Go to the documentation of this file.
63 static int rule_warnings_only = 0;
119 { 0,
false,
false,
true,
"http_uri",
"http uri" },
120 { 0,
false,
false,
false,
"http_raw_uri",
"http raw uri" },
121 { 0,
false,
true,
false,
"http_method",
"http method" },
122 { 0,
false,
false,
false,
"http_request_line",
"http request line" },
123 { 0,
false,
false,
false,
"http_client_body",
"http client body" },
124 { 0,
false,
false,
true,
"http_header",
"http header" },
125 { 0,
false,
false,
false,
"http_raw_header",
"http raw header" },
126 { 0,
false,
false,
true,
"http_cookie",
"http cookie" },
127 { 0,
false,
false,
false,
"http_user_agent",
"http user agent" },
128 { 0,
false,
false,
false,
"http_host",
"http host" },
129 { 0,
false,
false,
false,
"http_raw_host",
"http raw host" },
130 { 0,
false,
false,
false,
"http_accept_enc",
"http accept enc" },
131 { 0,
false,
false,
false,
"http_referer",
"http referer" },
132 { 0,
false,
false,
false,
"http_content_type",
"http content type" },
133 { 0,
false,
false,
false,
"http_header_names",
"http header names" },
136 { 0,
false,
false,
false,
"http_stat_msg",
"http stat msg" },
137 { 0,
false,
false,
false,
"http_stat_code",
"http stat code" },
138 { 0,
false,
true,
false,
"file_data",
"http server body" },
141 { 0,
false,
false,
false,
"http_request_line",
"http request line" },
142 { 0,
false,
false,
false,
"http_accept",
"http accept" },
143 { 0,
false,
false,
false,
"http_accept_lang",
"http accept lang" },
144 { 0,
false,
false,
false,
"http_connection",
"http connection" },
145 { 0,
false,
false,
false,
"http_content_len",
"http content len" },
146 { 0,
false,
false,
false,
"http_protocol",
"http protocol" },
147 { 0,
false,
false,
false,
"http_start",
"http start" },
150 { 0,
false,
false,
false,
"http_response_line",
"http response line" },
151 { 0,
false,
false,
false,
"http.server",
"http server" },
152 { 0,
false,
false,
false,
"http.location",
"http location" },
155 static void FpPatternStatsAdd(
FpPatternStats *fp,
int list, uint16_t patlen)
164 else if (patlen < f->min)
176 int fast_pattern_set = 0;
177 int fast_pattern_only_set = 0;
178 int fast_pattern_chop_set = 0;
183 if (mpm_sm != NULL) {
186 fast_pattern_set = 1;
188 fast_pattern_only_set = 1;
190 fast_pattern_chop_set = 1;
196 fprintf(fp,
"== Sid: %u ==\n", s->
id);
197 fprintf(fp,
"%s\n", line);
199 fprintf(fp,
" Fast Pattern analysis:\n");
201 fprintf(fp,
" Prefilter on: %s\n",
208 fprintf(fp,
" No content present\n");
213 fprintf(fp,
" Fast pattern matcher: ");
214 int list_type = mpm_sm_list;
216 fprintf(fp,
"content\n");
221 fprintf(fp,
"%s (%s)\n", desc,
name);
226 fprintf(fp,
" Flags:");
228 fprintf(fp,
" Offset");
231 fprintf(fp,
" Depth");
235 fprintf(fp,
" Within");
239 fprintf(fp,
" Distance");
243 fprintf(fp,
" Nocase");
247 fprintf(fp,
" Negated");
251 fprintf(fp,
" None");
254 fprintf(fp,
" Fast pattern set: %s\n", fast_pattern_set ?
"yes" :
"no");
255 fprintf(fp,
" Fast pattern only set: %s\n", fast_pattern_only_set ?
"yes" :
"no");
256 fprintf(fp,
" Fast pattern chop set: %s\n", fast_pattern_chop_set ?
"yes" :
"no");
257 if (fast_pattern_chop_set) {
258 fprintf(fp,
" Fast pattern offset, length: %u, %u\n", fp_cd->
fp_chop_offset,
269 fprintf(fp,
" Original content: ");
273 if (fast_pattern_chop_set) {
282 fprintf(fp,
" Final content: ");
288 fprintf(fp,
" Final content: ");
317 char *log_path =
SCMalloc(PATH_MAX);
318 if (log_path == NULL) {
319 FatalError(
"Unable to allocate scratch memory for rule filename");
321 snprintf(log_path, PATH_MAX,
"%s/%s%s", log_dir,
324 FILE *fp = fopen(log_path,
"w");
326 SCLogError(
"failed to open %s: %s", log_path, strerror(errno));
333 SCLogInfo(
"Engine-Analysis for fast_pattern printed to file - %s",
338 gettimeofday(&tval, NULL);
340 struct tm *tms =
SCLocalTime(tval.tv_sec, &local_tm);
341 fprintf(fp,
"----------------------------------------------"
342 "---------------------\n");
344 "Date: %" PRId32
"/%" PRId32
"/%04d -- "
346 tms->tm_mday, tms->tm_mon + 1, tms->tm_year + 1900, tms->tm_hour, tms->tm_min,
348 fprintf(fp,
"----------------------------------------------"
349 "---------------------\n");
362 #define DETECT_PERCENT_ENCODING_REGEX "%[0-9|a-f|A-F]{2}"
368 PCRE2_ZERO_TERMINATED, opts, &en, &eo, NULL);
370 PCRE2_UCHAR errbuffer[256];
371 pcre2_get_error_message(en, errbuffer,
sizeof(errbuffer));
392 }
else if (value && strcasecmp(value,
"warnings-only") == 0) {
394 rule_warnings_only = 1;
399 char log_path[PATH_MAX];
400 snprintf(log_path,
sizeof(log_path),
"%s/%s%s", log_dir,
404 SCLogError(
"failed to open %s: %s", log_path, strerror(errno));
408 SCLogInfo(
"Engine-Analysis for rules printed to file - %s",
412 gettimeofday(&tval, NULL);
414 struct tm *tms =
SCLocalTime(tval.tv_sec, &local_tm);
416 "----------------------------------------------"
417 "---------------------\n");
419 "Date: %" PRId32
"/%" PRId32
"/%04d -- "
421 tms->tm_mday, tms->tm_mon + 1, tms->tm_year + 1900, tms->tm_hour, tms->tm_min,
424 "----------------------------------------------"
425 "---------------------\n");
428 if (!PerCentEncodingSetup(
de_ctx->
ea)) {
430 "Error compiling regex; can't check for percent encoding in normalized "
436 SCLogInfo(
"Conf parameter \"engine-analysis.rules\" not found. "
437 "Defaulting to not printing the rules analysis report.");
440 SCLogInfo(
"Engine-Analysis for rules disabled in conf file.");
452 fprintf(fp,
"============\n"
453 "Summary:\n============\n");
461 "%s, smallest pattern %u byte(s), longest pattern %u byte(s), number of patterns "
462 "%u, avg pattern len %.2f byte(s)\n",
464 (
float)((
double)
f->tot / (
float)
f->cnt));
484 *fp_analysis =
false;
485 *rule_analysis =
false;
489 FatalError(
"Unable to allocate per-engine analysis context");
494 if (cfg_prefix_len > 0) {
499 FatalError(
"Unable to allocate per-engine analysis context name buffer");
505 *fp_analysis = SetupFPAnalyzer(
de_ctx);
506 *rule_analysis = SetupRuleAnalyzer(
de_ctx);
508 if (!(*fp_analysis || *rule_analysis)) {
521 CleanupRuleAnalyzer(
de_ctx);
522 CleanupFPAnalyzer(
de_ctx);
539 static int PerCentEncodingMatch(
EngineAnalysisCtx *ea_ctx, uint8_t *content, uint16_t content_len)
543 pcre2_match_data *match = pcre2_match_data_create_from_pattern(ea_ctx->
percent_re, NULL);
544 ret = pcre2_match(ea_ctx->
percent_re, (PCRE2_SPTR8)content, content_len, 0, 0, match, NULL);
547 }
else if (ret < -1) {
548 SCLogError(
"Error parsing content - %s; error code is %d", content, ret);
551 pcre2_match_data_free(match);
561 if (mpm_sm != NULL) {
599 const int list_type = mpm_sm_list;
608 payload ? (stream ?
