASS;
482 }
483 
484 /**
485  * \test this is a test for a valid dsize value !1
486  *
487  */
488 static int DsizeTestParse09(void)
489 {
490  DetectU16Data *dd = DetectU16Parse("!1");
491  FAIL_IF_NULL(dd);
492  DetectDsizeFree(NULL, dd);
493  PASS;
494 }
495 
496 /**
497  * \test this is a test for a valid dsize value ! 1
498  *
499  */
500 static int DsizeTestParse10(void)
501 {
502  DetectU16Data *dd = DetectU16Parse("! 1");
503  FAIL_IF_NULL(dd);
504  DetectDsizeFree(NULL, dd);
505  PASS;
506 }
507 
508 /**
509  * \test this is a test for invalid dsize values
510  * A, >10<>10, <>10, 1<>, "", " ", 2<>1, 1!
511  *
512  */
513 static int DsizeTestParse11(void)
514 {
515  const char *strings[] = { "A", ">10<>10", "<>10", "1<>", "", " ", "2<>1", "1!", NULL };
516  for (int i = 0; strings[i]; i++) {
517  DetectU16Data *dd = DetectU16Parse(strings[i]);
518  FAIL_IF_NOT_NULL(dd);
519  }
520 
521  PASS;
522 }
523 
524 /**
525  * \test this is a test for positive ! dsize matching
526  *
527  */
528 static int DsizeTestMatch01(void)
529 {
530  uint16_t psize = 1;
531  uint16_t dsizelow = 2;
532  uint16_t dsizehigh = 0;
533  DetectU16Data du16;
534  du16.mode = DETECT_UINT_NE;
535  du16.arg1 = dsizelow;
536  du16.arg2 = dsizehigh;
537  FAIL_IF_NOT(DetectU16Match(psize, &du16));
538 
539  PASS;
540 }
541 
542 /**
543  * \test this is a test for negative ! dsize matching
544  *
545  */
546 static int DsizeTestMatch02(void)
547 {
548  uint16_t psize = 1;
549  uint16_t dsizelow = 1;
550  uint16_t dsizehigh = 0;
551  DetectU16Data du16;
552  du16.mode = DETECT_UINT_NE;
553  du16.arg1 = dsizelow;
554  du16.arg2 = dsizehigh;
555  FAIL_IF(DetectU16Match(psize, &du16));
556 
557  PASS;
558 }
559 
560 /**
561  * \test DetectDsizeIcmpv6Test01 is a test for checking the working of
562  * dsize keyword by creating 2 rules and matching a crafted packet
563  * against them. Only the first one shall trigger.
564  */
565 static int DetectDsizeIcmpv6Test01(void)
566 {
567  static uint8_t raw_icmpv6[] = {
568  0x60, 0x00, 0x00, 0x00, 0x00, 0x30, 0x3a, 0xff,
569  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
570  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
571  0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
572  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
573  0x01, 0x00, 0x7b, 0x85, 0x00, 0x00, 0x00, 0x00,
574  0x60, 0x4b, 0xe8, 0xbd, 0x00, 0x00, 0x3b, 0xff,
575  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
576  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
577  0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
578  0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 };
579 
581  FAIL_IF_NULL(p);
582 
585  DetectEngineThreadCtx *det_ctx = NULL;
586 
587  memset(&dtv, 0, sizeof(DecodeThreadVars));
588  memset(&th_v, 0, sizeof(ThreadVars));
590 
592  p->src.family = AF_INET6;
593  p->dst.family = AF_INET6;
594 
595  DecodeIPV6(&th_v, &dtv, p, raw_icmpv6, sizeof(raw_icmpv6));
596 
599 
600  de_ctx->flags |= DE_QUIET;
601 
603  "alert icmp any any -> any any "
604  "(msg:\"ICMP Large ICMP Packet\"; dsize:>8; sid:1; rev:4;)");
605  FAIL_IF_NULL(s);
606 
608  "alert icmp any any -> any any "
609  "(msg:\"ICMP Large ICMP Packet\"; dsize:>800; sid:2; rev:4;)");
610  FAIL_IF_NULL(s);
611 
613  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
614 
615  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
616  FAIL_IF(PacketAlertCheck(p, 1) == 0);
618 
619  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
621 
622  PacketFree(p);
623  FlowShutdown();
625  PASS;
626 }
627 
628 /**
629  * \brief this function registers unit tests for dsize
630  */
631 static void DsizeRegisterTests(void)
632 {
633  UtRegisterTest("DsizeTestParse01", DsizeTestParse01);
634  UtRegisterTest("DsizeTestParse02", DsizeTestParse02);
