suricata
detect-engine-payload.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  * Performs payload matching functions
24  */
25 
26 #include "suricata-common.h"
27 #include "suricata.h"
28 #include "rust.h"
29 
30 #include "decode.h"
31 
32 #include "detect.h"
33 #include "detect-engine.h"
34 #include "detect-parse.h"
37 #include "detect-engine-state.h"
38 #include "detect-engine-payload.h"
39 #include "detect-engine-build.h"
40 
41 #include "stream.h"
42 #include "stream-tcp.h"
43 
44 #include "util-debug.h"
45 #include "util-print.h"
46 
47 #include "util-unittest-helper.h"
48 #include "util-validate.h"
49 #include "util-profiling.h"
50 #include "util-mpm-ac.h"
51 
52 struct StreamMpmData {
54  const MpmCtx *mpm_ctx;
55 };
56 
57 static int StreamMpmFunc(
58  void *cb_data, const uint8_t *data, const uint32_t data_len, const uint64_t _offset)
59 {
60  struct StreamMpmData *smd = cb_data;
61  if (data_len >= smd->mpm_ctx->minlen) {
62 #ifdef DEBUG
63  smd->det_ctx->stream_mpm_cnt++;
64  smd->det_ctx->stream_mpm_size += data_len;
65 #endif
66  (void)mpm_table[smd->mpm_ctx->mpm_type].Search(
67  smd->mpm_ctx, &smd->det_ctx->mtc, &smd->det_ctx->pmq, data, data_len);
68  PREFILTER_PROFILING_ADD_BYTES(smd->det_ctx, data_len);
69  }
70  return 0;
71 }
72 
73 static void PrefilterPktStream(DetectEngineThreadCtx *det_ctx,
74  Packet *p, const void *pectx)
75 {
76  SCEnter();
77 
78  const MpmCtx *mpm_ctx = (MpmCtx *)pectx;
79 
80  /* for established packets inspect any stream we may have queued up */
82  SCLogDebug("PRE det_ctx->raw_stream_progress %"PRIu64,
84  struct StreamMpmData stream_mpm_data = { det_ctx, mpm_ctx };
86  StreamMpmFunc, &stream_mpm_data,
88  false /* mpm doesn't use min inspect depth */);
89  SCLogDebug("POST det_ctx->raw_stream_progress %"PRIu64,
91 
92  /* packets that have not been added to the stream will be inspected as if they are stream
93  * chunks */
94  } else if ((p->flags & (PKT_NOPAYLOAD_INSPECTION | PKT_STREAM_ADD)) == 0) {
95  if (p->payload_len >= mpm_ctx->minlen) {
96 #ifdef DEBUG
97  det_ctx->payload_mpm_cnt++;
98  det_ctx->payload_mpm_size += p->payload_len;
99 #endif
101  &det_ctx->mtc, &det_ctx->pmq,
102  p->payload, p->payload_len);
104  }
105  }
106 }
107 
109  SigGroupHead *sgh, MpmCtx *mpm_ctx)
110 {
112  PrefilterPktStream, mpm_ctx, NULL, "stream");
113 }
114 
115 static void PrefilterPktPayload(DetectEngineThreadCtx *det_ctx,
116  Packet *p, const void *pectx)
117 {
118  SCEnter();
119 
120  const MpmCtx *mpm_ctx = (MpmCtx *)pectx;
121  if (p->payload_len < mpm_ctx->minlen)
122  SCReturn;
123 
125  &det_ctx->mtc, &det_ctx->pmq,
126  p->payload, p->payload_len);
127 
129 }
130 
132  SigGroupHead *sgh, MpmCtx *mpm_ctx)
133 {
135  PrefilterPktPayload, mpm_ctx, NULL, "payload");
136 }
137 
138 
139 /**
140  * \brief Do the content inspection & validation for a signature
141  *
142  * \param de_ctx Detection engine context
143  * \param det_ctx Detection engine thread context
144  * \param s Signature to inspect
145  * \param f flow (for pcre flowvar storage)
146  * \param p Packet
147  *
148  * \retval 0 no match
149  * \retval 1 match
150  */
152  const Signature *s, Flow *f, Packet *p)
153 {
154  SCEnter();
155 
156  if (s->sm_arrays[DETECT_SM_LIST_PMATCH] == NULL) {
157  SCReturnInt(0);
158  }
159 #ifdef DEBUG
160  det_ctx->payload_persig_cnt++;
161  det_ctx->payload_persig_size += p->payload_len;
162 #endif
163  const bool match = DetectEngineContentInspection(de_ctx, det_ctx, s,
166  if (match) {
167  SCReturnInt(1);
168  }
169  SCReturnInt(0);
170 }
171 
172 /**
173  * \brief Do the content inspection & validation for a sigmatch list
174  *
175  * \param de_ctx Detection engine context
176  * \param det_ctx Detection engine thread context
177  * \param s Signature to inspect
178  * \param smd array of matches to eval
179  * \param f flow (for pcre flowvar storage)
180  * \param p Packet
181  *
182  * \retval 0 no match
183  * \retval 1 match
184  */
185 static uint8_t DetectEngineInspectStreamUDPPayload(DetectEngineCtx *de_ctx,
186  DetectEngineThreadCtx *det_ctx, const Signature *s, const SigMatchData *smd, Flow *f,
187  Packet *p)
188 {
189  SCEnter();
190 
191  if (smd == NULL) {
192  SCReturnInt(0);
193  }
194 #ifdef DEBUG
195  det_ctx->payload_persig_cnt++;
196  det_ctx->payload_persig_size += p->payload_len;
197 #endif
198  const bool match =
201  if (match) {
202  SCReturnInt(1);
203  }
204  SCReturnInt(0);
205 }
206 
210  const Signature *s;
211  Flow *f;
212 };
213 
214 static int StreamContentInspectFunc(
215  void *cb_data, const uint8_t *data, const uint32_t data_len, const uint64_t _offset)
216 {
217  SCEnter();
218  struct StreamContentInspectData *smd = cb_data;
219 #ifdef DEBUG
220  smd->det_ctx->stream_persig_cnt++;
221  smd->det_ctx->stream_persig_size += data_len;
222 #endif
223 
224  const bool match = DetectEngineContentInspection(smd->de_ctx, smd->det_ctx, smd->s,
