suricata
detect-fragbits.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2020 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Breno Silva <breno.silva@gmail.com>
22  * \author Victor Julien <victor@inliniac.net>
23  *
24  * Implements fragbits keyword
25  */
26 
27 #include "suricata-common.h"
28 #include "suricata.h"
29 #include "decode.h"
30 #include "rust.h"
31 
32 #include "detect.h"
33 #include "detect-parse.h"
36 #include "detect-engine-uint.h"
37 
38 #include "flow-var.h"
39 #include "decode-events.h"
40 #include "app-layer.h"
41 #include "app-layer-detect-proto.h"
42 
43 #include "detect-fragbits.h"
44 #include "util-debug.h"
45 
46 #include "pkt-var.h"
47 #include "host.h"
48 #include "util-profiling.h"
49 
50 static int DetectFragBitsMatch (DetectEngineThreadCtx *, Packet *,
51  const Signature *, const SigMatchCtx *);
52 static int DetectFragBitsSetup (DetectEngineCtx *, Signature *, const char *);
53 static void DetectFragBitsFree(DetectEngineCtx *, void *);
54 
55 static int PrefilterSetupFragBits(DetectEngineCtx *de_ctx, SigGroupHead *sgh);
56 static bool PrefilterFragBitsIsPrefilterable(const Signature *s);
57 #ifdef UNITTESTS
58 static void FragBitsRegisterTests(void);
59 #endif
60 
61 /**
62  * \brief Registration function for fragbits: keyword
63  */
64 
66 {
67  sigmatch_table[DETECT_FRAGBITS].name = "fragbits";
68  sigmatch_table[DETECT_FRAGBITS].desc = "check if the fragmentation and reserved bits are set in the IP header";
69  sigmatch_table[DETECT_FRAGBITS].url = "/rules/header-keywords.html#fragbits-ip-fragmentation";
70  sigmatch_table[DETECT_FRAGBITS].Match = DetectFragBitsMatch;
71  sigmatch_table[DETECT_FRAGBITS].Setup = DetectFragBitsSetup;
72  sigmatch_table[DETECT_FRAGBITS].Free = DetectFragBitsFree;
73 #ifdef UNITTESTS
74  sigmatch_table[DETECT_FRAGBITS].RegisterTests = FragBitsRegisterTests;
75 #endif
76  sigmatch_table[DETECT_FRAGBITS].SetupPrefilter = PrefilterSetupFragBits;
77  sigmatch_table[DETECT_FRAGBITS].SupportsPrefilter = PrefilterFragBitsIsPrefilterable;
79 }
80 
81 /**
82  * \internal
83  * \brief This function is used to match fragbits on a packet with those passed via fragbits:
84  *
85  * \param t pointer to thread vars
86  * \param det_ctx pointer to the pattern matcher thread
87  * \param p pointer to the current packet
88  * \param s pointer to the Signature
89  * \param m pointer to the sigmatch
90  *
91  * \retval 0 no match
92  * \retval 1 match
93  */
94 static int DetectFragBitsMatch (DetectEngineThreadCtx *det_ctx,
95  Packet *p, const Signature *s, const SigMatchCtx *ctx)
96 {
98  if (!ctx || !PacketIsIPv4(p))
99  return 0;
100 
101  const IPV4Hdr *ip4h = PacketGetIPv4(p);
102  DetectU16Data *du16 = (DetectU16Data *)ctx;
103  return DetectU16Match(IPV4_GET_RAW_IPOFFSET(ip4h), du16);
104 }
105 
106 /**
107  * \internal
108  * \brief this function is used to add the parsed fragbits into the current signature
109  *
110  * \param de_ctx pointer to the Detection Engine Context
111  * \param s pointer to the Current Signature
112  * \param m pointer to the Current SigMatch
113  * \param rawstr pointer to the user provided fragbits options
114  *
115  * \retval 0 on Success
116  * \retval -1 on Failure
117  */