635  UtRegisterTest("DsizeTestParse03", DsizeTestParse03);
636  UtRegisterTest("DsizeTestParse04", DsizeTestParse04);
637  UtRegisterTest("DsizeTestParse05", DsizeTestParse05);
638  UtRegisterTest("DsizeTestParse06", DsizeTestParse06);
639  UtRegisterTest("DsizeTestParse07", DsizeTestParse07);
640  UtRegisterTest("DsizeTestParse08", DsizeTestParse08);
641  UtRegisterTest("DsizeTestParse09", DsizeTestParse09);
642  UtRegisterTest("DsizeTestParse10", DsizeTestParse10);
643  UtRegisterTest("DsizeTestParse11", DsizeTestParse11);
644  UtRegisterTest("DsizeTestMatch01", DsizeTestMatch01);
645  UtRegisterTest("DsizeTestMatch02", DsizeTestMatch02);
646 
647  UtRegisterTest("DetectDsizeIcmpv6Test01", DetectDsizeIcmpv6Test01);
648 }
649 #endif /* UNITTESTS */
util-byte.h
host.h
DetectDsizeRegister
void DetectDsizeRegister(void)
Registration function for dsize: keyword.
Definition: detect-dsize.c:60
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-content.h
detect-engine.h
DETECT_SM_LIST_PMATCH
@ DETECT_SM_LIST_PMATCH
Definition: detect.h:120
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
SIG_MASK_REQUIRE_REAL_PKT
#define SIG_MASK_REQUIRE_REAL_PKT
Definition: detect.h:320
SignatureInitData_::smlists
struct SigMatch_ * smlists[DETECT_SM_LIST_MAX]
Definition: detect.h:666
PrefilterPacketU16Set
void PrefilterPacketU16Set(PrefilterPacketHeaderValue *v, void *smctx)
Definition: detect-engine-uint.c:124
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
detect-dsize.h
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
Signature_::sig_str
char * sig_str
Definition: detect.h:773
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
PKT_IS_PSEUDOPKT
#define PKT_IS_PSEUDOPKT(p)
return 1 if the packet is a pseudo packet
Definition: decode.h:1364
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
DETECT_UINT_LT
#define DETECT_UINT_LT
Definition: detect-engine-uint.h:37
DETECT_CONTENT
@ DETECT_CONTENT
Definition: detect-engine-register.h:78
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
DETECT_UINT_NE
#define DETECT_UINT_NE
Definition: detect-engine-uint.h:36
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
SCDetectGetLastSMFromLists
SigMatch * SCDetectGetLastSMFromLists(const Signature *s,...)
Returns the sm with the largest index (added latest) from the lists passed to us.
Definition: detect-parse.c:600
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
SigParseGetMaxDsize
int SigParseGetMaxDsize(const Signature *s, uint16_t *dsize)
get max dsize "depth"
Definition: detect-dsize.c:204
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
DETECT_UINT_EQ
#define DETECT_UINT_EQ
Definition: detect-engine-uint.h:35
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
DetectContentData_
Definition: detect-content.h:93
DETECT_UINT_GT
#define DETECT_UINT_GT
Definition: detect-engine-uint.h:32
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
Signature_::dsize_low
uint16_t dsize_low
Definition: detect.h:699
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
SigTableElmt_::SetupPrefilter
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
Definition: detect.h:1527
FlowInitConfig
void FlowInitConfig(bool quiet)
initialize the configuration
Definition: flow.c:574
PrefilterPacketHeaderCtx_
Definition: detect-engine-prefilter-common.h:35
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
SIGMATCH_INFO_UINT16
#define SIGMATCH_INFO_UINT16
Definition: detect-engine-register.h:344
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
DETECT_CONTENT_DEPTH
#define DETECT_CONTENT_DEPTH
Definition: detect-content.h:33
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
pkt-var.h
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
SigMatch_::next
struct SigMatch_ * next
Definition: detect.h:364
PacketFree
void PacketFree(Packet *p)
Return a malloced packet.