225  smd->s->sm_arrays[DETECT_SM_LIST_PMATCH], NULL, smd->f, data, data_len, 0,
226  0, // TODO
228  if (match) {
229  SCReturnInt(1);
230  }
231 
232  SCReturnInt(0);
233 }
234 
235 /**
236  * \brief Do the content inspection & validation for a signature
237  * on the raw stream
238  *
239  * \param de_ctx Detection engine context
240  * \param det_ctx Detection engine thread context
241  * \param s Signature to inspect
242  * \param f flow (for pcre flowvar storage)
243  *
244  * \retval 0 no match
245  * \retval 1 match
246  */
249  Flow *f, Packet *p)
250 {
251  SCEnter();
252  SCLogDebug("FLUSH? %s", (s->flags & SIG_FLAG_FLUSH)?"true":"false");
253  uint64_t unused;
254  struct StreamContentInspectData inspect_data = { de_ctx, det_ctx, s, f };
255  int r = StreamReassembleRaw(f->protoctx, p,
256  StreamContentInspectFunc, &inspect_data,
257  &unused, ((s->flags & SIG_FLAG_FLUSH) != 0));
258  return r;
259 }
260 
264  const Signature *s;
266  Flow *f;
267 };
268 
269 static int StreamContentInspectEngineFunc(
270  void *cb_data, const uint8_t *data, const uint32_t data_len, const uint64_t _offset)
271 {
272  SCEnter();
273  struct StreamContentInspectEngineData *smd = cb_data;
274 #ifdef DEBUG
275  smd->det_ctx->stream_persig_cnt++;
276  smd->det_ctx->stream_persig_size += data_len;
277 #endif
278 
279  const bool match = DetectEngineContentInspection(smd->de_ctx, smd->det_ctx, smd->s, smd->smd,
280  NULL, smd->f, data, data_len, 0, 0, // TODO
282  if (match) {
283  SCReturnInt(1);
284  }
285 
286  SCReturnInt(0);
287 }
288 
289 /**
290  * \brief inspect engine for stateful rules
291  *
292  * Caches results as it may be called multiple times if we inspect
293  * multiple transactions in one packet.
294  *
295  * Returns "can't match" if depth is reached.
296  */
298  const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f,
299  uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
300 {
301  Packet *p = det_ctx->p; /* TODO: get rid of this HACK */
302 
303  /* in certain sigs, e.g. 'alert dns', which apply to both tcp and udp
304  * we can get called for UDP. Then we simply inspect the packet payload */
305  if (p->proto == IPPROTO_UDP) {
306  return DetectEngineInspectStreamUDPPayload(de_ctx, det_ctx, s, engine->smd, f, p);
307  /* for other non-TCP protocols we assume match */
308  } else if (p->proto != IPPROTO_TCP)
310 
311  TcpSession *ssn = f->protoctx;
312  if (ssn == NULL)
314 
315  SCLogDebug("pre-inspect det_ctx->raw_stream_progress %"PRIu64" FLUSH? %s",
317  (s->flags & SIG_FLAG_FLUSH)?"true":"false");
318  uint64_t unused;
319  struct StreamContentInspectEngineData inspect_data = { de_ctx, det_ctx, s, engine->smd, f };
320  int match = StreamReassembleRaw(f->protoctx, p,
321  StreamContentInspectEngineFunc, &inspect_data,
322  &unused, ((s->flags & SIG_FLAG_FLUSH) != 0));
323 
324  bool is_last = false;
325  if (flags & STREAM_TOSERVER) {
326  TcpStream *stream = &ssn->client;
328  is_last = true;
329  } else {
330  TcpStream *stream = &ssn->server;
332  is_last = true;
333  }
334 
335  SCLogDebug("%s ran stream for sid %u on packet %" PRIu64 " and we %s",
336  is_last ? "LAST:" : "normal:", s->id, PcapPacketCntGet(p),
337  match ? "matched" : "didn't match");
338 
339  if (match) {
341  } else {
342  if (is_last) {
343  //SCLogNotice("last, so DETECT_ENGINE_INSPECT_SIG_CANT_MATCH");
345  }
346  /* TODO maybe we can set 'CANT_MATCH' for EOF too? */
348  }
349 }
350 
351 #ifdef UNITTESTS
352 #include "detect-engine-alert.h"
353 
354 /** \test Not the first but the second occurrence of "abc" should be used
355  * for the 2nd match */
356 static int PayloadTestSig01 (void)
357 {
358  uint8_t *buf = (uint8_t *)
359  "abcabcd";
360  uint16_t buflen = strlen((char *)buf);
361  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
362 
363  FAIL_IF_NULL(p);
364 
365  char sig[] = "alert tcp any any -> any any (content:\"abc\"; content:\"d\"; distance:0; within:1; sid:1;)";
366 
368 
369  UTHFreePacket(p);
370 
371  PASS;
372 }
373 
374 /** \test Nocase matching */
375 static int PayloadTestSig02 (void)
376 {
377  uint8_t *buf = (uint8_t *)
378  "abcaBcd";
379  uint16_t buflen = strlen((char *)buf);
380  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
381 
382  FAIL_IF_NULL(p);
383 
384  char sig[] = "alert tcp any any -> any any (content:\"abc\"; nocase; content:\"d\"; distance:0; within:1; sid:1;)";
385 
387 
388  UTHFreePacket(p);
389 
390  PASS;
391 }
392 
393 /** \test Negative distance matching */
394 static int PayloadTestSig03 (void)
395 {
396  uint8_t *buf = (uint8_t *)
397  "abcaBcd";
398  uint16_t buflen = strlen((char *)buf);
399  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
400 
401  FAIL_IF_NULL(p);
402 
403  char sig[] = "alert tcp any any -> any any (content:\"aBc\"; nocase; content:\"abca\"; distance:-10; within:4; sid:1;)";
404 
406 
407  UTHFreePacket(p);
408 
409  PASS;
410 }
411 
412 /**
413  * \test Test multiple relative matches.
