suricata
detect-file-data.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  *
23  */
24 
25 #include "suricata-common.h"
26 #include "threads.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-parse.h"
31 
32 #include "detect-engine.h"
33 #include "detect-engine-buffer.h"
34 #include "detect-engine-mpm.h"
35 #include "detect-engine-state.h"
38 #include "detect-engine-file.h"
39 #include "detect-file-data.h"
40 
41 #include "app-layer.h"
42 #include "app-layer-parser.h"
43 #include "app-layer-htp.h"
44 #include "app-layer-smtp.h"
45 
46 #include "flow.h"
47 #include "flow-var.h"
48 #include "flow-util.h"
49 
50 #include "util-debug.h"
51 #include "util-spm-bm.h"
52 #include "util-unittest.h"
53 #include "util-unittest-helper.h"
55 #include "util-profiling.h"
56 
57 static int DetectFiledataSetup (DetectEngineCtx *, Signature *, const char *);
58 #ifdef UNITTESTS
59 static void DetectFiledataRegisterTests(void);
60 #endif
61 static void DetectFiledataSetupCallback(
62  const DetectEngineCtx *de_ctx, Signature *s, const DetectBufferType *map);
63 static int g_file_data_buffer_id = 0;
64 
65 /* file API */
67  const DetectBufferMpmRegistry *mpm_reg, int list_id);
68 
69 // file protocols with common file handling
70 typedef struct {
71  int direction;
73  uint8_t progress_ts;
74  uint8_t sub_state_ts;
75  uint8_t progress_tc;
76  uint8_t sub_state_tc;
78 
79 /* Table with all filehandler registrations */
81 
82 #define ALPROTO_WITHFILES_MAX 16
83 
84 // file protocols with common file handling
87  { .alproto = ALPROTO_SMB, .direction = SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT },
88  { .alproto = ALPROTO_FTP, .direction = SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT },
89  { .alproto = ALPROTO_FTPDATA, .direction = SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT },
90  { .alproto = ALPROTO_HTTP1,
91  .direction = SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT,
92  .progress_tc = HTP_RESPONSE_PROGRESS_BODY,
93  .progress_ts = HTP_REQUEST_PROGRESS_BODY },
94  {
95  .alproto = ALPROTO_HTTP2,
96  .direction = SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT,
97  .progress_tc = HTTP2ProgData,
98  .sub_state_tc = HTTP2TxTypeStream,
99  .progress_ts = HTTP2ProgData,
100  .sub_state_ts = HTTP2TxTypeStream,
101  },
102  { .alproto = ALPROTO_SMTP, .direction = SIG_FLAG_TOSERVER, .progress_ts = SMTP_REQUEST_DATA },
103  { .alproto = ALPROTO_UNKNOWN }
104 };
105 
107  AppProto alproto, int direction, uint8_t progress_tc, uint8_t progress_ts)
108 {
109  size_t i = 0;
110  while (i < ALPROTO_WITHFILES_MAX && al_protocols[i].alproto != ALPROTO_UNKNOWN) {
111  i++;
112  }
113  if (i == ALPROTO_WITHFILES_MAX) {
114  return;
115  }
116  al_protocols[i].alproto = alproto;
117  al_protocols[i].direction = direction;
118  al_protocols[i].progress_tc = progress_tc;
119  al_protocols[i].progress_ts = progress_ts;
120  if (i + 1 < ALPROTO_WITHFILES_MAX) {
122  }
123 }
124 
126 {
127  for (size_t i = 0; i < g_alproto_max; i++) {
129  if (p->alproto == ALPROTO_UNKNOWN) {
130  break;
131  }
132  int direction =
133  p->direction == 0 ? (int)(SIG_FLAG_TOSERVER | SIG_FLAG_TOCLIENT) : p->direction;
134 
135  if (direction & SIG_FLAG_TOCLIENT) {
137  reg->PrefilterFn, NULL, p->alproto, p->sub_state_tc, p->progress_tc);
139  p->sub_state_tc, p->progress_tc, reg->Callback, NULL);
140  }
141  if (direction & SIG_FLAG_TOSERVER) {
143  reg->PrefilterFn, NULL, p->alproto, p->sub_state_ts, p->progress_ts);
145  p->sub_state_ts, p->progress_ts, reg->Callback, NULL);
146  }
147  }
148 }
149 
150 /**
151  * \brief Registration function for keyword: file_data
152  */
154 {
155  sigmatch_table[DETECT_FILE_DATA].name = "file.data";
156  sigmatch_table[DETECT_FILE_DATA].alias = "file_data";
157  sigmatch_table[DETECT_FILE_DATA].desc = "make content keywords match on file data";
158  sigmatch_table[DETECT_FILE_DATA].url = "/rules/file-keywords.html#file-data";
159  sigmatch_table[DETECT_FILE_DATA].Setup = DetectFiledataSetup;
160 #ifdef UNITTESTS
162 #endif
165 
166  filehandler_table[DETECT_FILE_DATA].name = "file_data";
170 
171  DetectBufferTypeRegisterSetupCallback("file_data", DetectFiledataSetupCallback);
172 
173  DetectBufferTypeSetDescriptionByName("file_data", "data from tracked files");
175 
176  g_file_data_buffer_id = DetectBufferTypeGetByName("file_data");
177 }
178 
179 static void SetupDetectEngineConfig(DetectEngineCtx *de_ctx) {
180  if (de_ctx->filedata_config)
181  return;
182 
184  if (unlikely(de_ctx->filedata_config == NULL))
185  return;
186  /* initialize default */
