Go to the documentation of this file.
50 static void DsizeRegisterTests(
void);
55 static bool PrefilterDsizeIsPrefilterable(
const Signature *s);
123 "the same sig. Invalidating signature.");
144 SCLogDebug(
"dd->arg1 %" PRIu16
", dd->arg2 %" PRIu16
", dd->mode %" PRIu8
"", dd->arg1,
165 SCDetectU16Free(de_ptr);
174 if (!PrefilterPacketHeaderExtraMatch(
ctx,
p))
179 du16.mode =
ctx->v1.u8[0];
180 du16.arg1 =
ctx->v1.u16[1];
181 du16.arg2 =
ctx->v1.u16[2];
185 PrefilterAddSids(&det_ctx->
pmq,
ctx->sigs_array,
ctx->sigs_cnt);
195 static bool PrefilterDsizeIsPrefilterable(
const Signature *s)
235 uint16_t high = 65535;
268 SCLogDebug(
"low %u, high %u, mode %u", low, high, dd->mode);
302 if (total_length > dsize) {
303 SCLogDebug(
"required_dsize: %d exceeds dsize: %d", total_length, dsize);
307 if ((total_length +
offset) > dsize) {
308 SCLogDebug(
"length + offset: %d exceeds dsize: %d", total_length +
offset, dsize);
309 return total_length +
offset;
333 for ( ; sm != NULL; sm = sm->
next) {
345 cd->
depth = (uint16_t)dsize;
346 SCLogDebug(
"updated %u, content %u to have depth %u "
347 "because of dsize.", s->
id, cd->
id, cd->
depth);
367 static int DsizeTestParse01(
void)
374 DetectDsizeFree(NULL, dd);
382 static int DsizeTestParse02(
void)
388 DetectDsizeFree(NULL, dd);
396 static int DsizeTestParse03(
void)
403 DetectDsizeFree(NULL, dd);
411 static int DsizeTestParse04(
void)
419 DetectDsizeFree(NULL, dd);
427 static int DsizeTestParse05(
void)
435 DetectDsizeFree(NULL, dd);
443 static int DsizeTestParse06(
void)
450 DetectDsizeFree(NULL, dd);
458 static int DsizeTestParse07(
void)
465 DetectDsizeFree(NULL, dd);
473 static int DsizeTestParse08(
void)
480 DetectDsizeFree(NULL, dd);
488 static int DsizeTestParse09(
void)
492 DetectDsizeFree(NULL, dd);
500 static int DsizeTestParse10(
void)
504 DetectDsizeFree(NULL, dd);
513 static int DsizeTestParse11(
void)
515 const char *strings[] = {
"A",
">10<>10",
"<>10",
"1<>",
"",
" ",
"2<>1",
"1!", NULL };
516 for (
int i = 0; strings[i]; i++) {
528 static int DsizeTestMatch01(
void)
531 uint16_t dsizelow = 2;
532 uint16_t dsizehigh = 0;
535 du16.arg1 = dsizelow;
536 du16.arg2 = dsizehigh;
546 static int DsizeTestMatch02(
void)
549 uint16_t dsizelow = 1;
550 uint16_t dsizehigh = 0;
553 du16.arg1 = dsizelow;
554 du16.arg2 = dsizehigh;
565 static int DetectDsizeIcmpv6Test01(
void)
567 static uint8_t raw_icmpv6[] = {
568 0x60, 0x00, 0x00, 0x00, 0x00, 0x30, 0x3a, 0xff,
569 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
570 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
571 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
572 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
573 0x01, 0x00, 0x7b, 0x85, 0x00, 0x00, 0x00, 0x00,
574 0x60, 0x4b, 0xe8, 0xbd, 0x00, 0x00, 0x3b, 0xff,
575 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
576 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
577 0xff, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
578 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 };
603 "alert icmp any any -> any any "
604 "(msg:\"ICMP Large ICMP Packet\"; dsize:>8; sid:1; rev:4;)");
608 "alert icmp any any -> any any "
609 "(msg:\"ICMP Large ICMP Packet\"; dsize:>800; sid:2; rev:4;)");
631 static void DsizeRegisterTests(
void)
647 UtRegisterTest(
"DetectDsizeIcmpv6Test01", DetectDsizeIcmpv6Test01);
void DetectDsizeRegister(void)
Registration function for dsize: keyword.
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
#define SIG_MASK_REQUIRE_REAL_PKT
struct SigMatch_ * smlists[DETECT_SM_LIST_MAX]
void PrefilterPacketU16Set(PrefilterPacketHeaderValue *v, void *smctx)
SigTableElmt * sigmatch_table
void(* Free)(DetectEngineCtx *, void *)
#define PKT_IS_PSEUDOPKT(p)
return 1 if the packet is a pseudo packet
Container for matching data for a signature group.
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
SigMatch * SCDetectGetLastSMFromLists(const Signature *s,...)
Returns the sm with the largest index (added latest) from the lists passed to us.
main detection engine ctx
int SigParseGetMaxDsize(const Signature *s, uint16_t *dsize)
get max dsize "depth"
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
void FlowInitConfig(bool quiet)
initialize the configuration
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
#define SIGMATCH_INFO_UINT16
#define PASS
Pass the test.
#define DETECT_CONTENT_DEPTH
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Per thread variable structure.
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
void PacketFree(Packet *p)
Return a malloced packet.
void SigParseSetDsizePair(Signature *s)
set prefilter dsize pair
void SigParseRequiredContentSize(const Signature *s, const uint64_t max_size, const SigMatch *sm, int *len, int *offset)
Determine the size needed to accommodate the content elements of a signature.
SignatureInitData * init_data
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
int DecodeIPV6(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
void StatsThreadInit(StatsThreadContext *stats)
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
int DetectU16Match(const uint16_t parg, const DetectUintData_u16 *du16)
DetectUintData_u16 * DetectU16Parse(const char *u16str)
This function is used to parse u16 options passed via some u16 keyword.
bool PrefilterPacketU16Compare(PrefilterPacketHeaderValue v, void *smctx)
void FlowShutdown(void)
shutdown the flow engine
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
#define SCLogError(...)
Macro used to log ERROR messages.
Structure to hold thread specific data for all decode modules.
bool(* SupportsPrefilter)(const Signature *s)
a single match condition for a signature
DetectEngineCtx * DetectEngineCtxInit(void)
#define SIGMATCH_SUPPORT_FIREWALL
void SigParseApplyDsizeToContent(Signature *s)
Apply dsize as depth to content matches in the rule.
DetectUintData_u16 DetectU16Data
int SigParseMaxRequiredDsize(const Signature *s)
Determine the required dsize for the signature.
void StatsThreadCleanup(StatsThreadContext *stats)
#define DEBUG_VALIDATE_BUG_ON(exp)
void(* RegisterTests)(void)
#define SIG_FLAG_REQUIRE_PACKET