414  */
415 static int PayloadTestSig04(void)
416 {
417  uint8_t *buf = (uint8_t *)"now this is is big big string now";
418  uint16_t buflen = strlen((char *)buf);
419  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
420 
421  FAIL_IF_NULL(p);
422 
423  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
424  "content:\"this\"; content:\"is\"; within:6; content:\"big\"; within:8; "
425  "content:\"string\"; within:8; sid:1;)";
426 
428 
429  UTHFreePacket(p);
430 
431  PASS;
432 }
433 
434 /**
435  * \test Test multiple relative matches.
436  */
437 static int PayloadTestSig05(void)
438 {
439  uint8_t *buf = (uint8_t *)"now this is is is big big big string now";
440  uint16_t buflen = strlen((char *)buf);
441  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
442 
443  FAIL_IF_NULL(p);
444 
445  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
446  "content:\"this\"; content:\"is\"; within:9; content:\"big\"; within:12; "
447  "content:\"string\"; within:8; sid:1;)";
448 
450 
451  UTHFreePacket(p);
452 
453  PASS;
454 }
455 
456 /**
457  * \test Test multiple relative matches.
458  */
459 static int PayloadTestSig06(void)
460 {
461  uint8_t *buf = (uint8_t *)"this this now is is big string now";
462  uint16_t buflen = strlen((char *)buf);
463  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
464 
465  FAIL_IF_NULL(p);
466 
467  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
468  "content:\"now\"; content:\"this\"; content:\"is\"; within:12; content:\"big\"; within:8; "
469  "content:\"string\"; within:8; sid:1;)";
470 
472 
473  UTHFreePacket(p);
474 
475  PASS;
476 }
477 
478 /**
479  * \test Test multiple relative matches.
480  */
481 static int PayloadTestSig07(void)
482 {
483  uint8_t *buf = (uint8_t *)" thus thus is a big";
484  uint16_t buflen = strlen((char *)buf);
485  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
486 
487  FAIL_IF_NULL(p);
488 
489  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
490  "content:\"thus\"; offset:8; content:\"is\"; within:6; content:\"big\"; within:8; sid:1;)";
491 
493 
494  UTHFreePacket(p);
495 
496  PASS;
497 }
498 
499 /**
500  * \test Test multiple relative matches with negative matches
501  * and show the need for det_ctx->discontinue_matching.
502  */
503 static int PayloadTestSig08(void)
504 {
505  uint8_t *buf = (uint8_t *)"we need to fix this and yes fix this now";
506  uint16_t buflen = strlen((char *)buf);
507  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
508 
509  FAIL_IF_NULL(p);
510 
511  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
512  "content:\"fix\"; content:\"this\"; within:6; content:!\"and\"; distance:0; sid:1;)";
513 
515 
516  UTHFreePacket(p);
517 
518  PASS;
519 }
520 
521 /**
522  * \test Test pcre recursive matching.
523  */
524 static int PayloadTestSig09(void)
525 {
526  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
527  uint16_t buflen = strlen((char *)buf);
528  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
529 
530  FAIL_IF_NULL(p);
531 
532  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
533  "pcre:/super/; content:\"nova\"; within:7; sid:1;)";
534 
536 
537  UTHFreePacket(p);
538 
539  PASS;
540 }
541 
542 /**
543  * \test Test invalid sig.
544  */
545 static int PayloadTestSig10(void)
546 {
547  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
548  uint16_t buflen = strlen((char *)buf);
549  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
550 
551  FAIL_IF_NULL(p);
552 
553  char sig[] = "alert udp any any -> any any (msg:\"crash\"; "
554  "byte_test:4,>,2,0,relative; sid:11;)";
555 
557 
558  UTHFreePacket(p);
559 
560  PASS;
561 }
562 
563 /**
564  * \test Test invalid sig.
565  */
566 static int PayloadTestSig11(void)
567 {
568  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
569  uint16_t buflen = strlen((char *)buf);
570  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
571 
572  FAIL_IF_NULL(p);
573 
574  char sig[] = "alert udp any any -> any any (msg:\"crash\"; "
575  "byte_jump:1,0,relative; sid:11;)";
576 
578 
579  UTHFreePacket(p);
580 
581  PASS;
582 }
583 
584 /**
585  * \test Test invalid sig.