187  for (AppProto i = 0; i < g_alproto_max; i++) {
190  }
191 
192  /* add protocol specific settings here */
193 
194  /* help scan-build understand the protocol specific logic is within the array bounds. */
196 
197  /* SMTP */
201 }
202 
203 /**
204  * \brief this function is used to parse filedata options
205  * \brief into the current signature
206  *
207  * \param de_ctx pointer to the Detection Engine Context
208  * \param s pointer to the Current Signature
209  * \param str pointer to the user provided "filestore" option
210  *
211  * \retval 0 on Success
212  * \retval -1 on Failure
213  */
214 static int DetectFiledataSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
215 {
216  SCEnter();
217 
218  if (s->alproto != ALPROTO_UNKNOWN && !AppLayerParserSupportsFiles(IPPROTO_TCP, s->alproto) &&
219  !AppLayerParserSupportsFiles(IPPROTO_UDP, s->alproto)) {
220  SCLogError("The 'file_data' keyword cannot be used with protocol %s",
222  return -1;
223  }
224 
226  !(s->flags & SIG_FLAG_TOSERVER) && (s->flags & SIG_FLAG_TOCLIENT)) {
227  SCLogError("The 'file-data' keyword cannot be used with SMTP flow:to_client or "
228  "flow:from_server.");
229  return -1;
230  }
231 
233  return -1;
234 
237  // we cannot use a transactional rule with a fast pattern to client and this
239  SCLogError("fast_pattern cannot be used on to_client keyword for "
240  "transactional rule with a streaming buffer to server %u",
241  s->id);
242  return -1;
243  }
245  }
246 
247  SetupDetectEngineConfig(de_ctx);
248  return 0;
249 }
250 
251 static void DetectFiledataSetupCallback(
252  const DetectEngineCtx *de_ctx, Signature *s, const DetectBufferType *map)
253 {
254  if (s->alproto == ALPROTO_HTTP1 || s->alproto == ALPROTO_UNKNOWN ||
255  s->alproto == ALPROTO_HTTP) {
257  }
258 
259  /* server body needs to be inspected in sync with stream if possible */
261 
262  SCLogDebug("callback invoked by %u", s->id);
263 }
264 
265 /* common */
266 
267 static void PrefilterMpmFiledataFree(void *ptr)
268 {
269  SCFree(ptr);
270 }
271 
272 /* file API based inspection */
273 
274 static inline InspectionBuffer *FiledataWithXformsGetDataCallback(DetectEngineThreadCtx *det_ctx,
275  const DetectEngineTransforms *transforms, const int list_id, int local_file_id,
276  InspectionBuffer *base_buffer)
277 {
278  InspectionBuffer *buffer = InspectionBufferMultipleForListGet(det_ctx, list_id, local_file_id);
279  if (buffer == NULL) {
280  SCLogDebug("list_id: %d: no buffer", list_id);
281  return NULL;
282  }
283  if (buffer->initialized) {
284  SCLogDebug("list_id: %d: returning %p", list_id, buffer);
285  return buffer;
286  }
287 
289  det_ctx, buffer, transforms, base_buffer->inspect, base_buffer->inspect_len);
290  buffer->inspect_offset = base_buffer->inspect_offset;
291  SCLogDebug("xformed buffer %p size %u", buffer, buffer->inspect_len);
292  SCReturnPtr(buffer, "InspectionBuffer");
293 }
294 
295 static InspectionBuffer *FiledataGetDataCallback(DetectEngineThreadCtx *det_ctx,
296  const DetectEngineTransforms *transforms, Flow *f, uint8_t flow_flags, File *cur_file,
297  const int list_id, const int base_id, int local_file_id, void *txv)
298 {
299  SCEnter();
300  SCLogDebug("starting: list_id %d base_id %d", list_id, base_id);
301 
302  InspectionBuffer *buffer = InspectionBufferMultipleForListGet(det_ctx, base_id, local_file_id);
303  SCLogDebug("base: buffer %p", buffer);
304  if (buffer == NULL)
305  return NULL;
306  if (base_id != list_id && buffer->inspect != NULL) {
307  SCLogDebug("handle xform %s", (list_id != base_id) ? "true" : "false");
308  return FiledataWithXformsGetDataCallback(
309  det_ctx, transforms, list_id, local_file_id, buffer);
310  }
311  if (buffer->initialized) {
312  SCLogDebug("base_id: %d, not first: use %p", base_id, buffer);
313  return buffer;
314  }
315 
316  const uint64_t file_size = FileDataSize(cur_file);
317  const DetectEngineCtx *de_ctx = det_ctx->de_ctx;
318  uint32_t content_limit = FILEDATA_CONTENT_LIMIT;
319  uint32_t content_inspect_min_size = FILEDATA_CONTENT_INSPECT_MIN_SIZE;
320  if (de_ctx->filedata_config) {
321  content_limit = de_ctx->filedata_config[f->alproto].content_limit;
322  content_inspect_min_size = de_ctx->filedata_config[f->alproto].content_inspect_min_size;
323  }
324 
325  SCLogDebug("[list %d] content_limit %u, content_inspect_min_size %u", list_id, content_limit,
326  content_inspect_min_size);
327 
328  SCLogDebug("[list %d] file %p size %" PRIu64 ", state %d", list_id, cur_file, file_size,
329  cur_file->state);
330 
331  /* no new data */
332  if (cur_file->content_inspected == file_size) {