"payload and reassembled stream" :
"payload")
609 :
"reassembled stream");
616 }
else if (desc ||
name) {
636 fprintf(tmp_fp,
"== Sid: UNKNOWN ==\n");
637 fprintf(tmp_fp,
"%s\n", line);
638 fprintf(tmp_fp,
" FAILURE: invalid rule.\n");
639 fprintf(tmp_fp,
" File: %s.\n", file);
640 fprintf(tmp_fp,
" Line: %d.\n", lineno);
641 fprintf(tmp_fp,
"\n");
658 vsnprintf(
str,
sizeof(
str), fmt, ap);
662 ctx->js_notes = SCJbNewArray();
664 SCJbAppendString(
ctx->js_notes,
str);
673 vsnprintf(
str,
sizeof(
str), fmt, ap);
676 if (!
ctx->js_warnings)
677 ctx->js_warnings = SCJbNewArray();
678 if (
ctx->js_warnings)
679 SCJbAppendString(
ctx->js_warnings,
str);
682 #define CHECK(pat) if (strlen((pat)) <= len && memcmp((pat), buf, MIN(len, strlen((pat)))) == 0) return true;
684 static bool LooksLikeHTTPMethod(
const uint8_t *buf, uint16_t
len)
693 static bool LooksLikeHTTPUA(
const uint8_t *buf, uint16_t
len)
695 CHECK(
"User-Agent: ");
696 CHECK(
"\nUser-Agent: ");
702 char pattern_str[1024] =
"";
705 SCJbSetString(js,
"pattern", pattern_str);
714 SCJbSetUint(js,
"offset", cd->
offset);
717 SCJbSetUint(js,
"depth", cd->
depth);
720 SCJbSetInt(js,
"distance", cd->
distance);
723 SCJbSetInt(js,
"within", cd->
within);
742 SCJbOpenArray(js,
"matches");
746 SCJbSetString(js,
"name", mname);
752 SCJbOpenObject(js,
"content");
755 AnalyzerNote(
ctx, (
char *)
"'fast_pattern:only' option is silently ignored and "
756 "is interpreted as regular 'fast_pattern'");
760 (
char *)
"pattern looks like it inspects HTTP, use http.request_line or "
761 "http.method and http.uri instead for improved performance");
765 (
char *)
"pattern looks like it inspects HTTP, use http.user_agent "
766 "or http.header for improved performance");
769 AnalyzerNote(
ctx, (
char *)
"'within' option for pattern w/o previous content "
770 "was converted to 'depth'");
773 AnalyzerNote(
ctx, (
char *)
"'distance' option for pattern w/o previous content "
774 "was converted to 'offset'");
782 SCJbOpenObject(js,
"pcre");
787 (
char *)
"'/B' (rawbytes) option is a no-op and is silently ignored");
790 AnalyzerNote(
ctx, (
char *)
"pcre with \\X (Unicode extended grapheme cluster) "
798 SCJbOpenObject(js,
"byte_jump");
799 SCJbSetUint(js,
"nbytes", cd->
nbytes);
800 SCJbSetInt(js,
"offset", cd->
offset);
801 SCJbSetUint(js,
"multiplier", cd->
multiplier);
805 SCJbSetString(js,
"base",
"unset");
808 SCJbSetString(js,
"base",
"oct");
811 SCJbSetString(js,
"base",
"dec");
814 SCJbSetString(js,
"base",
"hex");
817 SCJbOpenArray(js,
"flags");
819 SCJbAppendString(js,
"from_beginning");
821 SCJbAppendString(js,
"little_endian");
823 SCJbAppendString(js,
"big_endian");
825 SCJbAppendString(js,
"string");
827 SCJbAppendString(js,
"relative");
829 SCJbAppendString(js,
"align");
831 SCJbAppendString(js,
"dce");
833 SCJbAppendString(js,
"offset_be");
835 SCJbAppendString(js,
"from_end");
843 SCJbOpenObject(js,
"byte_test");
844 SCJbSetUint(js,
"nbytes", cd->
nbytes);
845 SCJbSetInt(js,
"offset", cd->
offset);
848 SCJbSetString(js,
"base",
"unset");
851 SCJbSetString(js,
"base",
"oct");
854 SCJbSetString(js,
"base",
"dec");
857 SCJbSetString(js,
"base",
"hex");
860 SCJbOpenArray(js,
"flags");
862 SCJbAppendString(js,
"little_endian");
864 SCJbAppendString(js,
"big_endian");
866 SCJbAppendString(js,
"string");
868 SCJbAppendString(js,
"relative");
870 SCJbAppendString(js,
"dce");
877 SCJbOpenObject(js,
"absent");
878 SCJbSetBool(js,
"or_else", dad->
or_else);
886 SCJbOpenObject(js,
"ipopts");
888 SCJbSetString(js,
"option", flag);
895 SCJbOpenObject(js,
"flowbits");
898 SCJbSetString(js,
"cmd",
"isset");
901 SCJbSetString(js,
"cmd",
"isnotset");
904 SCJbSetString(js,
"cmd",
"set");
907 SCJbSetString(js,
"cmd",
"unset");
911 SCJbOpenArray(js,
"names");
917 const char *varname =
919 SCJbAppendString(js, varname);
924 SCJbSetString(js,
"operator",
"or");
932 SCJbOpenObject(js,
"xbits");
935 SCJbSetString(js,
"cmd",
"isset");
938 SCJbSetString(js,
"cmd",
"isnotset");
941 SCJbSetString(js,
"cmd",
"set");
944 SCJbSetString(js,
"cmd",
"unset");
947 SCJbSetString(js,
"cmd",
"toggle");
953 SCJbSetString(js,
"track",
"ip_src");
956 SCJbSetString(js,
"track",
"ip_dst");
959 SCJbSetString(js,
"track",
"ip_pair");
962 SCJbSetString(js,
"track",
"tx");
966 SCJbSetUint(js,
"expire", xd->
expire);
973 SCJbOpenObject(js,
"flowint");
976 SCJbSetString(js,
"cmd",
"set");
979 SCJbSetString(js,
"cmd",
"add");
982 SCJbSetString(js,
"cmd",
"sub");
985 SCJbSetString(js,
"cmd",
"lt");
988 SCJbSetString(js,
"cmd",
"lte");
991 SCJbSetString(js,
"cmd",
"eq");
994 SCJbSetString(js,
"cmd",
"ne");
997 SCJbSetString(js,
"cmd",
"gte");
1000 SCJbSetString(js,
"cmd",
"gt");
1003 SCJbSetString(js,
"cmd",
"isset");
1006 SCJbSetString(js,
"cmd",
"isnotset");
1010 if (varname != NULL) {
1011 SCJbSetString(js,
"var", varname);
1025 SCJbOpenObject(js,
"ack");
1026 SCDetectU32ToJson(js, cd);
1032 SCJbOpenObject(js,
"seq");
1033 SCDetectU32ToJson(js, cd);
1039 SCJbOpenObject(js,
"tcp_mss");
1040 SCDetectU16ToJson(js, cd);
1046 SCJbOpenObject(js,
"dsize");
1047 SCDetectU16ToJson(js, cd);
1053 SCJbOpenObject(js,
"code");
1054 SCDetectU8ToJson(js, cd);
1060 SCJbOpenObject(js,
"ttl");