586  */
587 static int PayloadTestSig12(void)
588 {
589  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
590  uint16_t buflen = strlen((char *)buf);
591  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
592 
593  FAIL_IF_NULL(p);
594 
595  char sig[] = "alert udp any any -> any any (msg:\"crash\"; "
596  "isdataat:10,relative; sid:11;)";
597 
599 
600  UTHFreePacket(p);
601 
602  PASS;
603 }
604 
605 /**
606  * \test Used to check the working of recursion_limit counter.
607  */
608 static int PayloadTestSig13(void)
609 {
610  uint8_t *buf = (uint8_t *)"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
611  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
612  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
613  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
614  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
615  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
616  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
617  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
618  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
619  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
620  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
621  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
622  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
623  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
624  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
625  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
626  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
627  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
628  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
629  "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa";
630 
631  uint16_t buflen = strlen((char *)buf);
632  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
633  uint16_t mpm_type = mpm_default_matcher;
634 
635  FAIL_IF_NULL(p);
636 
637  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
638  "content:\"aa\"; content:\"aa\"; distance:0; content:\"aa\"; distance:0; "
639  "byte_test:1,>,200,0,relative; sid:1;)";
640 
644 
645  memset(&dtv, 0, sizeof(DecodeThreadVars));
646  memset(&th_v, 0, sizeof(th_v));
648 
652  de_ctx->flags |= DE_QUIET;
653  de_ctx->mpm_matcher = mpm_type;
654 
656  FAIL_IF_NULL(s);
657 
659  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
660 
663 
664  UTHFreePacket(p);
668  PASS;
669 }
670 
671 /**
672  * \test normal & negated matching, both absolute and relative
673  */
674 static int PayloadTestSig14(void)
675 {
676  uint8_t *buf = (uint8_t *)"User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b4) Gecko/20090423 Firefox/3.6 GTB5";
677  uint16_t buflen = strlen((char *)buf);
678  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
679 
680  FAIL_IF_NULL(p);
681 
682  char sig[] = "alert tcp any any -> any any (content:\"User-Agent|3A| Mozilla/5.0 |28|Macintosh|3B| \"; content:\"Firefox/3.\"; distance:0; content:!\"Firefox/3.6.12\"; distance:-10; content:!\"Mozilla/5.0 |28|Macintosh|3B| U|3B| Intel Mac OS X 10.5|3B| en-US|3B| rv|3A|1.9.1b4|29| Gecko/20090423 Firefox/3.6 GTB5\"; sid:1; rev:1;)";
683 
684  //char sig[] = "alert tcp any any -> any any (content:\"User-Agent: Mozilla/5.0 (Macintosh; \"; content:\"Firefox/3.\"; distance:0; content:!\"Firefox/3.6.12\"; distance:-10; content:!\"Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b4) Gecko/20090423 Firefox/3.6 GTB5\"; sid:1; rev:1;)";
685 
687 
688  UTHFreePacket(p);
689 
690  PASS;
691 }
692 
693 static int PayloadTestSig15(void)
694 {
695  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
696  uint16_t buflen = strlen((char *)buf);
697  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
698 
699  FAIL_IF_NULL(p);
700 
701  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
702  "content:\"nova\"; isdataat:18,relative; sid:1;)";
703 
705 
706  UTHFreePacket(p);
707 
708  PASS;
709 }
710 
711 static int PayloadTestSig16(void)
712 {
713  uint8_t *buf = (uint8_t *)"this is a super duper nova in super nova now";
714  uint16_t buflen = strlen((char *)buf);
715  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
716 
717  FAIL_IF_NULL(p);
718 
719  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
720  "content:\"nova\"; isdataat:!20,relative; sid:1;)";
721 
723 
724  UTHFreePacket(p);
725 
726  PASS;
727 }
728 
729 static int PayloadTestSig17(void)
730 {
731  uint8_t buf[] = { 0xEB, 0x29, 0x25, 0x38, 0x78, 0x25, 0x38, 0x78, 0x25 };
732  uint16_t buflen = 9;
733  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
734 
735  FAIL_IF_NULL(p);
736 
737  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
738  "content:\"%\"; depth:4; offset:0; "
739  "content:\"%\"; within:2; distance:1; sid:1;)";
740 
742 
743  UTHFreePacket(p);
744 
745  PASS;
746 }
747 
748 static int PayloadTestSig18(void)
749 {
750  uint8_t buf[] = {
751  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x35, /* the last byte is 2 */