333  SCLogDebug("no new data");
334  goto empty_return;
335  }
336 
337  if (file_size == 0) {
338  SCLogDebug("no data to inspect for this transaction");
339  goto empty_return;
340  }
341 
342  SCLogDebug("offset %" PRIu64, StreamingBufferGetOffset(cur_file->sb));
343  SCLogDebug("size %" PRIu64, cur_file->size);
344  SCLogDebug("content_inspected %" PRIu64, cur_file->content_inspected);
345  SCLogDebug("inspect_window %" PRIu32, cur_file->inspect_window);
346  SCLogDebug("inspect_min_size %" PRIu32, cur_file->inspect_min_size);
347 
348  bool ips = false;
349  uint64_t offset = 0;
350  if (f->alproto == ALPROTO_HTTP1) {
351 
352  htp_tx_t *tx = txv;
353  HtpState *htp_state = f->alstate;
354  ips = htp_state->cfg->http_body_inline;
355 
356  const bool body_done = AppLayerParserGetStateProgress(IPPROTO_TCP, ALPROTO_HTTP1, tx,
357  flow_flags) > HTP_RESPONSE_PROGRESS_BODY;
358 
359  SCLogDebug("response.body_limit %u file_size %" PRIu64
360  ", cur_file->inspect_min_size %" PRIu32 ", EOF %s, progress > body? %s",
361  htp_state->cfg->response.body_limit, file_size, cur_file->inspect_min_size,
362  flow_flags & STREAM_EOF ? "true" : "false", BOOL2STR(body_done));
363 
364  if (!htp_state->cfg->http_body_inline) {
365  /* inspect the body if the transfer is complete or we have hit
366  * our body size limit */
367  if ((htp_state->cfg->response.body_limit == 0 ||
368  file_size < htp_state->cfg->response.body_limit) &&
369  file_size < cur_file->inspect_min_size && !body_done &&
370  !(flow_flags & STREAM_EOF)) {
371  SCLogDebug("we still haven't seen the entire response body. "
372  "Let's defer body inspection till we see the "
373  "entire body.");
374  goto empty_return;
375  }
376  SCLogDebug("inline and we're continuing");
377  }
378 
379  bool force = (flow_flags & STREAM_EOF) || (cur_file->state > FILE_STATE_OPENED) ||
380  body_done || htp_state->cfg->http_body_inline;
381  /* get the inspect buffer
382  *
383  * make sure that we have at least the configured inspect_win size.
384  * If we have more, take at least 1/4 of the inspect win size before
385  * the new data.
386  */
387  if (cur_file->content_inspected == 0) {
388  if (!force && file_size < cur_file->inspect_min_size) {
389  SCLogDebug("skip as file_size %" PRIu64 " < inspect_min_size %u", file_size,
390  cur_file->inspect_min_size);
391  goto empty_return;
392  }
393  } else {
394  uint64_t new_data = file_size - cur_file->content_inspected;
395  DEBUG_VALIDATE_BUG_ON(new_data == 0);
396  if (new_data < cur_file->inspect_window) {
397  uint64_t inspect_short = cur_file->inspect_window - new_data;
398  if (cur_file->content_inspected < inspect_short) {
399  offset = 0;
400  SCLogDebug("offset %" PRIu64, offset);
401  } else {
402  offset = cur_file->content_inspected - inspect_short;
403  SCLogDebug("offset %" PRIu64, offset);
404  }
405  } else {
406  BUG_ON(cur_file->content_inspected == 0);
407  uint32_t margin = cur_file->inspect_window / 4;
408  if ((uint64_t)margin <= cur_file->content_inspected) {
409  offset = cur_file->content_inspected - (cur_file->inspect_window / 4);
410  } else {
411  offset = 0;
412  }
413  SCLogDebug("offset %" PRIu64 " (data from offset %" PRIu64 ")", offset,
414  file_size - offset);
415  }
416  }
417 
418  } else {
419  if ((content_limit == 0 || file_size < content_limit) &&
420  file_size < content_inspect_min_size && !(flow_flags & STREAM_EOF) &&
421  !(cur_file->state > FILE_STATE_OPENED)) {
422  SCLogDebug("we still haven't seen the entire content. "
423  "Let's defer content inspection till we see the "
424  "entire content. We've seen %ld and need at least %d",
425  file_size, content_inspect_min_size);
426  goto empty_return;
427  }
428  offset = cur_file->content_inspected;
429  }
430 
431  const uint8_t *data;
432  uint32_t data_len;
433 
434  SCLogDebug("Fetching data at offset: %ld", offset);
435  StreamingBufferGetDataAtOffset(cur_file->sb, &data, &data_len, offset);
436  SCLogDebug("data_len %u", data_len);
437  /* update inspected tracker */
438  buffer->inspect_offset = offset;
439 
440  if (ips && file_size < cur_file->inspect_min_size) {
441  // don't update content_inspected yet
442  } else {
443  SCLogDebug("content inspected: %" PRIu64, cur_file->content_inspected);
444  cur_file->content_inspected = MAX(cur_file->content_inspected, offset + data_len);
445  SCLogDebug("content inspected: %" PRIu64, cur_file->content_inspected);
446  }
447 
448  InspectionBufferSetupMulti(det_ctx, buffer, NULL, data, data_len);
449  SCLogDebug("[list %d] [before] buffer offset %" PRIu64 "; buffer len %" PRIu32