1061 SCDetectU8ToJson(js, cd);
1067 SCJbOpenObject(js,
"id");
1068 SCDetectU16ToJson(js, cd);
1074 SCJbOpenObject(js,
"window");
1075 SCDetectU16ToJson(js, cd);
1081 SCJbOpenObject(js,
"flow_age");
1082 SCDetectU32ToJson(js, cd);
1087 const uint8_t *dfd = (
const uint8_t *)smd->
ctx;
1088 SCJbOpenObject(js,
"flow_elephant");
1090 case DETECT_FLOW_TOSERVER:
1091 SCJbSetString(js,
"dir",
"toserver");
1093 case DETECT_FLOW_TOCLIENT:
1094 SCJbSetString(js,
"dir",
"toclient");
1096 case DETECT_FLOW_TOEITHER:
1097 SCJbSetString(js,
"dir",
"either");
1099 case DETECT_FLOW_TOBOTH:
1100 SCJbSetString(js,
"dir",
"both");
1108 SCJbOpenObject(js,
"app_layer_protocol");
1111 SCJbOpenArray(js,
"protocols");
1112 for (uint16_t i = 0; i < n; i++) {
1117 SCJbSetBool(js,
"negated", ad->
negated);
1123 SCJbOpenObject(js,
"tcp_session");
1124 SCJbOpenArray(js,
"phases");
1126 SCJbAppendString(js,
"setup");
1128 SCJbAppendString(js,
"established");
1130 SCJbAppendString(js,
"closing");
1152 ctx.js = SCJbNewObject();
1163 SCJbSetUint(
ctx.js,
"id", s->
id);
1164 SCJbSetUint(
ctx.js,
"gid", s->
gid);
1165 SCJbSetUint(
ctx.js,
"rev", s->
rev);
1166 SCJbSetString(
ctx.js,
"msg", s->
msg);
1169 SCJbSetString(
ctx.js,
"app_proto", alproto);
1171 SCJbOpenArray(
ctx.js,
"requirements");
1173 SCJbAppendString(
ctx.js,
"payload");
1176 SCJbAppendString(
ctx.js,
"no_payload");
1179 SCJbAppendString(
ctx.js,
"flow");
1182 SCJbAppendString(
ctx.js,
"tcp_flags_init_deinit");
1185 SCJbAppendString(
ctx.js,
"tcp_flags_unusual");
1188 SCJbAppendString(
ctx.js,
"engine_event");
1191 SCJbAppendString(
ctx.js,
"real_pkt");
1195 SCJbOpenObject(
ctx.js,
"match_policy");
1196 SCJbOpenArray(
ctx.js,
"actions");
1198 SCJbAppendString(
ctx.js,
"alert");
1201 SCJbAppendString(
ctx.js,
"drop");
1204 SCJbAppendString(
ctx.js,
"reject");
1207 SCJbAppendString(
ctx.js,
"reject_dst");
1210 SCJbAppendString(
ctx.js,
"reject_both");
1213 SCJbAppendString(
ctx.js,
"config");
1216 SCJbAppendString(
ctx.js,
"pass");
1219 SCJbAppendString(
ctx.js,
"accept");
1225 switch (flow_action) {
1227 SCJbSetString(
ctx.js,
"scope",
"packet");
1230 SCJbSetString(
ctx.js,
"scope",
"flow");
1233 SCJbSetString(
ctx.js,
"scope",
"flow_if_stateful");
1240 SCJbSetString(
ctx.js,
"scope",
"packet");
1243 SCJbSetString(
ctx.js,
"scope",
"flow");
1246 SCJbSetString(
ctx.js,
"scope",
"hook");
1249 SCJbSetString(
ctx.js,
"scope",
"tx");
1259 SCJbSetString(
ctx.js,
"type",
"unset");
1262 SCJbSetString(
ctx.js,
"type",
"ip_only");
1265 SCJbSetString(
ctx.js,
"type",
"like_ip_only");
1268 SCJbSetString(
ctx.js,
"type",
"pd_only");
1271 SCJbSetString(
ctx.js,
"type",
"de_only");
1274 SCJbSetString(
ctx.js,
"type",
"pkt");
1277 SCJbSetString(
ctx.js,
"type",
"pkt_stream");
1280 SCJbSetString(
ctx.js,
"type",
"stream");
1283 SCJbSetString(
ctx.js,
"type",
"app_layer");
1286 SCJbSetString(
ctx.js,
"type",
"app_tx");
1289 SCJbSetString(
ctx.js,
"type",
"error");
1295 SCJbOpenObject(
ctx.js,
"dependencies");
1296 SCJbOpenObject(
ctx.js,
"flowbits");
1297 SCJbOpenObject(
ctx.js,
"upstream");
1299 SCJbOpenObject(
ctx.js,
"state_modifying_rules");
1300 SCJbOpenArray(
ctx.js,
"sids");
1305 SCJbOpenArray(
ctx.js,
"names");
1308 SCJbAppendString(
ctx.js,
1321 SCJbOpenArray(
ctx.js,
"flags");
1323 SCJbAppendString(
ctx.js,
"src_any");
1326 SCJbAppendString(
ctx.js,
"dst_any");
1329 SCJbAppendString(
ctx.js,
"sp_any");
1332 SCJbAppendString(
ctx.js,
"dp_any");
1335 SCJbAppendString(
ctx.js,
"noalert");
1338 SCJbAppendString(
ctx.js,
"dsize");
1341 SCJbAppendString(
ctx.js,
"applayer");
1344 SCJbAppendString(
ctx.js,
"need_packet");
1347 SCJbAppendString(
ctx.js,
"need_stream");
1350 SCJbAppendString(
ctx.js,
"negated_mpm");
1353 SCJbAppendString(
ctx.js,
"flush");
1356 SCJbAppendString(
ctx.js,
"need_flowvar");
1359 SCJbAppendString(
ctx.js,
"filestore");
1362 SCJbAppendString(
ctx.js,
"toserver");
1365 SCJbAppendString(
ctx.js,
"toclient");
1368 SCJbAppendString(
ctx.js,
"tlsstore");
1371 SCJbAppendString(
ctx.js,
"bypass");
1374 SCJbAppendString(
ctx.js,
"prefilter");
1377 SCJbAppendString(
ctx.js,
"src_is_target");
1380 SCJbAppendString(
ctx.js,
"dst_is_target");
1387 SCJbOpenArray(
ctx.js,
"pkt_engines");
1389 for ( ; pkt != NULL; pkt = pkt->
next) {
1404 SCJbStartObject(
ctx.js);
1405 SCJbSetString(
ctx.js,
"name",
name);
1406 SCJbSetBool(
ctx.js,
"is_mpm", pkt->
mpm);
1408 SCJbOpenArray(
ctx.js,
"transforms");
1410 SCJbStartObject(
ctx.js);
1411 SCJbSetString(
ctx.js,
"name",
1424 SCJbOpenArray(
ctx.js,
"frame_engines");
1426 for (; frame != NULL; frame = frame->
next) {
1428 SCJbStartObject(
ctx.js);
1429 SCJbSetString(
ctx.js,
"name",
name);
1430 SCJbSetBool(
ctx.js,
"is_mpm", frame->
mpm);
1432 SCJbOpenArray(
ctx.js,
"transforms");
1434 SCJbStartObject(
ctx.js);
1435 SCJbSetString(
ctx.js,
"name",
1447 bool has_stream =
false;
1448 bool has_client_body_mpm =
false;
1449 bool has_file_data_mpm =
false;
1451 SCJbOpenArray(
ctx.js,
"engines");
1453 for ( ; app != NULL; app = app->
next) {
1468 }
else if (app->
mpm && strcmp(
name,
"http_client_body") == 0) {
1469 has_client_body_mpm =
true;
1470 }
else if (app->
mpm && strcmp(
name,
"file_data") == 0) {
1471 has_file_data_mpm =
true;