752  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
753  0x0E, 0x0F,
754  };
755  uint16_t buflen = sizeof(buf);
756  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
757 
758  FAIL_IF_NULL(p);
759 
760  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
761  "content:\"|01 02 03 04|\"; "
762  "byte_extract:1,2,one,string,dec,relative; "
763  "content:\"|0C 0D 0E 0F|\"; distance:one; sid:1;)";
764 
766 
767  UTHFreePacket(p);
768 
769  PASS;
770 }
771 
772 static int PayloadTestSig19(void)
773 {
774  uint8_t buf[] = {
775  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x35, /* the last byte is 2 */
776  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
777  0x0E, 0x0F,
778  };
779  uint16_t buflen = sizeof(buf);
780  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
781 
782  FAIL_IF_NULL(p);
783 
784  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
785  "content:\"|01 02 03 04|\"; "
786  "byte_extract:1,2,one,string,hex,relative; "
787  "content:\"|0C 0D 0E 0F|\"; distance:one; sid:1;)";
788 
790 
791  UTHFreePacket(p);
792 
793  PASS;
794 }
795 
796 static int PayloadTestSig20(void)
797 {
798  uint8_t buf[] = {
799  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x35, /* the last byte is 2 */
800  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
801  0x0E, 0x0F,
802  };
803  uint16_t buflen = sizeof(buf);
804  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
805 
806  FAIL_IF_NULL(p);
807 
808  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
809  "content:\"|01 02 03 04|\"; "
810  "byte_extract:1,2,one,string,dec,relative; "
811  "content:\"|06 35 07 08|\"; offset:one; sid:1;)";
812 
814 
815  UTHFreePacket(p);
816 
817  PASS;
818 }
819 
820 static int PayloadTestSig21(void)
821 {
822  uint8_t buf[] = {
823  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x36, /* the last byte is 2 */
824  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
825  0x0E, 0x0F,
826  };
827  uint16_t buflen = sizeof(buf);
828  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
829 
830  FAIL_IF_NULL(p);
831 
832  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
833  "content:\"|01 02 03 04|\"; "
834  "byte_extract:1,2,one,string,dec,relative; "
835  "content:\"|03 04 05 06|\"; depth:one; sid:1;)";
836 
838 
839  UTHFreePacket(p);
840 
841  PASS;
842 }
843 
844 static int PayloadTestSig22(void)
845 {
846  uint8_t buf[] = {
847  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x36, /* the last byte is 2 */
848  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
849  0x0E, 0x0F,
850  };
851  uint16_t buflen = sizeof(buf);
852  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
853 
854  FAIL_IF_NULL(p);
855 
856  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
857  "content:\"|01 02 03 04|\"; "
858  "byte_extract:1,2,one,string,dec,relative; "
859  "content:\"|09 0A 0B 0C|\"; within:one; sid:1;)";
860 
862 
863  UTHFreePacket(p);
864 
865  PASS;
866 }
867 
868 static int PayloadTestSig23(void)
869 {
870  uint8_t buf[] = {
871  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x32, /* the last byte is 2 */
872  0x07, 0x08, 0x09, 0x33, 0x0B, 0x0C, 0x0D,
873  0x32, 0x0F,
874  };
875  uint16_t buflen = sizeof(buf);
876  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
877 
878  FAIL_IF_NULL(p);
879 
880  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
881  "content:\"|01 02 03 04|\"; "
882  "byte_extract:1,2,one,string,dec,relative; "
883  "byte_extract:1,3,two,string,dec,relative; "
884  "byte_test:1,=,one,two,string,dec,relative; sid:1;)";
885 
887 
888  UTHFreePacket(p);
889 
890  PASS;
891 }
892 
893 static int PayloadTestSig24(void)
894 {
895  uint8_t buf[] = {
896  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x32, /* the last byte is 2 */
897  0x07, 0x08, 0x33, 0x0A, 0x0B, 0x0C, 0x0D,
898  0x0E, 0x0F,
899  };
900  uint16_t buflen = sizeof(buf);
901  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
902 
903  FAIL_IF_NULL(p);
904 
905  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
906  "content:\"|01 02 03 04|\"; "
907  "byte_extract:1,2,one,string,dec,relative; "
908  "byte_jump:1,one,string,dec,relative; "
909  "content:\"|0D 0E 0F|\"; distance:0; sid:1;)";
910 
912 
913  UTHFreePacket(p);
914 
915  PASS;
916 }
917 
918 /*
919  * \test Test negative byte extract.
920  */
921 static int PayloadTestSig25(void)
922 {
923  uint8_t buf[] = {
924  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x35, /* the last byte is 2 */
925  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
926  0x0E, 0x0F,
927  };
928  uint16_t buflen = sizeof(buf);
929  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
930 
931  FAIL_IF_NULL(p);
932 
933  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
934  "content:\"|35 07 08 09|\"; "
935  "byte_extract:1,-4,one,string,dec,relative; "
936  "content:\"|0C 0D 0E 0F|\"; distance:one; sid:1;)";
937 
939 
940  UTHFreePacket(p);
941 
942  PASS;
943 }
944 
945 /*
946  * \test Test negative byte extract.