450  "; data_len %" PRIu32 "; file_size %" PRIu64,
451  list_id, buffer->inspect_offset, buffer->inspect_len, data_len, file_size);
452 
453  if (f->alproto == ALPROTO_HTTP1 && flow_flags & STREAM_TOCLIENT) {
454  HtpState *htp_state = f->alstate;
455  /* built-in 'transformation' */
456  if (htp_state->cfg->swf_decompression_enabled) {
457  int swf_file_type = FileIsSwfFile(data, data_len);
458  if (swf_file_type == FILE_SWF_ZLIB_COMPRESSION ||
459  swf_file_type == FILE_SWF_LZMA_COMPRESSION) {
460  SCLogDebug("decompressing ...");
461  (void)FileSwfDecompression(data, data_len, det_ctx, buffer,
462  htp_state->cfg->swf_compression_type, htp_state->cfg->swf_decompress_depth,
463  htp_state->cfg->swf_compress_depth);
464  SCLogDebug("uncompressed buffer %p size %u; buf: \"%s\"", buffer,
465  buffer->inspect_len, (char *)buffer->inspect);
466  }
467  }
468  }
469 
470  SCLogDebug("content inspected: %" PRIu64, cur_file->content_inspected);
471 
472  /* get buffer for the list id if it is different from the base id */
473  if (list_id != base_id) {
474  SCLogDebug("regular %d has been set up: now handle xforms id %d", base_id, list_id);
475  InspectionBuffer *tbuffer = FiledataWithXformsGetDataCallback(
476  det_ctx, transforms, list_id, local_file_id, buffer);
477  SCReturnPtr(tbuffer, "InspectionBuffer");
478  }
479  SCReturnPtr(buffer, "InspectionBuffer");
480 
481 empty_return:
483  return NULL;
484 }
485 
487  const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags,
488  void *alstate, void *txv, uint64_t tx_id)
489 {
490  const DetectEngineTransforms *transforms = NULL;
491  if (!engine->mpm) {
492  transforms = engine->v2.transforms;
493  }
494 
496  FileContainer *ffc = files.fc;
497  if (ffc == NULL) {
499  }
500  if (ffc->head == NULL) {
501  const bool eof = (AppLayerParserGetStateProgress(f->proto, f->alproto, txv, flags) >
502  engine->progress);
503  if (eof && engine->match_on_null) {
505  }
507  }
508 
509  int local_file_id = 0;
510  File *file = ffc->head;
511  for (; file != NULL; file = file->next) {
512  InspectionBuffer *buffer = FiledataGetDataCallback(det_ctx, transforms, f, flags, file,
513  engine->sm_list, engine->sm_list_base, local_file_id, txv);
514  if (buffer == NULL) {
515  local_file_id++;
516  continue;
517  }
518 
519  bool eof = (file->state == FILE_STATE_CLOSED);
520  uint8_t ciflags = eof ? DETECT_CI_FLAGS_END : 0;
521  if (buffer->inspect_offset == 0)
522  ciflags |= DETECT_CI_FLAGS_START;
523 
524  const bool match = DetectEngineContentInspection(de_ctx, det_ctx, s, engine->smd, NULL, f,
525  buffer->inspect, buffer->inspect_len, buffer->inspect_offset, ciflags,
527  if (match) {
529  }
530  local_file_id++;
531  }
532 
534 }
535 
536 typedef struct PrefilterMpmFiledata {
537  int list_id;
539  const MpmCtx *mpm_ctx;
542 
543 /** \brief Filedata Filedata Mpm prefilter callback
544  *
545  * \param det_ctx detection engine thread ctx
546  * \param pectx inspection context
547  * \param p packet to inspect
548  * \param f flow to inspect
549  * \param txv tx to inspect
550  * \param idx transaction id
551  * \param flags STREAM_* flags including direction
552  */
553 static void PrefilterTxFiledata(DetectEngineThreadCtx *det_ctx, const void *pectx, Packet *p,
554  Flow *f, void *txv, const uint64_t idx, const AppLayerTxData *txd, const uint8_t flags)
555 {
556  SCEnter();
557 
559  return;
560 
561  const PrefilterMpmFiledata *ctx = (const PrefilterMpmFiledata *)pectx;
562  const MpmCtx *mpm_ctx = ctx->mpm_ctx;
563  const int list_id = ctx->list_id;
564 
566  FileContainer *ffc = files.fc;
567  if (ffc != NULL) {
568  int local_file_id = 0;
569  for (File *file = ffc->head; file != NULL; file = file->next) {
570  InspectionBuffer *buffer = FiledataGetDataCallback(det_ctx, ctx->transforms, f, flags,
571  file, list_id, ctx->base_list_id, local_file_id, txv);
572  if (buffer == NULL) {
573  local_file_id++;
574  continue;
575  }
576  SCLogDebug("[%" PRIu64 "] buffer size %u", PcapPacketCntGet(p), buffer->inspect_len);
577 
578  if (buffer->inspect_len >= mpm_ctx->minlen) {
579  uint32_t prev_rule_id_array_cnt = det_ctx->pmq.rule_id_array_cnt;
580  (void)mpm_table[mpm_ctx->mpm_type].Search(mpm_ctx, &det_ctx->mtc, &det_ctx->pmq,
581  buffer->inspect, buffer->inspect_len);
582  PREFILTER_PROFILING_ADD_BYTES(det_ctx, buffer->inspect_len);
583 
584  if (det_ctx->pmq.rule_id_array_cnt > prev_rule_id_array_cnt) {
585  SCLogDebug(
586  "%u matches", det_ctx->pmq.rule_id_array_cnt - prev_rule_id_array_cnt);
587  }
588  }
589  local_file_id++;
590  }