118 static int DetectFragBitsSetup (DetectEngineCtx *de_ctx, Signature *s, const char *rawstr)
119 {
120  DetectU16Data *du16 = SCDetectIpv4FragbitsParse(rawstr);
121  if (du16 == NULL)
122  return -1;
123 
125  de_ctx, s, DETECT_FRAGBITS, (SigMatchCtx *)du16, DETECT_SM_LIST_MATCH) == NULL) {
126  goto error;
127  }
129 
130  return 0;
131 
132 error:
133  if (du16)
134  DetectFragBitsFree(NULL, du16);
135  return -1;
136 }
137 
138 /**
139  * \internal
140  * \brief this function will free memory associated with DetectU16Data
141  *
142  * \param de pointer to DetectU16Data
143  */
144 static void DetectFragBitsFree(DetectEngineCtx *de_ctx, void *de_ptr)
145 {
146  SCDetectU16Free(de_ptr);
147 }
148 
149 static void
150 PrefilterPacketFragBitsMatch(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx)
151 {
153  const PrefilterPacketHeaderCtx *ctx = pectx;
154 
155  if (!PacketIsIPv4(p))
156  return;
157 
158  const IPV4Hdr *ip4h = PacketGetIPv4(p);
159  DetectU16Data du16;
160  du16.mode = ctx->v1.u8[0];
161  du16.arg1 = ctx->v1.u16[1];
162  du16.arg2 = ctx->v1.u16[2];
163 
164  if (DetectU16Match(IPV4_GET_RAW_IPOFFSET(ip4h), &du16)) {
165  PrefilterAddSids(&det_ctx->pmq, ctx->sigs_array, ctx->sigs_cnt);
166  }
167 }
168 
169 static int PrefilterSetupFragBits(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
170 {
172  PrefilterPacketU16Set, PrefilterPacketU16Compare, PrefilterPacketFragBitsMatch);
173 }
174 
175 static bool PrefilterFragBitsIsPrefilterable(const Signature *s)
176 {
177  return PrefilterIsPrefilterableById(s, DETECT_FRAGBITS);
178 }
179 
180 /*
181  * ONLY TESTS BELOW THIS COMMENT
182  */
183 
184 #ifdef UNITTESTS
185 #include "util-unittest-helper.h"
186 #include "packet.h"
187 
188 /**
189  * \test FragBitsTestParse03 test if DONT FRAG is set. Must return success
190  *
191  * \retval 1 on success
192  * \retval 0 on failure
193  */
194 static int FragBitsTestParse03 (void)
195 {
196  uint8_t raw_eth[] = {
197  0x00 ,0x40 ,0x33 ,0xd9 ,0x7c ,0xfd ,0x00 ,0x00,
198  0x39 ,0xcf ,0xd9 ,0xcd ,0x08 ,0x00 ,0x45 ,0x00,
199  0x01 ,0x13 ,0x9c ,0x5d ,0x40 ,0x00 ,0xf6 ,0x11,
200  0x44 ,0xca ,0x97 ,0xa4 ,0x01 ,0x08 ,0x0a ,0x00,
201  0x00 ,0x06 ,0x00 ,0x35 ,0x04 ,0x0b ,0x00 ,0xff,
202  0x3c ,0x87 ,0x7d ,0x9e ,0x85 ,0x80 ,0x00 ,0x01,
203  0x00 ,0x01 ,0x00 ,0x05 ,0x00 ,0x05 ,0x06 ,0x70,
204  0x69 ,0x63 ,0x61 ,0x72 ,0x64 ,0x07 ,0x75 ,0x74,
205  0x68 ,0x73 ,0x63 ,0x73 ,0x61 ,0x03 ,0x65 ,0x64,
206  0x75 ,0x00 ,0x00 ,0x01 ,0x00 ,0x01 ,0xc0 ,0x0c,
207  0x00 ,0x01 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10,
208  0x00 ,0x04 ,0x81 ,0x6f ,0x1e ,0x1b ,0x07 ,0x75,
209  0x74 ,0x68 ,0x73 ,0x63 ,0x73 ,0x61 ,0x03 ,0x65,
210  0x64 ,0x75 ,0x00 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
211  0x00 ,0x0e ,0x10 ,0x00 ,0x09 ,0x06 ,0x6b ,0x65,
212  0x6e ,0x6f ,0x62 ,0x69 ,0xc0 ,0x34 ,0xc0 ,0x34,
213  0x00 ,0x02 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10,
214  0x00 ,0x07 ,0x04 ,0x6a ,0x69 ,0x6e ,0x6e ,0xc0,
215  0x34 ,0xc0 ,0x34 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
216  0x00 ,0x0e ,0x10 ,0x00 ,0x0c ,0x04 ,0x64 ,0x6e,
217  0x73 ,0x31 ,0x04 ,0x6e ,0x6a ,0x69 ,0x74 ,0xc0,
218  0x3c ,0xc0 ,0x34 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
219  0x00 ,0x0e ,0x10 ,0x00 ,0x08 ,0x05 ,0x65 ,0x6c,