947  */
948 static int PayloadTestSig26(void)
949 {
950  uint8_t buf[] = {
951  0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x35, /* the last byte is 2 */
952  0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D,
953  0x0E, 0x0F,
954  };
955  uint16_t buflen = sizeof(buf);
956  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
957 
958  FAIL_IF_NULL(p);
959 
960  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
961  "content:\"|35 07 08 09|\"; "
962  "byte_extract:1,-3000,one,string,dec,relative; "
963  "content:\"|0C 0D 0E 0F|\"; distance:one; sid:1;)";
964 
966 
967  UTHFreePacket(p);
968 
969  PASS;
970 }
971 
972 /*
973  * \test Test packet/stream sigs
974  */
975 static int PayloadTestSig27(void)
976 {
977  uint8_t buf[] = "dummypayload";
978  uint16_t buflen = sizeof(buf) - 1;
979  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
980 
981  FAIL_IF_NULL(p);
982 
983  char sig[] = "alert tcp any any -> any any (content:\"dummy\"; "
984  "depth:5; sid:1;)";
985 
986  p->flags |= PKT_STREAM_ADD;
988 
989  UTHFreePacket(p);
990 
991  PASS;
992 }
993 
994 /*
995  * \test Test packet/stream sigs
996  */
997 static int PayloadTestSig28(void)
998 {
999  uint8_t buf[] = "dummypayload";
1000  uint16_t buflen = sizeof(buf) - 1;
1001  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1002 
1003  FAIL_IF_NULL(p);
1004 
1005  char sig[] = "alert tcp any any -> any any (content:\"payload\"; "
1006  "offset:4; depth:12; sid:1;)";
1007 
1008  p->flags |= PKT_STREAM_ADD;
1010 
1011  UTHFreePacket(p);
1012 
1013  PASS;
1014 }
1015 
1016 /**
1017  * \test Test pcre recursive matching - bug #529
1018  */
1019 static int PayloadTestSig29(void)
1020 {
1021  uint8_t *buf = (uint8_t *)"this is a super dupernova in super nova now";
1022  uint16_t buflen = strlen((char *)buf);
1023  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1024 
1025  FAIL_IF_NULL(p);
1026 
1027  char sig[] = "alert tcp any any -> any any (msg:\"dummy\"; "
1028  "pcre:/^.{4}/; content:\"nova\"; within:4; sid:1;)";
1029 
1031 
1032  UTHFreePacket(p);
1033 
1034  PASS;
1035 }
1036 
1037 static int PayloadTestSig30(void)
1038 {
1039  uint8_t *buf = (uint8_t *)
1040  "xyonexxxxxxtwojunkonetwo";
1041  uint16_t buflen = strlen((char *)buf);
1042  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1043 
1044  FAIL_IF_NULL(p);
1045 
1046  char sig[] = "alert tcp any any -> any any (content:\"one\"; pcre:\"/^two/R\"; sid:1;)";
1047 
1049 
1050  UTHFreePacket(p);
1051 
1052  PASS;
1053 }
1054 
1055 static int PayloadTestSig31(void)
1056 {
1057  uint8_t *buf = (uint8_t *)
1058  "xyonexxxxxxtwojunkonetwo";
1059  uint16_t buflen = strlen((char *)buf);
1060  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1061 
1062  FAIL_IF_NULL(p);
1063 
1064  char sig[] = "alert tcp any any -> any any (content:\"one\"; pcre:\"/(fiv|^two)/R\"; sid:1;)";
1065 
1067 
1068  UTHFreePacket(p);
1069 
1070  PASS;
1071 }
1072 
1073 /**
1074  * \test Test byte_jump.
1075  */
1076 static int PayloadTestSig32(void)
1077 {
1078  uint8_t *buf = (uint8_t *)"dummy2xxcardmessage";
1079  uint16_t buflen = strlen((char *)buf);
1080  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1081 
1082  FAIL_IF_NULL(p);
1083 
1084  char sig[] = "alert tcp any any -> any any (msg:\"crash\"; "
1085  "content:\"message\"; byte_jump:2,-14,string,dec,relative; content:\"card\"; within:4; sid:1;)";
1086 
1088 
1089  UTHFreePacket(p);
1090 
1091  PASS;
1092 }
1093 
1094 /**
1095  * \test Test byte_test.
1096  */
1097 static int PayloadTestSig33(void)
1098 {
1099  uint8_t *buf = (uint8_t *)"dummy2xxcardmessage";
1100  uint16_t buflen = strlen((char *)buf);
1101  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1102 
1103  FAIL_IF_NULL(p);
1104 
1105  char sig[] = "alert tcp any any -> any any (msg:\"crash\"; "
1106  "content:\"message\"; byte_test:1,=,2,-14,string,dec,relative; sid:1;)";
1107 
1109 
1110  UTHFreePacket(p);
1111 
1112  PASS;
1113 }
1114 
1115 /**
1116  * \test Test byte_extract.
1117  */
1118 static int PayloadTestSig34(void)
1119 {
1120  uint8_t *buf = (uint8_t *)"dummy2xxcardmessage";
1121  uint16_t buflen = strlen((char *)buf);
1122  Packet *p = UTHBuildPacket(buf, buflen, IPPROTO_TCP);
1123 
1124  FAIL_IF_NULL(p);
1125 
1126  char sig[] = "alert tcp any any -> any any (msg:\"crash\"; "
1127  "content:\"message\"; byte_extract:1,-14,boom,string,dec,relative; sid:1;)";
1128 
1130 
1131  UTHFreePacket(p);
1132 
1133  PASS;
1134 }
1135 
1136 #endif /* UNITTESTS */
1137 
1139 {
1140 #ifdef UNITTESTS
1141  UtRegisterTest("PayloadTestSig01", PayloadTestSig01);
1142  UtRegisterTest("PayloadTestSig02", PayloadTestSig02);
1143  UtRegisterTest("PayloadTestSig03", PayloadTestSig03);
1144  UtRegisterTest("PayloadTestSig04", PayloadTestSig04);
1145  UtRegisterTest("PayloadTestSig05", PayloadTestSig05);
1146  UtRegisterTest("PayloadTestSig06", PayloadTestSig06);
1147  UtRegisterTest("PayloadTestSig07", PayloadTestSig07);
1148  UtRegisterTest("PayloadTestSig08", PayloadTestSig08);
1149  UtRegisterTest("PayloadTestSig09", PayloadTestSig09);
1150  UtRegisterTest("PayloadTestSig10", PayloadTestSig10);
1151  UtRegisterTest("PayloadTestSig11", PayloadTestSig11);
1152  UtRegisterTest("PayloadTestSig12", PayloadTestSig12);