591  }
592 }
593 
595  const DetectBufferMpmRegistry *mpm_reg, int list_id)
596 {
597  PrefilterMpmFiledata *pectx = SCCalloc(1, sizeof(*pectx));
598  if (pectx == NULL)
599  return -1;
600  pectx->list_id = list_id;
601  pectx->base_list_id = mpm_reg->sm_list_base;
602  pectx->mpm_ctx = mpm_ctx;
603  pectx->transforms = &mpm_reg->transforms;
604 
605  return PrefilterAppendTxEngineSubState(de_ctx, sgh, PrefilterTxFiledata,
606  mpm_reg->app_v2.alproto, mpm_reg->app_v2.sub_state, mpm_reg->app_v2.tx_min_progress,
607  pectx, PrefilterMpmFiledataFree, mpm_reg->pname);
608 }
609 
610 #ifdef UNITTESTS
611 #include "tests/detect-file-data.c"
612 #endif
DETECT_TBLSIZE_STATIC
@ DETECT_TBLSIZE_STATIC
Definition: detect-engine-register.h:296
HtpState_::cfg
const struct HTPCfgRec_ * cfg
Definition: app-layer-htp.h:190
AppLayerParserHasFilesInDir
#define AppLayerParserHasFilesInDir(txd, direction)
check if tx (possibly) has files in this tx for the direction
Definition: app-layer-parser.h:362
SMTPConfig::content_limit
uint32_t content_limit
Definition: app-layer-smtp.h:121
DetectEngineAppInspectionEngine_
Definition: detect.h:416
SigTableElmt_::url
const char * url
Definition: detect.h:1521
PrefilterAppendTxEngineSubState
int PrefilterAppendTxEngineSubState(DetectEngineCtx *de_ctx, SigGroupHead *sgh, PrefilterTxFn PrefilterTxFunc, AppProto alproto, uint8_t sub_state, const int8_t tx_min_progress, void *pectx, void(*FreeFunc)(void *pectx), const char *name)
Definition: detect-engine-prefilter.c:374
DetectEngineAppInspectionEngine_::mpm
bool mpm
Definition: detect.h:420
FileContainer_
Definition: util-file.h:37
MpmCtx_::mpm_type
uint8_t mpm_type
Definition: util-mpm.h:99
DetectEngineAppInspectionEngine_::v2
struct DetectEngineAppInspectionEngine_::@82 v2
detect-engine.h
DetectBufferTypeRegisterSetupCallback
void DetectBufferTypeRegisterSetupCallback(const char *name, void(*SetupCallback)(const DetectEngineCtx *, Signature *, const DetectBufferType *))
Definition: detect-engine.c:1640
SigTableElmt_::desc
const char * desc
Definition: detect.h:1520
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:79
offset
uint64_t offset
Definition: util-streaming-buffer.h:0
DETECT_CI_FLAGS_START
#define DETECT_CI_FLAGS_START
Definition: detect-engine-content-inspection.h:40
al_protocols
DetectFileHandlerProtocol al_protocols[ALPROTO_WITHFILES_MAX]
Definition: detect-file-data.c:85
flow-util.h
SigTableElmt_::name
const char * name
Definition: detect.h:1518
InspectionBuffer::initialized
bool initialized
Definition: detect-engine-inspect-buffer.h:38
PrefilterRuleStore_::rule_id_array_cnt
uint32_t rule_id_array_cnt
Definition: util-prefilter.h:40
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1693
SIG_FLAG_INIT_FLOW
#define SIG_FLAG_INIT_FLOW
Definition: detect.h:291
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
DetectEngineTransforms
Definition: detect.h:391
DetectBufferMpmRegistry_::sm_list_base
int16_t sm_list_base
Definition: detect.h:782
HTPCfgRec_::response
HTPCfgDir response
Definition: app-layer-htp.h:117
File_::inspect_min_size
uint32_t inspect_min_size
Definition: util-file.h:171
SIG_FLAG_INIT_NEED_FLUSH
#define SIG_FLAG_INIT_NEED_FLUSH
Definition: detect.h:297
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1509
File_::size
uint64_t size
Definition: util-file.h:169
PcapPacketCntGet
uint64_t PcapPacketCntGet(const Packet *p)
Definition: decode.c:1180
Signature_::alproto
AppProto alproto
Definition: detect.h:687
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
SIG_FLAG_INIT_FILEDATA
#define SIG_FLAG_INIT_FILEDATA
Definition: detect.h:300
DetectEngineCtx_::filedata_config
DetectFileDataCfg * filedata_config
Definition: detect.h:1095
HTPCfgDir_::body_limit
uint32_t body_limit
Definition: app-layer-htp.h:96
SIG_FLAG_INIT_TXDIR_FAST_TOCLIENT
#define SIG_FLAG_INIT_TXDIR_FAST_TOCLIENT
Definition: detect.h:306
DetectBufferMpmRegistry_::app_v2
struct DetectBufferMpmRegistry_::@90::@92 app_v2
Flow_::proto
uint8_t proto
Definition: flow.h:376
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
DetectFileDataCfg
Definition: detect.h:963
FileSwfDecompression
int FileSwfDecompression(const uint8_t *buffer, uint32_t buffer_len, DetectEngineThreadCtx *det_ctx, InspectionBuffer *out_buffer, int swf_type, uint32_t decompress_depth, uint32_t compress_depth)
This function decompresses a buffer with zlib/lzma algorithm.
Definition: util-file-decompression.c:71
InspectionBuffer
Definition: detect-engine-inspect-buffer.h:34
threads.h
FILE_STATE_OPENED
@ FILE_STATE_OPENED
Definition: util-file.h:137
Flow_
Flow data structure.
