47 #define PARSE_REGEX "^\\s*([A-z_]+)\\s*(?:,\\s*([A-z_]+))?\\s*(?:,\\s*([A-z_]+))?\\s*$"
55 static void DetectFlowRegisterTests(
void);
60 static bool PrefilterFlowIsPrefilterable(
const Signature *s);
89 static inline int FlowMatch(
const uint32_t pflags,
const uint8_t pflowflags,
const uint16_t dflags,
90 const uint16_t match_cnt)
116 return (match_cnt ==
cnt) ? 1 : 0;
150 SCLogDebug(
"returning %" PRId32
" fd->match_cnt %" PRId32
" fd->flags 0x%02X p->flowflags 0x%02X",
169 char *args[3] = {NULL,NULL,NULL};
172 char str1[16] =
"", str2[16] =
"", str3[16] =
"";
173 pcre2_match_data *match = NULL;
176 if (ret < 1 || ret > 4) {
177 SCLogError(
"parse error, ret %" PRId32
", string %s", ret, flowstr);
182 pcre2len =
sizeof(str1);
185 SCLogError(
"pcre2_substring_copy_bynumber failed");
188 args[0] = (
char *)str1;
191 pcre2len =
sizeof(str2);
192 res = pcre2_substring_copy_bynumber(match, 2, (PCRE2_UCHAR8 *)str2, &pcre2len);
194 SCLogError(
"pcre2_substring_copy_bynumber failed");
197 args[1] = (
char *)str2;
200 pcre2len =
sizeof(str3);
201 res = pcre2_substring_copy_bynumber(match, 3, (PCRE2_UCHAR8 *)str3, &pcre2len);
203 SCLogError(
"pcre2_substring_copy_bynumber failed");
206 args[2] = (
char *)str3;
216 for (
int i = 0; i < (ret - 1); i++) {
219 if (strcasecmp(args[i],
"established") == 0) {
221 SCLogError(
"DETECT_FLOW_FLAG_ESTABLISHED flag is already set");
224 SCLogError(
"cannot set DETECT_FLOW_FLAG_ESTABLISHED, "
225 "DETECT_FLOW_FLAG_NOT_ESTABLISHED already set");
228 SCLogError(
"DETECT_FLOW_FLAG_STATELESS already set");
233 }
else if (strcasecmp(args[i],
"not_established") == 0) {
235 SCLogError(
"DETECT_FLOW_FLAG_NOT_ESTABLISHED flag is already set");
238 SCLogError(
"cannot set DETECT_FLOW_FLAG_NOT_ESTABLISHED, "
239 "DETECT_FLOW_FLAG_ESTABLISHED already set");
244 }
else if (strcasecmp(args[i],
"stateless") == 0) {
246 SCLogError(
"DETECT_FLOW_FLAG_STATELESS flag is already set");
249 SCLogError(
"cannot set DETECT_FLOW_FLAG_STATELESS, "
250 "DETECT_FLOW_FLAG_ESTABLISHED already set");
255 }
else if (strcasecmp(args[i],
"to_client") == 0 || strcasecmp(args[i],
"from_server") == 0) {
257 SCLogError(
"cannot set DETECT_FLOW_FLAG_TOCLIENT flag is already set");
260 SCLogError(
"cannot set to_client, DETECT_FLOW_FLAG_TOSERVER already set");
265 }
else if (strcasecmp(args[i],
"to_server") == 0 || strcasecmp(args[i],
"from_client") == 0){
267 SCLogError(
"cannot set DETECT_FLOW_FLAG_TOSERVER flag is already set");
270 SCLogError(
"cannot set to_server, DETECT_FLOW_FLAG_TO_CLIENT flag already set");
275 }
else if (strcasecmp(args[i],
"no_frag") == 0) {
277 SCLogError(
"cannot set no_frag flag is already set");
280 SCLogError(
"cannot set no_frag flag, only_frag already set");
285 }
else if (strcasecmp(args[i],
"only_frag") == 0) {
287 SCLogError(
"cannot set only_frag flag is already set");
290 SCLogError(
"cannot set only_frag flag, no_frag already set");
298 }
else if (strcasecmp(args[i],
"only_stream") == 0) {
300 SCLogError(
"cannot set only_stream flag is already set");
304 "cannot set only_stream flag, DETECT_FLOW_FLAG_NOSTREAM already set");
308 }
else if (strcasecmp(args[i],