1474 SCJbStartObject(
ctx.js);
1475 SCJbSetString(
ctx.js,
"name",
name);
1476 const char *direction = app->
dir == 0 ?
"toserver" :
"toclient";
1477 SCJbSetString(
ctx.js,
"direction", direction);
1478 SCJbSetBool(
ctx.js,
"is_mpm", app->
mpm);
1482 SCJbSetString(
ctx.js,
"sub_state",
1486 SCJbOpenArray(
ctx.js,
"transforms");
1488 SCJbStartObject(
ctx.js);
1489 SCJbSetString(
ctx.js,
"name",
1503 if (has_stream && has_client_body_mpm)
1504 AnalyzerNote(&
ctx, (
char *)
"mpm in http_client_body combined with stream match leads to stream buffering");
1505 if (has_stream && has_file_data_mpm)
1506 AnalyzerNote(&
ctx, (
char *)
"mpm in file_data combined with stream match leads to stream buffering");
1509 SCJbOpenObject(
ctx.js,
"lists");
1519 if (pkt_mpm || app_mpm) {
1520 SCJbOpenObject(
ctx.js,
"mpm");
1528 SCJbSetString(
ctx.js,
"buffer",
name);
1536 switch (smd->
type) {
1540 DumpContent(
ctx.js, cd);
1552 SCJbOpenObject(
ctx.js,
"prefilter");
1559 SCJbSetString(
ctx.js,
"buffer",
name);
1561 SCJbSetString(
ctx.js,
"name", mname);
1565 if (
ctx.js_warnings) {
1566 SCJbClose(
ctx.js_warnings);
1567 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
1568 SCJbFree(
ctx.js_warnings);
1569 ctx.js_warnings = NULL;
1572 SCJbClose(
ctx.js_notes);
1573 SCJbSetObject(
ctx.js,
"notes",
ctx.js_notes);
1574 SCJbFree(
ctx.js_notes);
1575 ctx.js_notes = NULL;
1579 const char *filename =
"rules.json";
1581 char json_path[PATH_MAX] =
"";
1582 snprintf(json_path,
sizeof(json_path),
"%s/%s%s", log_dir,
1586 FILE *fp = fopen(json_path,
"a");
1588 fwrite(SCJbPtr(
ctx.js), SCJbLen(
ctx.js), 1, fp);
1603 if (root_jb == NULL) {
1607 if (arrays == NULL) {
1612 SCJbOpenArray(root_jb,
"buffers");
1616 char str[1024] =
"";
1621 if (arrays[
p->sm_list] == NULL) {
1622 jb = arrays[
p->sm_list] = SCJbNewObject();
1628 SCJbSetString(jb,
"name",
name);
1629 SCJbSetUint(jb,
"list_id",
p->sm_list);
1631 SCJbOpenArray(jb,
"patterns");
1634 SCJbStartObject(jb);
1635 SCJbSetString(jb,
"pattern",
str);
1636 SCJbSetUint(jb,
"patlen",
p->cd->content_len);
1637 SCJbSetUint(jb,
"cnt",
p->cnt);
1638 SCJbSetUint(jb,
"mpm",
p->mpm);
1639 SCJbOpenObject(jb,
"flags");
1657 SCJbAppendObject(root_jb, jb);
1663 const char *filename =
"patterns.json";
1665 char json_path[PATH_MAX] =
"";
1666 snprintf(json_path,
sizeof(json_path),
"%s/%s%s", log_dir,
1670 FILE *fp = fopen(json_path,
"a");
1672 fwrite(SCJbPtr(root_jb), SCJbLen(root_jb), 1, fp);
1694 EngineAnalysisItemsReset(ea_ctx);
1702 FatalError(
"Unable to allocate analysis scratch pad");
1712 analyzer_item->
item_id = (uint16_t)item_id;
1713 if (analyzer_item->
item_id == -1) {
1715 FatalError(
"unable to initialize engine-analysis table: detect buffer \"%s\" not "
1748 uint32_t rule_bidirectional = 0;
1749 uint32_t rule_pcre = 0;
1750 uint32_t rule_pcre_http = 0;
1751 uint32_t rule_content = 0;
1752 uint32_t rule_flow = 0;
1753 uint32_t rule_flags = 0;
1754 uint32_t rule_flow_toserver = 0;
1755 uint32_t rule_flow_toclient = 0;
1756 uint32_t rule_flow_nostream = 0;
1757 uint32_t rule_ipv4_only = 0;
1758 uint32_t rule_ipv6_only = 0;
1759 uint32_t rule_flowbits = 0;
1760 uint32_t rule_flowint = 0;
1761 uint32_t rule_content_http = 0;
1762 uint32_t rule_content_offset_depth = 0;
1763 int32_t list_id = 0;
1764 uint32_t rule_warning = 0;
1765 uint32_t stream_buf = 0;
1766 uint32_t packet_buf = 0;
1767 uint32_t file_store = 0;
1768 uint32_t warn_pcre_no_content = 0;
1769 uint32_t warn_pcre_http_content = 0;
1770 uint32_t warn_pcre_http = 0;
1771 uint32_t warn_content_http_content = 0;
1772 uint32_t warn_content_http = 0;
1773 uint32_t warn_tcp_no_flow = 0;
1774 uint32_t warn_client_ports = 0;
1775 uint32_t warn_direction = 0;
1776 uint32_t warn_method_toclient = 0;
1777 uint32_t warn_method_serverbody = 0;
1778 uint32_t warn_pcre_method = 0;
1779 uint32_t warn_encoding_norm_http_buf = 0;
1780 uint32_t warn_file_store_not_present = 0;
1781 uint32_t warn_offset_depth_pkt_stream = 0;
1782 uint32_t warn_offset_depth_alproto = 0;
1783 uint32_t warn_non_alproto_fp_for_alproto_sig = 0;
1784 uint32_t warn_no_direction = 0;
1785 uint32_t warn_both_direction = 0;
1787 EngineAnalysisItemsInit(
de_ctx->
ea);
1793 rule_bidirectional = 1;
1807 rule_ipv4_only += 1;
1810 rule_ipv6_only += 1;
1818 if (item_slot == -1) {
1826 if (item_slot == -1) {
1831 rule_content_offset_depth++;
1837 rule_content_http++;
1844 warn_encoding_norm_http_buf += 1;
1851 rule_flow_toserver = 1;
1854 rule_flow_toclient = 1;
1859 rule_flow_nostream = 1;
1873 if (sm->
ctx != NULL) {
1883 warn_file_store_not_present = 1;
1886 if (rule_pcre > 0 && rule_content == 0 && rule_content_http == 0) {
1888 warn_pcre_no_content = 1;
1891 if (rule_content_http > 0 && rule_pcre > 0 && rule_pcre_http == 0) {
1893 warn_pcre_http_content = 1;
1899 if (rule_content > 0 && rule_content_http > 0) {
1901 warn_content_http_content = 1;
1905 warn_content_http = 1;
1907 if (rule_content == 1) {
1912 (rule_content || rule_content_http || rule_pcre || rule_pcre_http || rule_flowbits ||
1915 warn_tcp_no_flow = 1;
1917 if (rule_flow && !rule_bidirectional && (rule_flow_toserver || rule_flow_toclient)
1922 warn_client_ports = 1;