Definition: flow.h:354
File_::state
FileState state
Definition: util-file.h:149
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1408
ctx
struct Thresholds ctx
AppLayerParserSupportsFiles
bool AppLayerParserSupportsFiles(uint8_t ipproto, AppProto alproto)
Definition: app-layer-parser.c:1436
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:981
PrefilterMpmFiledataRegister
int PrefilterMpmFiledataRegister(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx, const DetectBufferMpmRegistry *mpm_reg, int list_id)
Definition: detect-file-data.c:594
DetectBufferTypeSupportsMultiInstance
void DetectBufferTypeSupportsMultiInstance(const char *name)
Definition: detect-engine.c:1405
SIG_FLAG_INIT_FORCE_TOCLIENT
#define SIG_FLAG_INIT_FORCE_TOCLIENT
Definition: detect.h:301
DetectBufferMpmRegistry_
one time registration of keywords at start up
Definition: detect.h:777
detect-file-data.h
DetectEngineAppInspectionEngine_::sm_list_base
uint16_t sm_list_base
Definition: detect.h:425
ALPROTO_FTP
@ ALPROTO_FTP
Definition: app-layer-protos.h:37
FILEDATA_CONTENT_LIMIT
#define FILEDATA_CONTENT_LIMIT
Definition: app-layer-smtp.c:59
SCDetectBufferSetActiveList
int SCDetectBufferSetActiveList(DetectEngineCtx *de_ctx, Signature *s, const int list)
Definition: detect-engine-buffer.c:29
SignatureInitData_::init_flags
uint32_t init_flags
Definition: detect.h:615
DetectBufferType_
Definition: detect.h:450
p
Packet * p
Definition: fuzz_iprep.c:21
HTPCfgRec_::swf_compress_depth
uint32_t swf_compress_depth
Definition: app-layer-htp.h:114
StreamingBufferGetDataAtOffset
int StreamingBufferGetDataAtOffset(const StreamingBuffer *sb, const uint8_t **data, uint32_t *data_len, uint64_t offset)
Definition: util-streaming-buffer.c:1827
SIG_FLAG_TOCLIENT
#define SIG_FLAG_TOCLIENT
Definition: detect.h:271
MAX
#define MAX(x, y)
Definition: suricata-common.h:420
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1500
PrefilterMpmFiledata
struct PrefilterMpmFiledata PrefilterMpmFiledata
DetectBufferMpmRegistry_::transforms
DetectEngineTransforms transforms
Definition: detect.h:790
DetectAppLayerMpmRegisterSubState
void DetectAppLayerMpmRegisterSubState(const char *name, int direction, int priority, PrefilterRegisterFunc PrefilterRegister, InspectionBufferGetDataPtr GetData, AppProto alproto, uint8_t sub_state, uint8_t tx_min_progress)
Definition: detect-engine-mpm.c:167
detect-engine-prefilter.h
util-unittest.h
HtpState_
Definition: app-layer-htp.h:183
SMTPConfig::content_inspect_min_size
uint32_t content_inspect_min_size
Definition: app-layer-smtp.h:122
util-unittest-helper.h
AppLayerParserGetTxFiles
AppLayerGetFileState AppLayerParserGetTxFiles(const Flow *f, void *tx, const uint8_t direction)
Definition: app-layer-parser.c:958
DetectBufferTypeGetByName
int DetectBufferTypeGetByName(const char *name)
Definition: detect-engine.c:1455
File_::sb
StreamingBuffer * sb
Definition: util-file.h:150
DetectEngineAppInspectionEngine_::sm_list
uint16_t sm_list
Definition: detect.h:424
DETECT_ENGINE_INSPECT_SIG_CANT_MATCH_FILES
#define DETECT_ENGINE_INSPECT_SIG_CANT_MATCH_FILES
Definition: detect-engine-state.h:46
SIGMATCH_SUPPORT_DIR
#define SIGMATCH_SUPPORT_DIR
Definition: detect-engine-register.h:336
SIGMATCH_INFO_MULTI_BUFFER
#define SIGMATCH_INFO_MULTI_BUFFER
Definition: detect-engine-register.h:338
PrefilterMpmFiledata::transforms
const DetectEngineTransforms * transforms
Definition: detect-file-data.c:540
SIG_FLAG_TOSERVER
#define SIG_FLAG_TOSERVER
Definition: detect.h:270
app-layer-htp.h
DetectFileDataCfg::content_inspect_min_size
uint32_t content_inspect_min_size
Definition: detect.h:965
decode.h
DetectBufferMpmRegistry_::pname
char pname[DETECT_PROFILE_NAME_LEN]
Definition: detect.h:779
util-debug.h
HTPCfgRec_::http_body_inline
int http_body_inline
Definition: app-layer-htp.h:109
AppLayerTxData
Definition: app-layer-parser.h:166
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
g_alproto_max
AppProto g_alproto_max
Definition: app-layer-protos.c:30
DetectEngineThreadCtx_
Definition: detect.h:1300
ALPROTO_SMTP
@ ALPROTO_SMTP
Definition: app-layer-protos.h:38
detect-engine-file.h
BOOL2STR
#define BOOL2STR(b)
Definition: util-debug.h:542
SCEnter
#define SCEnter(...)
Definition: util-debug.h:284
detect-engine-mpm.h
FileContainer_::head
File * head
Definition: util-file.h:38
detect.h
DetectFileHandlerProtocol::alproto
AppProto alproto
Definition: detect-file-data.c:72
HTPCfgRec_::swf_decompress_depth
uint32_t swf_decompress_depth
Definition: app-layer-htp.h:113
ALPROTO_WITHFILES_MAX
#define ALPROTO_WITHFILES_MAX
Definition: detect-file-data.c:82
DETECT_ENGINE_INSPECT_SIG_MATCH
#define DETECT_ENGINE_INSPECT_SIG_MATCH
Definition: detect-engine-state.h:41
PrefilterMpmFiledata::mpm_ctx
const MpmCtx * mpm_ctx
Definition: detect-file-data.c:539
DetectFiledataRegister
void DetectFiledataRegister(void)
Registration function for keyword: file_data.