"no_stream") == 0) {
310 SCLogError(
"cannot set no_stream flag is already set");
314 "cannot set no_stream flag, DETECT_FLOW_FLAG_ONLYSTREAM already set");
319 SCLogError(
"invalid flow option \"%s\"", args[i]);
324 pcre2_match_data_free(match);
329 pcre2_match_data_free(match);
339 #define SIG_FLAG_BOTH (SIG_FLAG_TOSERVER|SIG_FLAG_TOCLIENT)
380 uint16_t parse_flags = 0;
384 SCLogError(
"A signature may have only one flow option.");
392 bool appendsm =
true;
397 "rule %u means to use both directions, cannot specify a flow direction", s->
id);
401 SCLogError(
"rule %u has flow to_server but a hook to_client", s->
id);
408 "rule %u means to use both directions, cannot specify a flow direction", s->
id);
412 SCLogError(
"rule %u has flow to_client but a hook to_server", s->
id);
474 if (!PrefilterPacketHeaderExtraMatch(
ctx, p))
479 PrefilterAddSids(&det_ctx->
pmq,
ctx->sigs_array,
ctx->sigs_cnt);
505 PrefilterPacketFlowCompare, PrefilterPacketFlowMatch);
508 static bool PrefilterFlowIsPrefilterable(
const Signature *s)
527 static int DetectFlowTestParse01 (
void)
529 uint16_t parsed_flags = 0;
530 DetectFlowData *fd = DetectFlowParse(NULL,
"established", &parsed_flags);
540 static int DetectFlowTestParse02 (
void)
542 uint16_t parsed_flags = 0;
543 DetectFlowData *fd = DetectFlowParse(NULL,
"established", &parsed_flags);
553 static int DetectFlowTestParse03 (
void)
555 uint16_t parsed_flags = 0;
556 DetectFlowData *fd = DetectFlowParse(NULL,
"stateless", &parsed_flags);
566 static int DetectFlowTestParse04 (
void)
568 uint16_t parsed_flags = 0;
569 DetectFlowData *fd = DetectFlowParse(NULL,
"to_client", &parsed_flags);
579 static int DetectFlowTestParse05 (
void)
581 uint16_t parsed_flags = 0;
582 DetectFlowData *fd = DetectFlowParse(NULL,
"to_server", &parsed_flags);
592 static int DetectFlowTestParse06 (
void)
594 uint16_t parsed_flags = 0;
595 DetectFlowData *fd = DetectFlowParse(NULL,
"from_server", &parsed_flags);
605 static int DetectFlowTestParse07 (
void)
607 uint16_t parsed_flags = 0;
608 DetectFlowData *fd = DetectFlowParse(NULL,
"from_client", &parsed_flags);
618 static int DetectFlowTestParse08 (
void)
620 uint16_t parsed_flags = 0;
621 DetectFlowData *fd = DetectFlowParse(NULL,
"established,to_client", &parsed_flags);
631 static int DetectFlowTestParse09 (
void)
633 uint16_t parsed_flags = 0;
634 DetectFlowData *fd = DetectFlowParse(NULL,
"to_client,stateless", &parsed_flags);
646 static int DetectFlowTestParse10 (
void)
648 uint16_t parsed_flags = 0;
649 DetectFlowData *fd = DetectFlowParse(NULL,
"from_server,stateless", &parsed_flags);
661 static int DetectFlowTestParse11 (
void)
663 uint16_t parsed_flags = 0;
664 DetectFlowData *fd = DetectFlowParse(NULL,
" from_server , stateless ", &parsed_flags);
677 static int DetectFlowTestParseNocase01 (
void)
679 uint16_t parsed_flags = 0;
680 DetectFlowData *fd = DetectFlowParse(NULL,
"ESTABLISHED", &parsed_flags);
689 static int DetectFlowTestParseNocase02 (
void)
691 uint16_t parsed_flags = 0;
692 DetectFlowData *fd = DetectFlowParse(NULL,
"ESTABLISHED", &parsed_flags);
703 static int DetectFlowTestParseNocase03 (
void)
705 uint16_t parsed_flags = 0;