1925 if (rule_flow && rule_bidirectional && (rule_flow_toserver || rule_flow_toclient)) {
1930 if (*http_method_item_seen_ptr) {
1931 if (rule_flow && rule_flow_toclient) {
1933 warn_method_toclient = 1;
1935 if (*http_server_body_item_seen_ptr) {
1937 warn_method_serverbody = 1;
1939 if (rule_content == 0 && rule_content_http == 0 && (rule_pcre > 0 || rule_pcre_http > 0)) {
1941 warn_pcre_method = 1;
1944 if (rule_content_offset_depth > 0 && stream_buf && packet_buf) {
1946 warn_offset_depth_pkt_stream = 1;
1950 warn_offset_depth_alproto = 1;
1955 warn_non_alproto_fp_for_alproto_sig = 1;
1959 warn_no_direction += 1;
1967 warn_both_direction += 1;
1972 if (!rule_warnings_only || (rule_warnings_only && rule_warning > 0)) {
1974 fprintf(fp,
"== Sid: %u ==\n", s->
id);
1975 fprintf(fp,
"%s\n", line);
1981 fprintf(fp,
" Rule is ip only.\n");
1984 fprintf(fp,
" Rule is like ip only.\n");
1987 fprintf(fp,
" Rule is PD only.\n");
1990 fprintf(fp,
" Rule is DE only.\n");
1993 fprintf(fp,
" Rule is packet inspecting.\n");
1996 fprintf(fp,
" Rule is packet and stream inspecting.\n");
1999 fprintf(fp,
" Rule is stream inspecting.\n");
2002 fprintf(fp,
" Rule is app-layer inspecting.\n");
2005 fprintf(fp,
" Rule is App-layer TX inspecting.\n");
2011 fprintf(fp,
" Rule is IPv6 only.\n");
2013 fprintf(fp,
" Rule is IPv4 only.\n");
2015 fprintf(fp,
" Rule matches on packets.\n");
2016 if (!rule_flow_nostream && stream_buf &&
2017 (rule_flow || rule_flowbits || rule_flowint || rule_content || rule_pcre)) {
2018 fprintf(fp,
" Rule matches on reassembled stream.\n");
2023 fprintf(fp,
" Rule matches on %s buffer.\n", ai->
display_name);
2029 if (rule_content || rule_content_http || rule_pcre || rule_pcre_http) {
2031 " Rule contains %u content options, %u http content options, %u pcre "
2032 "options, and %u pcre options with http modifiers.\n",
2033 rule_content, rule_content_http, rule_pcre, rule_pcre_http);
2038 fprintf(fp,
" Prefilter on: %s.\n",
2041 EngineAnalysisRulesPrintFP(
de_ctx, s);
2045 if (warn_pcre_no_content ) {
2046 fprintf(fp,
" Warning: Rule uses pcre without a content option present.\n"
2047 " -Consider adding a content to improve performance of this "
2050 if (warn_pcre_http_content ) {
2051 fprintf(fp,
" Warning: Rule uses content options with http_* and pcre options "
2052 "without http modifiers.\n"
2053 " -Consider adding http pcre modifier.\n");
2055 else if (warn_pcre_http ) {
2056 fprintf(fp,
" Warning: Rule app layer protocol is http, but pcre options do not "
2057 "have http modifiers.\n"
2058 " -Consider adding http pcre modifiers.\n");
2060 if (warn_content_http_content ) {
2062 " Warning: Rule contains content with http_* and content without http_*.\n"
2063 " -Consider adding http content modifiers.\n");
2065 if (warn_content_http ) {
2066 fprintf(fp,
" Warning: Rule app layer protocol is http, but content options do not "
2067 "have http_* modifiers.\n"
2068 " -Consider adding http content modifiers.\n");
2070 if (rule_content == 1) {
2073 if (warn_encoding_norm_http_buf) {
2074 fprintf(fp,
" Warning: Rule may contain percent encoded content for a normalized "
2075 "http buffer match.\n");
2077 if (warn_tcp_no_flow
2079 fprintf(fp,
" Warning: TCP rule without a flow or flags option.\n"
2080 " -Consider adding flow or flags to improve performance of "
2083 if (warn_client_ports
2088 " Warning: Rule contains ports or port variables only on the client side.\n"
2089 " -Flow direction possibly inconsistent with rule.\n");
2091 if (warn_direction ) {
2092 fprintf(fp,
" Warning: Rule is bidirectional and has a flow option with a specific "
2095 if (warn_method_toclient ) {
2096 fprintf(fp,
" Warning: Rule uses content or pcre for http_method with "
2097 "flow:to_client or from_server\n");
2099 if (warn_method_serverbody ) {
2100 fprintf(fp,
" Warning: Rule uses content or pcre for http_method with content or "
2101 "pcre for http_server_body.\n");
2103 if (warn_pcre_method
2105 fprintf(fp,
" Warning: Rule uses pcre with only a http_method content; possible "
2106 "performance issue.\n");
2108 if (warn_offset_depth_pkt_stream) {
2109 fprintf(fp,
" Warning: Rule has depth"
2110 "/offset with raw content keywords. Please note the "
2111 "offset/depth will be checked against both packet "
2112 "payloads and stream. If you meant to have the offset/"
2113 "depth checked against just the payload, you can update "
2114 "the signature as \"alert tcp-pkt...\"\n");
2116 if (warn_offset_depth_alproto) {
2118 " Warning: Rule has "
2119 "offset/depth set along with a match on a specific "
2120 "app layer protocol - %d. This can lead to FNs if we "
2121 "have a offset/depth content match on a packet payload "
2122 "before we can detect the app layer protocol for the "
2126 if (warn_non_alproto_fp_for_alproto_sig) {
2127 fprintf(fp,
" Warning: Rule app layer "
2128 "protocol is http, but the fast_pattern is set on the raw "
2129 "stream. Consider adding fast_pattern over a http "
2130 "buffer for increased performance.");
2132 if (warn_no_direction) {
2133 fprintf(fp,
" Warning: Rule has no direction indicator.\n");
2135 if (warn_both_direction) {
2136 fprintf(fp,
" Warning: Rule is inspecting both the request and the response.\n");