Definition: detect-file-data.c:153
HTPCfgRec_::swf_decompression_enabled
int swf_decompression_enabled
Definition: app-layer-htp.h:111
FILEDATA_CONTENT_INSPECT_MIN_SIZE
#define FILEDATA_CONTENT_INSPECT_MIN_SIZE
Definition: app-layer-smtp.c:61
InspectionBuffer::inspect_offset
uint64_t inspect_offset
Definition: detect-engine-inspect-buffer.h:36
DETECT_ENGINE_CONTENT_INSPECTION_MODE_STATE
@ DETECT_ENGINE_CONTENT_INSPECTION_MODE_STATE
Definition: detect-engine-content-inspection.h:36
app-layer-parser.h
MpmCtx_::minlen
uint16_t minlen
Definition: util-mpm.h:108
DetectEngineContentInspection
bool DetectEngineContentInspection(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const Signature *s, const SigMatchData *smd, Packet *p, Flow *f, const uint8_t *buffer, const uint32_t buffer_len, const uint64_t stream_start_offset, const uint8_t flags, const enum DetectContentInspectionType inspection_mode)
wrapper around DetectEngineContentInspectionInternal to return true/false only
Definition: detect-engine-content-inspection.c:751
AppLayerParserGetStateProgress
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
Definition: app-layer-parser.c:1225
BUG_ON
#define BUG_ON(x)
Definition: suricata-common.h:325
smtp_config
SMTPConfig smtp_config
Definition: app-layer-smtp.c:349
DetectFileHandlerTableElmt_
Definition: detect-file-data.h:32
util-profiling.h
PrefilterMpmFiledata::base_list_id
int base_list_id
Definition: detect-file-data.c:538
Signature_::flags
uint32_t flags
Definition: detect.h:683
DetectFileHandlerProtocol::progress_tc
uint8_t progress_tc
Definition: detect-file-data.c:75
Packet_
Definition: decode.h:516
DETECT_CI_FLAGS_END
#define DETECT_CI_FLAGS_END
Definition: detect-engine-content-inspection.h:42
DetectEngineAppInspectionEngine_::match_on_null
bool match_on_null
Definition: detect.h:423
DetectFileRegisterProto
void DetectFileRegisterProto(AppProto alproto, int direction, uint8_t progress_tc, uint8_t progress_ts)
Definition: detect-file-data.c:106
DetectFileDataCfg::content_limit
uint32_t content_limit
Definition: detect.h:964
Signature_::init_data
SignatureInitData * init_data
Definition: detect.h:761
SCReturnPtr
#define SCReturnPtr(x, type)
Definition: util-debug.h:300
FileIsSwfFile
int FileIsSwfFile(const uint8_t *buffer, uint32_t buffer_len)
Definition: util-file-decompression.c:41
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
AppLayerHtpEnableResponseBodyCallback
void AppLayerHtpEnableResponseBodyCallback(void)
Sets a flag that informs the HTP app layer that some module in the engine needs the http request body...
Definition: app-layer-htp.c:560
DetectFileHandlerTableElmt_::priority
int priority
Definition: detect-file-data.h:34
HTPCfgRec_::swf_compression_type
HtpSwfCompressType swf_compression_type
Definition: app-layer-htp.h:112
ALPROTO_HTTP2
@ ALPROTO_HTTP2
Definition: app-layer-protos.h:69
MpmTableElmt_::Search
uint32_t(* Search)(const struct MpmCtx_ *, struct MpmThreadCtx_ *, PrefilterRuleStore *, const uint8_t *, uint32_t)
Definition: util-mpm.h:186
DetectFileHandlerProtocol::direction
int direction
Definition: detect-file-data.c:71
DETECT_FILE_DATA
@ DETECT_FILE_DATA
Definition: detect-engine-register.h:202
DetectEngineThreadCtx_::mtc
MpmThreadCtx mtc
Definition: detect.h:1404
FileDataSize
uint64_t FileDataSize(const File *file)
get the size of the file data
Definition: util-file.c:308
DetectFileHandlerProtocol
Definition: detect-file-data.c:70
detect-engine-content-inspection.h
DetectEngineAppInspectionEngine_::smd
SigMatchData * smd
Definition: detect.h:440
File_::content_inspected
uint64_t content_inspected
Definition: util-file.h:166
FILE_STATE_CLOSED
@ FILE_STATE_CLOSED
Definition: util-file.h:138
File_
Definition: util-file.h:146
PREFILTER_PROFILING_ADD_BYTES
#define PREFILTER_PROFILING_ADD_BYTES(det_ctx, bytes)
Definition: util-profiling.h:286
flags
uint8_t flags
Definition: decode-gre.h:0
SigTableElmt_::alias
const char * alias
Definition: detect.h:1519
SMTP_REQUEST_DATA
@ SMTP_REQUEST_DATA
Definition: app-layer-smtp.h:75
AppLayerGetFileState
Definition: util-file.h:44
suricata-common.h
AppLayerGetFileState::fc
FileContainer * fc
Definition: util-file.h:45
SIGMATCH_OPTIONAL_OPT
#define SIGMATCH_OPTIONAL_OPT
Definition: detect-engine-register.h:313
ALPROTO_HTTP1
@ ALPROTO_HTTP1
Definition: app-layer-protos.h:36
File_::next
struct File_ * next
Definition: util-file.h:159
ALPROTO_FTPDATA
@ ALPROTO_FTPDATA
Definition: app-layer-protos.h:53
detect-engine-buffer.h
DetectFileHandlerTableElmt_::PrefilterFn