Definition: decode.c:221
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
DetectContentData_::id
PatIntId id
Definition: detect-content.h:105
SigMatch_::ctx
SigMatchCtx * ctx
Definition: detect.h:363
SigParseSetDsizePair
void SigParseSetDsizePair(Signature *s)
set prefilter dsize pair
Definition: detect-dsize.c:229
util-profiling.h
Signature_::flags
uint32_t flags
Definition: detect.h:693
DetectContentData_::depth
uint16_t depth
Definition: detect-content.h:106
Packet_
Definition: decode.h:516
detect-engine-build.h
DETECT_UINT_GTE
#define DETECT_UINT_GTE
Definition: detect-engine-uint.h:33
SigParseRequiredContentSize
void SigParseRequiredContentSize(const Signature *s, const uint64_t max_size, const SigMatch *sm, int *len, int *offset)
Determine the size needed to accommodate the content elements of a signature.
Definition: detect-content.c:404
detect-engine-alert.h
DetectContentData_::flags
uint32_t flags
Definition: detect-content.h:104
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:775
PrefilterSetupPacketHeader
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
Definition: detect-engine-prefilter-common.c:470
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
DETECT_DSIZE
@ DETECT_DSIZE
Definition: detect-engine-register.h:59
DecodeIPV6
int DecodeIPV6(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Definition: decode-ipv6.c:551
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
SignatureInitData_::dsize_sm
SigMatch * dsize_sm
Definition: detect.h:632
th_v
ThreadVars * th_v
Definition: fuzz_dataset.c:29
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
DetectU16Match
int DetectU16Match(const uint16_t parg, const DetectUintData_u16 *du16)
Definition: detect-engine-uint.c:105
DetectU16Parse
DetectUintData_u16 * DetectU16Parse(const char *u16str)
This function is used to parse u16 options passed via some u16 keyword.
Definition: detect-engine-uint.c:119
PrefilterPacketU16Compare
bool PrefilterPacketU16Compare(PrefilterPacketHeaderValue v, void *smctx)
Definition: detect-engine-uint.c:132
suricata-common.h
SigMatch_::type
uint16_t type
Definition: detect.h:361
Signature_::dsize_high
uint16_t dsize_high
Definition: detect.h:700
FlowShutdown
void FlowShutdown(void)
shutdown the flow engine
Definition: flow.c:718
packet.h
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
PacketGetFromAlloc
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
Definition: decode.c:260
DETECT_UINT_LTE
#define DETECT_UINT_LTE
Definition: detect-engine-uint.h:38
str
#define str(s)
Definition: suricata-common.h:313
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
SigTableElmt_::SupportsPrefilter
bool(* SupportsPrefilter)(const Signature *s)
Definition: detect.h:1526
Signature_::id
uint32_t id
Definition: detect.h:741
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
SigMatch_
a single match condition for a signature
Definition: detect.h:360
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
Signature_::dsize_mode
uint8_t dsize_mode
Definition: detect.h:701
SIGMATCH_SUPPORT_FIREWALL
#define SIGMATCH_SUPPORT_FIREWALL
Definition: detect-engine-register.h:336
Address_::family
char family
Definition: decode.h:114
Packet_::dst
Address dst
Definition: decode.h:521
FLOW_QUIET
#define FLOW_QUIET
Definition: flow.h:43
SigParseApplyDsizeToContent
void SigParseApplyDsizeToContent(Signature *s)
Apply dsize as depth to content matches in the rule.
Definition: detect-dsize.c:319
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
detect-engine-prefilter-common.h
DetectU16Data
DetectUintData_u16 DetectU16Data
Definition: detect-engine-uint.h:42
SigParseMaxRequiredDsize
int SigParseMaxRequiredDsize(const Signature *s)
Determine the required dsize for the signature.
Definition: detect-dsize.c:283
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
flow-var.h
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
Packet_::src
Address src
Definition: decode.h:520
DETECT_UINT_RA
#define DETECT_UINT_RA
Definition: detect-engine-uint.h:34
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
SIG_FLAG_DSIZE
#define SIG_FLAG_DSIZE
Definition: detect.h:251
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257