220  0x7a ,0x69 ,0x70 ,0xc0 ,0x34 ,0xc0 ,0x34 ,0x00,
221  0x02 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10 ,0x00,
222  0x08 ,0x05 ,0x61 ,0x72 ,0x77 ,0x65 ,0x6e ,0xc0,
223  0x34 ,0xc0 ,0x4b ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
224  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x1a,
225  0x06 ,0xc0 ,0x60 ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
226  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x1a,
227  0x07 ,0xc0 ,0x73 ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
228  0x01 ,0x03 ,0x82 ,0x00 ,0x04 ,0x80 ,0xeb ,0xfb,
229  0x0a ,0xc0 ,0x8b ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
230  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x01,
231  0x0b ,0xc0 ,0x9f ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
232  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x0b,
233  0x51};
235  FAIL_IF(unlikely(p == NULL));
236  ThreadVars tv;
238 
239  memset(&tv, 0, sizeof(ThreadVars));
240  memset(&dtv, 0, sizeof(DecodeThreadVars));
242 
244 
245  DecodeEthernet(&tv, &dtv, p, raw_eth, sizeof(raw_eth));
246 
247  DetectU16Data *de = SCDetectIpv4FragbitsParse("D");
248  FAIL_IF(de == NULL);
249  FAIL_IF(de->arg1 != 0x4000);
250  FAIL_IF(de->mode != DetectUintModeEqual);
251 
252  SigMatch *sm = SigMatchAlloc();
253  FAIL_IF(sm == NULL);
254  sm->type = DETECT_FRAGBITS;
255  sm->ctx = (SigMatchCtx *)de;
256 
257  int ret = DetectFragBitsMatch(NULL, p, NULL, sm->ctx);
258  FAIL_IF(ret == 0);
259 
260  DetectFragBitsFree(NULL, de);
261  SCFree(sm);
262  PacketFree(p);
263 
265  FlowShutdown();
266  PASS;
267 }
268 
269 /**
270  * \test FragBitsTestParse04 test if DONT FRAG is not set. Must fails.
271  *
272  * \retval 1 on success
273  * \retval 0 on failure
274  */
275 static int FragBitsTestParse04 (void)
276 {
277  uint8_t raw_eth[] = {
278  0x00 ,0x40 ,0x33 ,0xd9 ,0x7c ,0xfd ,0x00 ,0x00,
279  0x39 ,0xcf ,0xd9 ,0xcd ,0x08 ,0x00 ,0x45 ,0x00,
280  0x01 ,0x13 ,0x9c ,0x5d ,0x40 ,0x00 ,0xf6 ,0x11,
281  0x44 ,0xca ,0x97 ,0xa4 ,0x01 ,0x08 ,0x0a ,0x00,
282  0x00 ,0x06 ,0x00 ,0x35 ,0x04 ,0x0b ,0x00 ,0xff,
283  0x3c ,0x87 ,0x7d ,0x9e ,0x85 ,0x80 ,0x00 ,0x01,
284  0x00 ,0x01 ,0x00 ,0x05 ,0x00 ,0x05 ,0x06 ,0x70,
285  0x69 ,0x63 ,0x61 ,0x72 ,0x64 ,0x07 ,0x75 ,0x74,
286  0x68 ,0x73 ,0x63 ,0x73 ,0x61 ,0x03 ,0x65 ,0x64,
287  0x75 ,0x00 ,0x00 ,0x01 ,0x00 ,0x01 ,0xc0 ,0x0c,
288  0x00 ,0x01 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10,
289  0x00 ,0x04 ,0x81 ,0x6f ,0x1e ,0x1b ,0x07 ,0x75,
290  0x74 ,0x68 ,0x73 ,0x63 ,0x73 ,0x61 ,0x03 ,0x65,
291  0x64 ,0x75 ,0x00 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
292  0x00 ,0x0e ,0x10 ,0x00 ,0x09 ,0x06 ,0x6b ,0x65,
293  0x6e ,0x6f ,0x62 ,0x69 ,0xc0 ,0x34 ,0xc0 ,0x34,
294  0x00 ,0x02 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10,
295  0x00 ,0x07 ,0x04 ,0x6a ,0x69 ,0x6e ,0x6e ,0xc0,
296  0x34 ,0xc0 ,0x34 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
297  0x00 ,0x0e ,0x10 ,0x00 ,0x0c ,0x04 ,0x64 ,0x6e,
298  0x73 ,0x31 ,0x04 ,0x6e ,0x6a ,0x69 ,0x74 ,0xc0,
299  0x3c ,0xc0 ,0x34 ,0x00 ,0x02 ,0x00 ,0x01 ,0x00,
300  0x00 ,0x0e ,0x10 ,0x00 ,0x08 ,0x05 ,0x65 ,0x6c,
301  0x7a ,0x69 ,0x70 ,0xc0 ,0x34 ,0xc0 ,0x34 ,0x00,
302  0x02 ,0x00 ,0x01 ,0x00 ,0x00 ,0x0e ,0x10 ,0x00,
