detect-engine-state.h File Reference

Data structures and function prototypes for keeping state for the detection engine. More...

Go to the source code of this file.

Data Structures

struct  DeStateStoreItem_
struct  DeStateStore_
struct  DetectEngineStateDirection_
struct  DetectEngineState_
#define DE_STATE_CHUNK_SIZE   15
typedef struct DeStateStoreItem_ DeStateStoreItem
typedef struct DeStateStore_ DeStateStore
typedef struct DetectEngineStateDirection_ DetectEngineStateDirection
typedef struct DetectEngineState_ DetectEngineState
DetectEngineStateDetectEngineStateAlloc (void)
 Alloc a DetectEngineState object. More...
void DetectEngineStateFree (DetectEngineState *state)
 Frees a DetectEngineState object. More...

Detailed Description

Data structures and function prototypes for keeping state for the detection engine.

Victor Julien
Anoop Saldanha

Definition in file detect-engine-state.h.

Macro Definition Documentation


#define DE_STATE_CHUNK_SIZE   15

number of DeStateStoreItem's in one DeStateStore object

Definition at line 53 of file detect-engine-state.h.



Definition at line 64 of file detect-engine-state.h.



Definition at line 61 of file detect-engine-state.h.



Definition at line 56 of file detect-engine-state.h.



Definition at line 57 of file detect-engine-state.h.



Definition at line 60 of file detect-engine-state.h.



Definition at line 40 of file detect-engine-state.h.



indicate that the file inspection portion of a sig didn't match. This is used to handle state keeping as the detect engine is still only marginally aware of files.

Definition at line 44 of file detect-engine-state.h.



Definition at line 39 of file detect-engine-state.h.



hack to work around a file inspection limitation. Since there can be multiple files in a TX and the detection engine really don't know about that, we have to give the file inspection engine a way to indicate that one of the files matched, but that there are still more files that have ongoing inspection.

Definition at line 50 of file detect-engine-state.h.



Definition at line 38 of file detect-engine-state.h.



Definition at line 71 of file detect-engine-state.h.

Typedef Documentation

◆ DeStateStore

typedef struct DeStateStore_ DeStateStore

◆ DeStateStoreItem

◆ DetectEngineState

◆ DetectEngineStateDirection