1153  UtRegisterTest("PayloadTestSig13", PayloadTestSig13);
1154  UtRegisterTest("PayloadTestSig14", PayloadTestSig14);
1155  UtRegisterTest("PayloadTestSig15", PayloadTestSig15);
1156  UtRegisterTest("PayloadTestSig16", PayloadTestSig16);
1157  UtRegisterTest("PayloadTestSig17", PayloadTestSig17);
1158 
1159  UtRegisterTest("PayloadTestSig18", PayloadTestSig18);
1160  UtRegisterTest("PayloadTestSig19", PayloadTestSig19);
1161  UtRegisterTest("PayloadTestSig20", PayloadTestSig20);
1162  UtRegisterTest("PayloadTestSig21", PayloadTestSig21);
1163  UtRegisterTest("PayloadTestSig22", PayloadTestSig22);
1164  UtRegisterTest("PayloadTestSig23", PayloadTestSig23);
1165  UtRegisterTest("PayloadTestSig24", PayloadTestSig24);
1166  UtRegisterTest("PayloadTestSig25", PayloadTestSig25);
1167  UtRegisterTest("PayloadTestSig26", PayloadTestSig26);
1168  UtRegisterTest("PayloadTestSig27", PayloadTestSig27);
1169  UtRegisterTest("PayloadTestSig28", PayloadTestSig28);
1170  UtRegisterTest("PayloadTestSig29", PayloadTestSig29);
1171 
1172  UtRegisterTest("PayloadTestSig30", PayloadTestSig30);
1173  UtRegisterTest("PayloadTestSig31", PayloadTestSig31);
1174  UtRegisterTest("PayloadTestSig32", PayloadTestSig32);
1175  UtRegisterTest("PayloadTestSig33", PayloadTestSig33);
1176  UtRegisterTest("PayloadTestSig34", PayloadTestSig34);
1177 #endif /* UNITTESTS */
1178 }
DetectEngineAppInspectionEngine_
Definition: detect.h:420
Packet_::proto
uint8_t proto
Definition: decode.h:538
TcpStream_
Definition: stream-tcp-private.h:106
DETECT_ENGINE_CONTENT_INSPECTION_MODE_STREAM
@ DETECT_ENGINE_CONTENT_INSPECTION_MODE_STREAM
Definition: detect-engine-content-inspection.h:34
MpmCtx_::mpm_type
uint8_t mpm_type
Definition: util-mpm.h:113
detect-engine.h
DETECT_SM_LIST_PMATCH
@ DETECT_SM_LIST_PMATCH
Definition: detect.h:120
StreamContentInspectEngineData::de_ctx
DetectEngineCtx * de_ctx
Definition: detect-engine-payload.c:262
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
StreamReassembleRaw
int StreamReassembleRaw(TcpSession *ssn, const Packet *p, StreamReassembleRawFunc Callback, void *cb_data, uint64_t *progress_out, bool respect_inspect_depth)
Definition: stream-tcp-reassemble.c:1912
stream-tcp.h
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
PcapPacketCntGet
uint64_t PcapPacketCntGet(const Packet *p)
Definition: decode.c:1193
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
Packet_::payload
uint8_t * payload
Definition: decode.h:620
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
Packet_::flags
uint32_t flags
Definition: decode.h:562
ssn
TcpSession ssn
Definition: fuzz_dataset.c:31
Flow_
Flow data structure.
Definition: flow.h:359
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
DetectEngineCtx_::inspection_recursion_limit
int inspection_recursion_limit
Definition: detect.h:1040
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
UTHPacketMatchSigMpm
int UTHPacketMatchSigMpm(Packet *p, char *sig, uint16_t mpm_type)
Definition: util-unittest-helper.c:768
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
DetectEngineThreadCtx_::p
Packet * p
Definition: detect.h:1396
DetectEngineInspectPacketPayload
uint8_t DetectEngineInspectPacketPayload(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const Signature *s, Flow *f, Packet *p)
Do the content inspection & validation for a signature.
Definition: detect-engine-payload.c:151
rust.h
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
TcpStream_::flags
uint16_t flags
Definition: stream-tcp-private.h:107
mpm_default_matcher
uint8_t mpm_default_matcher
Definition: util-mpm.c:47
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
Signature_::sm_arrays
SigMatchData * sm_arrays[DETECT_SM_LIST_MAX]
Definition: detect.h:759
PKT_NOPAYLOAD_INSPECTION
#define PKT_NOPAYLOAD_INSPECTION
Definition: decode.h:1297
detect-engine-payload.h
DetectEngineAppendSig
Signature * DetectEngineAppendSig(DetectEngineCtx *, const char *)
Parse and append a Signature into the Detection Engine Context signature list.
Definition: detect-parse.c:3965
Flow_::protoctx
void * protoctx
Definition: flow.h:438
SigMatchData_
Data needed for Match()
Definition: detect.h:369
Packet_::payload_len
uint16_t payload_len
Definition: decode.h:621
STREAMTCP_STREAM_FLAG_DEPTH_REACHED
#define STREAMTCP_STREAM_FLAG_DEPTH_REACHED
Definition: stream-tcp-private.h:223
DETECT_ENGINE_CONTENT_INSPECTION_MODE_PAYLOAD
@ DETECT_ENGINE_CONTENT_INSPECTION_MODE_PAYLOAD
Definition: detect-engine-content-inspection.h:32
detect-engine-prefilter.h
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
StreamMpmData::mpm_ctx
const MpmCtx * mpm_ctx
Definition: detect-engine-payload.c:54
decode.h
util-debug.h
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
StreamContentInspectData::de_ctx
DetectEngineCtx * de_ctx
Definition: detect-engine-payload.c:208
PKT_STREAM_ADD
#define PKT_STREAM_ADD
Definition: decode.h:1305
StreamMpmData::det_ctx
DetectEngineThreadCtx * det_ctx
Definition: detect-engine-payload.c:53
SIG_FLAG_FLUSH
#define SIG_FLAG_FLUSH
Definition: detect.h:262
DetectEngineInspectStreamPayload
int DetectEngineInspectStreamPayload(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const Signature *s, Flow *f, Packet *p)
Do the content inspection & validation for a signature on the raw stream.