PrefilterRegisterFunc PrefilterFn
Definition: detect-file-data.h:35
util-spm-bm.h
DETECT_ENGINE_INSPECT_SIG_NO_MATCH
#define DETECT_ENGINE_INSPECT_SIG_NO_MATCH
Definition: detect-engine-state.h:40
DetectFileHandlerProtocol::sub_state_tc
uint8_t sub_state_tc
Definition: detect-file-data.c:76
DetectAppLayerInspectEngineRegisterSubState
void DetectAppLayerInspectEngineRegisterSubState(const char *name, AppProto alproto, uint32_t dir, uint8_t sub_state, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
register an app inspection engine for a tx type
Definition: detect-engine.c:299
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
SIG_FLAG_INIT_TXDIR_STREAMING_TOSERVER
#define SIG_FLAG_INIT_TXDIR_STREAMING_TOSERVER
Definition: detect.h:304
InspectionBuffer::inspect_len
uint32_t inspect_len
Definition: detect-engine-inspect-buffer.h:37
DetectFiledataRegisterTests
void DetectFiledataRegisterTests(void)
Definition: detect-file-data.c:64
InspectionBuffer::inspect
const uint8_t * inspect
Definition: detect-engine-inspect-buffer.h:35
str
#define str(s)
Definition: suricata-common.h:316
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
FILE_SWF_LZMA_COMPRESSION
@ FILE_SWF_LZMA_COMPRESSION
Definition: util-file-decompression.h:34
Flow_::alstate
void * alstate
Definition: flow.h:479
Signature_::id
uint32_t id
Definition: detect.h:727
detect-parse.h
Signature_
Signature container.
Definition: detect.h:682
AppLayerGetProtoName
const char * AppLayerGetProtoName(AppProto alproto)
Given the internal protocol id, returns a string representation of the protocol.
Definition: app-layer.c:1014
DetectEngineAppInspectionEngine_::transforms
const DetectEngineTransforms * transforms
Definition: detect.h:437
util-file-decompression.h
ALPROTO_HTTP
@ ALPROTO_HTTP
Definition: app-layer-protos.h:77
ALPROTO_UNKNOWN
@ ALPROTO_UNKNOWN
Definition: app-layer-protos.h:29
File_::inspect_window
uint32_t inspect_window
Definition: util-file.h:170
mpm_table
MpmTableElmt mpm_table[MPM_TABLE_SIZE]
Definition: util-mpm.c:47
DetectFileHandlerTableElmt_::Callback
InspectEngineFuncPtr Callback
Definition: detect-file-data.h:36
DetectEngineThreadCtx_::de_ctx
DetectEngineCtx * de_ctx
Definition: detect.h:1423
InspectionBufferSetupMultiEmpty
void InspectionBufferSetupMultiEmpty(InspectionBuffer *buffer)
setup the buffer empty
Definition: detect-engine-inspect-buffer.c:144
DetectFileHandlerProtocol::sub_state_ts
uint8_t sub_state_ts
Definition: detect-file-data.c:74
ALPROTO_SMB
@ ALPROTO_SMB
Definition: app-layer-protos.h:43
DetectFileHandlerTableElmt_::name
const char * name
Definition: detect-file-data.h:33
app-layer-smtp.h
DetectBufferTypeSetDescriptionByName
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
Definition: detect-engine.c:1552
PrefilterMpmFiledata
Definition: detect-file-data.c:536
MpmCtx_
Definition: util-mpm.h:97
flow.h
detect-file-data.c
Flow_::alproto
AppProto alproto
application level protocol
Definition: flow.h:450
FILE_SWF_ZLIB_COMPRESSION
@ FILE_SWF_ZLIB_COMPRESSION
Definition: util-file-decompression.h:33
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
PrefilterMpmFiledata::list_id
int list_id
Definition: detect-file-data.c:537
DetectFileRegisterFileProtocols
void DetectFileRegisterFileProtocols(DetectFileHandlerTableElmt *reg)
Definition: detect-file-data.c:125
flow-var.h
DetectEngineInspectFiledata
uint8_t DetectEngineInspectFiledata(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Definition: detect-file-data.c:486
filehandler_table
DetectFileHandlerTableElmt filehandler_table[DETECT_TBLSIZE_STATIC]
Definition: detect-file-data.c:80
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
InspectionBufferSetupMulti
void InspectionBufferSetupMulti(DetectEngineThreadCtx *det_ctx, InspectionBuffer *buffer, const DetectEngineTransforms *transforms, const uint8_t *data, const uint32_t data_len)
setup the buffer with our initial data
Definition: detect-engine-inspect-buffer.c:157
ALPROTO_NFS
@ ALPROTO_NFS
Definition: app-layer-protos.h:51
InspectionBufferMultipleForListGet
InspectionBuffer * InspectionBufferMultipleForListGet(DetectEngineThreadCtx *det_ctx, const int list_id, const uint32_t local_id)
for a InspectionBufferMultipleForList get a InspectionBuffer
Definition: detect-engine-inspect-buffer.c:76
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1507
app-layer.h
DetectEngineAppInspectionEngine_::progress
uint8_t progress
Definition: detect.h:426
DetectFileHandlerProtocol::progress_ts
uint8_t progress_ts
Definition: detect-file-data.c:73