2138 if (warn_file_store_not_present) {
2139 fprintf(fp,
" Warning: Rule requires file-store but the output file-store is not "
2142 if (rule_warning == 0) {
2143 fprintf(fp,
" No warnings for this rule.\n");
2157 static bool FirewallPolicyToString(
2166 snprintf(out, out_size,
"rejectdst:%s", as);
2168 snprintf(out, out_size,
"rejectboth:%s", as);
2170 snprintf(out, out_size,
"rejectsrc:%s", as);
2173 snprintf(out, out_size,
"drop:%s", as);
2175 snprintf(out, out_size,
"accept:%s", as);
2182 if (
strlcat(out,
",pass:", out_size) >= out_size ||
2183 strlcat(out, as, out_size) >= out_size) {
2193 if (
strlcat(out,
",alert", out_size) >= out_size) {
2202 const uint8_t sub_state,
const uint8_t state,
const uint8_t direction)
2204 char policy_string[64] =
"";
2213 if (!FirewallPolicyToString(&ap->
policy, policy_string,
sizeof(policy_string)))
2215 SCJbSetString(
ctx->js,
"policy", policy_string);
2221 uint32_t accept_rules = 0;
2223 SCJbOpenArray(
ctx->js,
"rules");
2247 bool skip_rule =
false;
2249 engine = engine->
next) {
2252 }
else if (engine->sub_state !=
sub_state) {
2273 if (accept_rules == 0) {
2274 AnalyzerWarning(
ctx, (
char *)
"no accept rules for state, default policy will be applied");
2281 ctx.js = SCJbNewObject();
2285 SCJbOpenObject(
ctx.js,
"tables");
2286 SCJbOpenObject(
ctx.js,
"packet:filter");
2287 char pkt_policy[64] =
"";
2289 pkt_policy,
sizeof(pkt_policy))) {
2290 SCJbSetString(
ctx.js,
"policy", pkt_policy);
2292 SCJbOpenArray(
ctx.js,
"rules");
2293 uint32_t accept_rules = 0;
2294 uint32_t last_sid = 0;
2301 if (last_sid == s->
id)
2308 if (accept_rules == 0) {
2309 AnalyzerWarning(&
ctx,
2310 (
char *)
"no accept rules for \'packet:filter\', default policy will be applied");
2312 if (
ctx.js_warnings) {
2313 SCJbClose(
ctx.js_warnings);
2314 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
2315 SCJbFree(
ctx.js_warnings);
2316 ctx.js_warnings = NULL;
2321 if (!AppProtoIsValid(a))
2330 for (uint8_t state = 0; state <= max_progress; state++) {
2336 char table_name[256];
2337 snprintf(table_name,
sizeof(table_name),
"app:%s:%s:%s",
AppProtoToString(a),
2338 sub_state_name,
name);
2339 SCJbOpenObject(
ctx.js, table_name);
2341 if (
ctx.js_warnings) {
2342 SCJbClose(
ctx.js_warnings);
2343 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
2344 SCJbFree(
ctx.js_warnings);
2345 ctx.js_warnings = NULL;
2349 for (uint8_t state = 0; state <= max_progress; state++) {
2355 char table_name[256];
2356 snprintf(table_name,
sizeof(table_name),
"app:%s:%s:%s",
AppProtoToString(a),
2357 sub_state_name,
name);
2358 SCJbOpenObject(
ctx.js, table_name);
2360 if (
ctx.js_warnings) {
2361 SCJbClose(
ctx.js_warnings);
2362 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
2363 SCJbFree(
ctx.js_warnings);
2364 ctx.js_warnings = NULL;
2375 const uint8_t complete_state_ts =
2378 for (uint8_t state = 0; state <= complete_state_ts; state++) {
2387 char table_name[128];
2389 SCJbOpenObject(
ctx.js, table_name);
2390 FirewallAddRulesForState(
de_ctx, a, 0, state, STREAM_TOSERVER, &
ctx);
2391 if (
ctx.js_warnings) {
2392 SCJbClose(
ctx.js_warnings);
2393 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
2394 SCJbFree(
ctx.js_warnings);
2395 ctx.js_warnings = NULL;
2399 const uint8_t complete_state_tc =
2401 for (uint8_t state = 0; state <= complete_state_tc; state++) {
2409 char table_name[128];
2411 SCJbOpenObject(
ctx.js, table_name);
2412 FirewallAddRulesForState(
de_ctx, a, 0, state, STREAM_TOCLIENT, &
ctx);
2413 if (
ctx.js_warnings) {
2414 SCJbClose(
ctx.js_warnings);
2415 SCJbSetObject(
ctx.js,
"warnings",
ctx.js_warnings);
2416 SCJbFree(
ctx.js_warnings);
2417 ctx.js_warnings = NULL;
2423 SCJbOpenObject(
ctx.js,
"packet:td");
2424 SCJbSetString(
ctx.js,
"policy",
"accept:hook");
2426 SCJbOpenArray(
ctx.js,
"rules");
2432 if (last_sid == s->
id)
2439 SCJbOpenObject(
ctx.js,
"app:td");
2440 SCJbSetString(
ctx.js,
"policy",
"accept:hook");
2442 SCJbOpenArray(
ctx.js,
"rules");
2448 if (last_sid == s->
id)
2457 SCJbOpenObject(
ctx.js,
"lists");
2458 SCJbOpenObject(
ctx.js,
"firewall");
2460 SCJbOpenArray(
ctx.js,
"rules");
2464 if (last_sid == s->
id)
2472 SCJbOpenObject(
ctx.js,
"td");
2474 SCJbOpenArray(
ctx.js,
"rules");
2478 if (last_sid == s->
id)
2486 SCJbOpenObject(
ctx.js,
"all");
2488 SCJbOpenArray(
ctx.js,
"rules");
2490 if (last_sid == s->
id)
2501 SCJbOpenObject(
ctx.js,
"keyword_info");
2511 snprintf(sid_key,
sizeof(sid_key),
"%u", s->
id);
2512 SCJbOpenObject(
ctx.js, sid_key);
2513 SCJbOpenArray(
ctx.js,
"tcp_session");
2515 SCJbAppendString(
ctx.js,
"setup");
2517 SCJbAppendString(
ctx.js,
"established");
2519 SCJbAppendString(
ctx.js,
"closing");
2534 const char *filename =
"firewall.json";
2536 char json_path[PATH_MAX] =
"";
2537 snprintf(json_path,
sizeof(json_path),
"%s/%s", log_dir, filename);
2540 FILE *fp = fopen(json_path,
"w");
2542 fwrite(SCJbPtr(
ctx.js), SCJbLen(
ctx.js), 1, fp);
#define DETECT_PCRE_CASELESS
struct SCJsonBuilder SCJsonBuilder
#define DETECT_CONTENT_NOCASE
int SignatureHasPacketContent(const Signature *s)
check if a signature has patterns that are to be inspected against a packets payload (as opposed to t...