706 DetectFlowData *fd = DetectFlowParse(NULL,
"STATELESS", &parsed_flags);
716 static int DetectFlowTestParseNocase04 (
void)
718 uint16_t parsed_flags = 0;
719 DetectFlowData *fd = DetectFlowParse(NULL,
"TO_CLIENT", &parsed_flags);
729 static int DetectFlowTestParseNocase05 (
void)
731 uint16_t parsed_flags = 0;
732 DetectFlowData *fd = DetectFlowParse(NULL,
"TO_SERVER", &parsed_flags);
742 static int DetectFlowTestParseNocase06 (
void)
744 uint16_t parsed_flags = 0;
745 DetectFlowData *fd = DetectFlowParse(NULL,
"FROM_SERVER", &parsed_flags);
755 static int DetectFlowTestParseNocase07 (
void)
757 uint16_t parsed_flags = 0;
758 DetectFlowData *fd = DetectFlowParse(NULL,
"FROM_CLIENT", &parsed_flags);
768 static int DetectFlowTestParseNocase08 (
void)
770 uint16_t parsed_flags = 0;
771 DetectFlowData *fd = DetectFlowParse(NULL,
"ESTABLISHED,TO_CLIENT", &parsed_flags);
783 static int DetectFlowTestParseNocase09 (
void)
785 uint16_t parsed_flags = 0;
786 DetectFlowData *fd = DetectFlowParse(NULL,
"TO_CLIENT,STATELESS", &parsed_flags);
798 static int DetectFlowTestParseNocase10 (
void)
800 uint16_t parsed_flags = 0;
801 DetectFlowData *fd = DetectFlowParse(NULL,
"FROM_SERVER,STATELESS", &parsed_flags);
813 static int DetectFlowTestParseNocase11 (
void)
815 uint16_t parsed_flags = 0;
816 DetectFlowData *fd = DetectFlowParse(NULL,
" FROM_SERVER , STATELESS ", &parsed_flags);
828 static int DetectFlowTestParse12 (
void)
830 uint16_t parsed_flags = 0;
831 DetectFlowData *fd = DetectFlowParse(NULL,
"from_server:stateless", &parsed_flags);
839 static int DetectFlowTestParse13 (
void)
841 uint16_t parsed_flags = 0;
842 DetectFlowData *fd = DetectFlowParse(NULL,
"invalidoptiontest", &parsed_flags);
850 static int DetectFlowTestParse14 (
void)
852 uint16_t parsed_flags = 0;
861 static int DetectFlowTestParse15 (
void)
863 uint16_t parsed_flags = 0;
864 DetectFlowData *fd = DetectFlowParse(NULL,
"established,stateless", &parsed_flags);
872 static int DetectFlowTestParse16 (
void)
874 uint16_t parsed_flags = 0;
875 DetectFlowData *fd = DetectFlowParse(NULL,
"to_client,to_server", &parsed_flags);
884 static int DetectFlowTestParse17 (
void)
886 uint16_t parsed_flags = 0;
887 DetectFlowData *fd = DetectFlowParse(NULL,
"to_client,from_server", &parsed_flags);
895 static int DetectFlowTestParse18 (
void)
897 uint16_t parsed_flags = 0;
899 DetectFlowParse(NULL,
"from_server,established,only_stream", &parsed_flags);
911 static int DetectFlowTestParseNocase18 (
void)
913 uint16_t parsed_flags = 0;
915 DetectFlowParse(NULL,
"FROM_SERVER,ESTABLISHED,ONLY_STREAM", &parsed_flags);
928 static int DetectFlowTestParse19 (
void)
930 uint16_t parsed_flags = 0;
932 DetectFlowParse(NULL,
"from_server,established,only_stream,a", &parsed_flags);
940 static int DetectFlowTestParse20 (
void)
942 uint16_t parsed_flags = 0;
943 DetectFlowData *fd = DetectFlowParse(NULL,
"from_server,established,no_stream", &parsed_flags);
955 static int DetectFlowTestParseNocase20 (
void)
957 uint16_t parsed_flags = 0;
958 DetectFlowData *fd = DetectFlowParse(NULL,
"FROM_SERVER,ESTABLISHED,NO_STREAM", &parsed_flags);
970 static int DetectFlowTestParse21 (
void)