Definition: detect-engine-payload.c:247
util-print.h
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
StreamContentInspectEngineData::s
const Signature * s
Definition: detect-engine-payload.c:264
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
DETECT_ENGINE_INSPECT_SIG_MATCH
#define DETECT_ENGINE_INSPECT_SIG_MATCH
Definition: detect-engine-state.h:41
PKT_DETECT_HAS_STREAMDATA
#define PKT_DETECT_HAS_STREAMDATA
Definition: decode.h:1350
DetectEngineCtx_::mpm_matcher
uint8_t mpm_matcher
Definition: detect.h:998
MpmCtx_::minlen
uint16_t minlen
Definition: util-mpm.h:122
DetectEngineContentInspection
bool DetectEngineContentInspection(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const Signature *s, const SigMatchData *smd, Packet *p, Flow *f, const uint8_t *buffer, const uint32_t buffer_len, const uint64_t stream_start_offset, const uint8_t flags, const enum DetectContentInspectionType inspection_mode)
wrapper around DetectEngineContentInspectionInternal to return true/false only
Definition: detect-engine-content-inspection.c:750
util-profiling.h
DetectEngineThreadCtx_::raw_stream_progress
uint64_t raw_stream_progress
Definition: detect.h:1337
DetectEngineInspectStream
uint8_t DetectEngineInspectStream(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
inspect engine for stateful rules
Definition: detect-engine-payload.c:297
SCReturn
#define SCReturn
Definition: util-debug.h:286
Signature_::flags
uint32_t flags
Definition: detect.h:693
stream.h
Packet_
Definition: decode.h:516
detect-engine-build.h
detect-engine-alert.h
PrefilterPktPayloadRegister
int PrefilterPktPayloadRegister(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx)
Definition: detect-engine-payload.c:131
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
util-mpm-ac.h
MpmTableElmt_::Search
uint32_t(* Search)(const struct MpmCtx_ *, struct MpmThreadCtx_ *, PrefilterRuleStore *, const uint8_t *, uint32_t)
Definition: util-mpm.h:200
DETECT_ENGINE_INSPECT_SIG_CANT_MATCH
#define DETECT_ENGINE_INSPECT_SIG_CANT_MATCH
Definition: detect-engine-state.h:42
DetectEngineThreadCtx_::mtc
MpmThreadCtx mtc
Definition: detect.h:1425
StreamContentInspectData::det_ctx
DetectEngineThreadCtx * det_ctx
Definition: detect-engine-payload.c:209
StreamContentInspectData::f
Flow * f
Definition: detect-engine-payload.c:211
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
PrefilterAppendPayloadEngine
int PrefilterAppendPayloadEngine(DetectEngineCtx *de_ctx, SigGroupHead *sgh, PrefilterPktFn PrefilterFunc, void *pectx, void(*FreeFunc)(void *pectx), const char *name)
Definition: detect-engine-prefilter.c:349
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
detect-engine-content-inspection.h
DetectEngineAppInspectionEngine_::smd
SigMatchData * smd
Definition: detect.h:444
th_v
ThreadVars * th_v
Definition: fuzz_dataset.c:29
PREFILTER_PROFILING_ADD_BYTES
#define PREFILTER_PROFILING_ADD_BYTES(det_ctx, bytes)
Definition: util-profiling.h:286
Packet_::flow
struct Flow_ * flow
Definition: decode.h:564
StreamMpmData
Definition: detect-engine-payload.c:52
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
DETECT_CI_FLAGS_SINGLE
#define DETECT_CI_FLAGS_SINGLE
Definition: detect-engine-content-inspection.h:50
flags
uint8_t flags
Definition: decode-gre.h:0
suricata-common.h
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
DetectEngineCtx_::sig_list
Signature * sig_list
Definition: detect.h:1005
TcpSession_::client
TcpStream client
Definition: stream-tcp-private.h:297
DETECT_ENGINE_INSPECT_SIG_NO_MATCH
#define DETECT_ENGINE_INSPECT_SIG_NO_MATCH
Definition: detect-engine-state.h:40
util-validate.h
StreamContentInspectEngineData
Definition: detect-engine-payload.c:261
TcpSession_::server
TcpStream server
Definition: stream-tcp-private.h:296
StreamContentInspectData
Definition: detect-engine-payload.c:207
StreamContentInspectEngineData::f
Flow * f
Definition: detect-engine-payload.c:266
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
UTHFreePacket
void UTHFreePacket(Packet *p)
UTHFreePacket: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:470
Signature_::id
uint32_t id
Definition: detect.h:741
StreamContentInspectEngineData::det_ctx
DetectEngineThreadCtx * det_ctx
Definition: detect-engine-payload.c:263
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
mpm_table
MpmTableElmt mpm_table[MPM_TABLE_SIZE]
Definition: util-mpm.c:46
suricata.h
StreamContentInspectData::s
const Signature * s
Definition: detect-engine-payload.c:210
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
MpmCtx_
Definition: util-mpm.h:111
TcpSession_
Definition: stream-tcp-private.h:283
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
PrefilterPktStreamRegister
int PrefilterPktStreamRegister(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx)
Definition: detect-engine-payload.c:108
StreamContentInspectEngineData::smd
const SigMatchData * smd
Definition: detect-engine-payload.c:265
PayloadRegisterTests
void PayloadRegisterTests(void)
Definition: detect-engine-payload.c:1138
f
Flow f
Definition: fuzz_dataset.c:32