#define HashListTableGetListData(hb)
uint32_t rule_state_dependant_sids_idx
#define DETECT_CONTENT_RELATIVE_NEXT
struct DetectEngineAppInspectionEngine_::@82 v2
int SCConfValIsTrue(const char *val)
Check if a value is true.
#define SIG_MASK_REQUIRE_REAL_PKT
#define DETECT_CONTENT_FAST_PATTERN_CHOP
struct SigMatch_ * smlists[DETECT_SM_LIST_MAX]
#define SIG_FLAG_FW_HOOK_LTE
SigTableElmt * sigmatch_table
const char * AppLayerParserGetStateNameById(uint8_t ipproto, AppProto alproto, const int id, const uint8_t direction)
struct DetectEngineAppInspectionEngine_ * next
#define DETECT_PROTO_IPV6
#define DETECT_FLOW_FLAG_NOSTREAM
const char * DetectListToHumanString(int list)
HashListTable * pattern_hash_table
void DumpPatterns(DetectEngineCtx *de_ctx)
#define DETECT_BYTEJUMP_LITTLE
void SetupEngineAnalysis(DetectEngineCtx *de_ctx, bool *fp_analysis, bool *rule_analysis)
uint8_t app_progress_hook
FILE * rule_engine_analysis_fp
bool is_rule_state_dependant
#define DETECT_BYTETEST_BASE_HEX
const char * ActionScopeToString(enum ActionScope s)
Per-rule keyword data for app-layer-protocol:.
void DetectContentPatternPrettyPrint(const uint8_t *pat, const uint16_t pat_len, char *str, size_t str_len)
SCMutex g_rules_analyzer_write_m
const char * display_name
#define DETECT_CONTENT_WITHIN2DEPTH
@ DETECT_SM_LIST_DYNAMIC_START
#define DETECT_FLOWBITS_CMD_ISNOTSET
#define SIG_FLAG_DEST_IS_TARGET
#define DETECT_CONTENT_NO_DOUBLE_INSPECTION_REQUIRED
uint8_t AppLayerParserGetStateProgressCompletionStatus(AppProto alproto, uint8_t direction)
const char * AppProtoToString(AppProto alproto)
Maps the ALPROTO_*, to its normalized string equivalent.
tcp.session: keyword (Redmine #7704).
#define DETECT_BYTEJUMP_BASE_OCT
const DetectEngineTransforms * transforms
main detection engine ctx
struct DetectFirewallPolicy policy
#define DETECT_BYTETEST_DCE
HashListTableBucket * HashListTableGetListHead(HashListTable *ht)
FpPatternStats fp_pattern_stats[DETECT_SM_LIST_MAX]
const char * DetectAppLayerProtocolModeName(uint8_t mode)
Map a DETECT_ALPROTO_* mode value to its textual qualifier.
const char * DetectEngineBufferTypeGetNameById(const DetectEngineCtx *de_ctx, const int id)
#define SIG_FLAG_REQUIRE_STREAM
#define DETECT_XBITS_TRACK_IPDST
FILE * fp_engine_analysis_fp
int SCConfGetBool(const char *name, int *val)
Retrieve a configuration value as a boolean.
bool analyzer_initialized
#define ACTION_REJECT_ANY
#define DETECT_BYTEJUMP_DCE
const char * VarNameStoreSetupLookup(const uint32_t id, const enum VarTypes type)
#define SCMUTEX_INITIALIZER
SigMatchData * sm_arrays[DETECT_SM_LIST_MAX]
#define DETECT_FLOWBITS_CMD_ISSET
const char * SCConfNodeLookupChildValue(const SCConfNode *node, const char *name)
Lookup the value of a child configuration node by name.
int16_t analyzer_item_map[256]
#define SIG_FLAG_TOCLIENT
#define DETECT_BYTEJUMP_BIG
void EngineAnalysisRulesFailure(const DetectEngineCtx *de_ctx, const char *line, const char *file, int lineno)
DetectEngineFrameInspectionEngine * frame_inspect
const DetectEngineTransforms * transforms
DetectEngineAnalyzerItems * analyzer_items
#define DETECT_PERCENT_ENCODING_REGEX
int FirewallAnalyzer(const DetectEngineCtx *de_ctx)
#define SIG_FLAG_APPLAYER
int DetectBufferTypeGetByName(const char *name)
uint16_t DetectAppLayerProtocolGetValues(const DetectAppLayerProtocolData *data, AppProto *out, uint16_t max)
Fill out[] with the keyword's set protocol values.
#define SIG_FLAG_FIREWALL
const char * DetectFirewallAppGenericHookName(const uint8_t state, const uint8_t complete_state, const int direction)
Generic start/complete hook alias for an app progress state, in config form (hyphens),...
#define ACTION_REJECT_DST
#define ATTR_FMT_PRINTF(x, y)
#define HashListTableGetListNext(hb)
@ DETECT_APP_LAYER_PROTOCOL
SignaturePropertyFlowAction
#define SIG_FLAG_TOSERVER
#define DETECT_XBITS_CMD_ISNOTSET
#define DETECT_BYTETEST_RELATIVE
uint8_t AppLayerParserGetSubStateCompletion(const AppProto alproto, const uint8_t sub_state)
const char * IpOptsFlagToString(uint16_t flag)
Return human readable value for ipopts flag.