972 uint16_t parsed_flags = 0;
973 DetectFlowData *fd = DetectFlowParse(NULL,
"from_server,a,no_stream", &parsed_flags);
981 static int DetectFlowTestParse22(
void)
983 uint16_t parsed_flags = 0;
984 DetectFlowData *fd = DetectFlowParse(NULL,
"established,not_established", &parsed_flags);
986 fd = DetectFlowParse(NULL,
"not_established,established", &parsed_flags);
991 static int DetectFlowSigTest01(
void)
993 uint8_t *buf = (uint8_t *)
"supernovaduper";
994 uint16_t buflen = strlen((
char *)buf);
998 memset(&th_v, 0,
sizeof(th_v));
1003 const char *sig1 =
"alert tcp any any -> any any (msg:\"dummy\"; "
1004 "content:\"nova\"; flow:no_stream; sid:1;)";
1031 static int DetectFlowTestParseNotEstablished(
void)
1033 uint16_t parsed_flags = 0;
1034 DetectFlowData *fd = DetectFlowParse(NULL,
"not_established", &parsed_flags);
1044 static int DetectFlowTestParseNoFrag(
void)
1046 uint16_t parsed_flags = 0;
1047 DetectFlowData *fd = DetectFlowParse(NULL,
"no_frag", &parsed_flags);
1057 static int DetectFlowTestParseOnlyFrag(
void)
1059 uint16_t parsed_flags = 0;
1060 DetectFlowData *fd = DetectFlowParse(NULL,
"only_frag", &parsed_flags);
1070 static int DetectFlowTestParseNoFragOnlyFrag(
void)
1072 uint16_t parsed_flags = 0;
1073 DetectFlowData *fd = DetectFlowParse(NULL,
"no_frag,only_frag", &parsed_flags);
1081 static int DetectFlowTestNoFragMatch(
void)
1083 uint16_t parsed_flags = 0;
1084 uint32_t pflags = 0;
1085 DetectFlowData *fd = DetectFlowParse(NULL,
"no_frag", &parsed_flags);
1098 static int DetectFlowTestOnlyFragMatch(
void)
1100 uint16_t parsed_flags = 0;
1101 uint32_t pflags = 0;
1102 DetectFlowData *fd = DetectFlowParse(NULL,
"only_frag", &parsed_flags);
1115 static void DetectFlowRegisterTests(
void)
1128 UtRegisterTest(
"DetectFlowTestParseNocase01", DetectFlowTestParseNocase01);
1129 UtRegisterTest(
"DetectFlowTestParseNocase02", DetectFlowTestParseNocase02);
1130 UtRegisterTest(
"DetectFlowTestParseNocase03", DetectFlowTestParseNocase03);
1131 UtRegisterTest(
"DetectFlowTestParseNocase04", DetectFlowTestParseNocase04);
1132 UtRegisterTest(
"DetectFlowTestParseNocase05", DetectFlowTestParseNocase05);
1133 UtRegisterTest(
"DetectFlowTestParseNocase06", DetectFlowTestParseNocase06);
1134 UtRegisterTest(
"DetectFlowTestParseNocase07", DetectFlowTestParseNocase07);
1135 UtRegisterTest(
"DetectFlowTestParseNocase08", DetectFlowTestParseNocase08);
1136 UtRegisterTest(
"DetectFlowTestParseNocase09", DetectFlowTestParseNocase09);
1137 UtRegisterTest(
"DetectFlowTestParseNocase10", DetectFlowTestParseNocase10);
1138 UtRegisterTest(
"DetectFlowTestParseNocase11", DetectFlowTestParseNocase11);
1146 UtRegisterTest(
"DetectFlowTestParseNocase18", DetectFlowTestParseNocase18);
1149 UtRegisterTest(
"DetectFlowTestParseNocase20", DetectFlowTestParseNocase20);
1153 DetectFlowTestParseNotEstablished);
1154 UtRegisterTest(
"DetectFlowTestParseNoFrag", DetectFlowTestParseNoFrag);
1156 DetectFlowTestParseOnlyFrag);
1158 DetectFlowTestParseNoFragOnlyFrag);
1159 UtRegisterTest(
"DetectFlowTestNoFragMatch", DetectFlowTestNoFragMatch);
1160 UtRegisterTest(
"DetectFlowTestOnlyFragMatch", DetectFlowTestOnlyFragMatch);