suricata
detect-file-data.h
Go to the documentation of this file.
1 /* Copyright (C) 2007-2011 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Victor Julien <victor@inliniac.net>
22  */
23 
24 #ifndef SURICATA_DETECT_FILEDATA_H
25 #define SURICATA_DETECT_FILEDATA_H
26 
27 /* prototypes */
28 void DetectFiledataRegister (void);
29 
30 /* File handler registration */
31 #define MAX_DETECT_ALPROTO_CNT 10
33  const char *name;
34  int priority;
39 
40 /* File registration table */
42 
44  const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags,
45  void *alstate, void *txv, uint64_t tx_id);
47  const DetectBufferMpmRegistry *mpm_reg, int list_id);
48 
49 #endif /* SURICATA_DETECT_FILEDATA_H */
DETECT_TBLSIZE_STATIC
@ DETECT_TBLSIZE_STATIC
Definition: detect-engine-register.h:296
DetectEngineAppInspectionEngine_
Definition: detect.h:416
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1679
DetectFileHandlerTableElmt
struct DetectFileHandlerTableElmt_ DetectFileHandlerTableElmt
Flow_
Flow data structure.
Definition: flow.h:354
DetectEngineInspectFiledata
uint8_t DetectEngineInspectFiledata(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Definition: detect-file-data.c:479
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:973
DetectBufferMpmRegistry_
one time registration of keywords at start up
Definition: detect.h:770
filehandler_table
DetectFileHandlerTableElmt filehandler_table[DETECT_TBLSIZE_STATIC]
Definition: detect-file-data.c:78
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1291
DetectFileHandlerTableElmt_
Definition: detect-file-data.h:32
PrefilterRegisterFunc
int(* PrefilterRegisterFunc)(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx, const DetectBufferMpmRegistry *mpm_reg, int list_id)
Definition: detect-engine-mpm.h:72
DetectFileHandlerTableElmt_::priority
int priority
Definition: detect-file-data.h:34
InspectEngineFuncPtr
uint8_t(* InspectEngineFuncPtr)(struct DetectEngineCtx_ *de_ctx, struct DetectEngineThreadCtx_ *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const struct Signature_ *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Definition: detect.h:411
flags
uint8_t flags
Definition: decode-gre.h:0
DetectFiledataRegister
void DetectFiledataRegister(void)
Registration function for keyword: file_data.
Definition: detect-file-data.c:146
DetectFileHandlerTableElmt_::PrefilterFn
PrefilterRegisterFunc PrefilterFn
Definition: detect-file-data.h:35
PrefilterMpmFiledataRegister
int PrefilterMpmFiledataRegister(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx, const DetectBufferMpmRegistry *mpm_reg, int list_id)
Definition: detect-file-data.c:587
Signature_
Signature container.
Definition: detect.h:675
DetectFileRegisterFileProtocols
void DetectFileRegisterFileProtocols(DetectFileHandlerTableElmt *entry)
Definition: detect-file-data.c:118
DetectFileHandlerTableElmt_::Callback
InspectEngineFuncPtr Callback
Definition: detect-file-data.h:36
DetectFileHandlerTableElmt_::name
const char * name
Definition: detect-file-data.h:33
MpmCtx_
Definition: util-mpm.h:97