#define JB_SET_STRING(jb, key, val)
struct EngineAnalysisCtx_ EngineAnalysisCtx
struct DetectFirewallPolicies * fw_policies
#define DETECT_CONTENT_ENDS_WITH
#define DETECT_PCRE_RAWBYTES
#define DETECT_CONTENT_DISTANCE
#define SIG_FLAG_INIT_BIDIREC
size_t strlcat(char *, const char *src, size_t siz)
#define SIG_MASK_REQUIRE_ENGINE_EVENT
#define DETECT_BYTETEST_BASE_UNSET
#define DETECT_BYTEJUMP_ALIGN
const char * DetectEngineBufferTypeGetDescriptionById(const DetectEngineCtx *de_ctx, const int id)
#define SCMutexUnlock(mut)
#define DETECT_BYTETEST_BASE_DEC
#define SIG_MASK_REQUIRE_FLOW
#define DETECT_CONTENT_DEPTH
#define DETECT_CONTENT_DISTANCE2OFFSET
#define DETECT_BYTEJUMP_END
DetectEnginePktInspectionEngine * pkt_inspect
struct DetectEngineAnalyzerItems DetectEngineAnalyzerItems
void * HashTableLookup(HashTable *ht, void *data, uint16_t datalen)
#define SIG_MASK_REQUIRE_FLAGS_INITDEINIT
uint32_t rule_state_flowbits_ids_size
#define DETECT_XBITS_TRACK_IPPAIR
struct DetectFirewallPolicy pkt[DETECT_FIREWALL_POLICY_SIZE]
#define DETECT_CONTENT_NEGATED
DetectUintData_u8 DetectU8Data
void EngineAnalysisRules(const DetectEngineCtx *de_ctx, const Signature *s, const char *line)
Prints analysis of loaded rules.
DetectEngineAppInspectionEngine * app_inspect
#define DETECT_TCP_SESSION_PHASE_SETUP
SCJsonBuilder * js_warnings
#define SIG_FLAG_REQUIRE_FLOWVAR
struct DetectEngineFrameInspectionEngine::@86 v1
#define DETECT_BYTETEST_BIG
struct tm * SCLocalTime(time_t timep, struct tm *result)
const char * SCConfigGetLogDirectory(void)
const DetectBufferType * DetectEngineBufferTypeGetById(const DetectEngineCtx *de_ctx, const int id)
#define DETECT_BYTEJUMP_BASE_UNSET
SignatureInitData * init_data
#define SIG_FLAG_SRC_IS_TARGET
uint32_t * rule_state_dependant_sids_array
bool fp_engine_analysis_set
uint32_t rule_state_dependant_sids_size
#define DETECT_PCRE_HAS_UNICODE_CLUSTER
#define DETECT_BYTEJUMP_BASE_HEX
@ SIG_PROP_FLOW_ACTION_PACKET
const struct SignatureProperties signature_properties[SIG_TYPE_MAX]
#define SIG_MASK_REQUIRE_PAYLOAD
#define DETECT_TCP_SESSION_PHASE_ESTABLISHED
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
#define DETECT_BYTEJUMP_OFFSET_BE
const char * DetectSigmatchListEnumToString(enum DetectSigmatchListEnum type)
const DetectEngineAnalyzerItems analyzer_items[]
#define SIG_FLAG_INIT_STATE_MATCH
#define DETECT_XBITS_TRACK_TX
void EngineAnalysisRules2(const DetectEngineCtx *de_ctx, const Signature *s)
#define ACTION_REJECT_BOTH
union DetectFlowintData_::@68 target
#define DETECT_CONTENT_STARTS_WITH
#define DETECT_PROTO_IPV4
#define DETECT_TCP_SESSION_PHASE_CLOSING
int SignatureHasStreamContent(const Signature *s)
check if a signature has patterns that are to be inspected against the stream payload (as opposed to ...
#define SIG_MASK_REQUIRE_NO_PAYLOAD
struct DetectEnginePktInspectionEngine::@85 v1
@ SIG_PROP_FLOW_ACTION_FLOW_IF_STATEFUL
@ DETECT_FIREWALL_POLICY_PACKET_FILTER
void HashListTableFree(HashListTable *ht)
bool check_encoding_match
void CleanupEngineAnalysis(DetectEngineCtx *de_ctx)
struct DetectEngineFrameInspectionEngine * next
DetectUintData_u32 DetectU32Data
struct DetectEnginePktInspectionEngine * next
const char * AppLayerParserGetSubStateProgressName(const AppProto alproto, const uint8_t sub_state, const uint8_t state, const uint8_t dir_flag)
#define DETECT_BYTEJUMP_BASE_DEC
void PrintRawUriFp(FILE *fp, const uint8_t *buf, uint32_t buflen)
#define SIG_MASK_REQUIRE_FLAGS_UNUSUAL
@ FLOWINT_MODIFIER_ISNOTSET
struct EngineAnalysisCtx_ * ea
#define DETECT_BYTETEST_BASE_OCT
void EngineAnalysisFP(const DetectEngineCtx *de_ctx, const Signature *s, const char *line)
struct FpPatternStats_ FpPatternStats
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
#define SCLogError(...)
Macro used to log ERROR messages.
int SigMatchListSMBelongsTo(const Signature *s, const SigMatch *key_sm)
const char * AppLayerParserGetSubStateName(const AppProto alproto, const uint8_t sub_state)
#define DETECT_CONTENT_OFFSET
#define DETECT_XBITS_TRACK_IPSRC
#define DETECT_FLOWBITS_CMD_UNSET
#define DETECT_CONTENT_FAST_PATTERN_ONLY
#define DETECT_CONTENT_MPM
DetectEngineTransforms transforms
a single match condition for a signature
const DetectEngineTransforms * transforms
bool SCRequiresFeature(const char *feature_name)
#define DETECT_XBITS_CMD_ISSET
#define DETECT_BYTETEST_STRING
#define DETECT_PCRE_RELATIVE_NEXT
#define DETECT_BYTEJUMP_STRING
uint8_t AppLayerParserGetMaxSubState(const AppProto alproto)
#define DETECT_XBITS_CMD_SET
#define DETECT_BYTEJUMP_BEGIN
uint32_t * rule_state_flowbits_ids_array
bool AppLayerParserSupportsSubStates(const AppProto alproto)
@ SIG_PROP_FLOW_ACTION_FLOW
#define DETECT_PCRE_RELATIVE
struct RuleAnalyzer RuleAnalyzer
#define SIG_FLAG_TLSSTORE
#define DETECT_XBITS_CMD_TOGGLE
DetectUintData_u16 DetectU16Data
#define DETECT_XBITS_CMD_UNSET
#define DETECT_CONTENT_FAST_PATTERN
#define DETECT_PCRE_NEGATE
struct ExposedItemSeen exposed_item_seen_list[2]
#define DETECT_BYTETEST_LITTLE
#define DEBUG_VALIDATE_BUG_ON(exp)
#define SIG_FLAG_PREFILTER
enum SignaturePropertyFlowAction flow_action
#define SIG_FLAG_FILESTORE
#define DETECT_CONTENT_WITHIN
#define DETECT_BYTEJUMP_RELATIVE
#define DETECT_FLOWBITS_CMD_SET
int DetectProtoContainsProto(const DetectProto *dp, int proto)
see if a DetectProto contains a certain proto
#define SIG_FLAG_REQUIRE_PACKET