303  0x08 ,0x05 ,0x61 ,0x72 ,0x77 ,0x65 ,0x6e ,0xc0,
304  0x34 ,0xc0 ,0x4b ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
305  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x1a,
306  0x06 ,0xc0 ,0x60 ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
307  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x1a,
308  0x07 ,0xc0 ,0x73 ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
309  0x01 ,0x03 ,0x82 ,0x00 ,0x04 ,0x80 ,0xeb ,0xfb,
310  0x0a ,0xc0 ,0x8b ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
311  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x01,
312  0x0b ,0xc0 ,0x9f ,0x00 ,0x01 ,0x00 ,0x01 ,0x00,
313  0x00 ,0x0e ,0x10 ,0x00 ,0x04 ,0x81 ,0x6f ,0x0b,
314  0x51};
316  FAIL_IF(unlikely(p == NULL));
317  ThreadVars tv;
319 
320  memset(&tv, 0, sizeof(ThreadVars));
321  memset(&dtv, 0, sizeof(DecodeThreadVars));
323 
325 
326  DecodeEthernet(&tv, &dtv, p, raw_eth, sizeof(raw_eth));
327 
328  DetectU16Data *de = SCDetectIpv4FragbitsParse("!D");
329  FAIL_IF(de == NULL);
330  FAIL_IF(de->arg1 != 0x4000);
331  FAIL_IF(de->arg2 != 0x4000);
332  FAIL_IF(de->mode != DetectUintModeNegBitmask);
333 
334  SigMatch *sm = SigMatchAlloc();
335  FAIL_IF(sm == NULL);
336  sm->type = DETECT_FRAGBITS;
337  sm->ctx = (SigMatchCtx *)de;
338 
339  int ret = DetectFragBitsMatch(NULL, p, NULL, sm->ctx);
340  FAIL_IF(ret);
341  DetectFragBitsFree(NULL, de);
342  SCFree(sm);
343  PacketFree(p);
344 
346  FlowShutdown();
347  PASS;
348 }
349 
350 /**
351  * \brief this function registers unit tests for FragBits
352  */
353 static void FragBitsRegisterTests(void)
354 {
355  UtRegisterTest("FragBitsTestParse03", FragBitsTestParse03);
356  UtRegisterTest("FragBitsTestParse04", FragBitsTestParse04);
357 }
358 #endif /* UNITTESTS */
DetectFragBitsRegister
void DetectFragBitsRegister(void)
Registration function for fragbits: keyword.
Definition: detect-fragbits.c:65
detect-engine-uint.h
host.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
SIG_MASK_REQUIRE_REAL_PKT
#define SIG_MASK_REQUIRE_REAL_PKT
Definition: detect.h:320
PrefilterPacketU16Set
void PrefilterPacketU16Set(PrefilterPacketHeaderValue *v, void *smctx)
Definition: detect-engine-uint.c:124
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
PKT_IS_PSEUDOPKT
#define PKT_IS_PSEUDOPKT(p)
return 1 if the packet is a pseudo packet
Definition: decode.h:1364
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
IPV4_GET_RAW_IPOFFSET
#define IPV4_GET_RAW_IPOFFSET(ip4h)
Definition: decode-ipv4.h:100
rust.h
p
Packet * p
Definition: fuzz_dataset.c:30
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
detect-engine-prefilter.h
util-unittest-helper.h
SigTableElmt_::SetupPrefilter
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
Definition: detect.h:1527
DETECT_FRAGBITS
@ DETECT_FRAGBITS
Definition: detect-engine-register.h:43
FlowInitConfig
void FlowInitConfig(bool quiet)
initialize the configuration
Definition: flow.c:574
app-layer-detect-proto.h
PrefilterPacketHeaderCtx_
Definition: detect-engine-prefilter-common.h:35
decode.h
util-debug.h
SIGMATCH_INFO_UINT16
#define SIGMATCH_INFO_UINT16
Definition: detect-engine-register.h:344
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
detect-fragbits.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
pkt-var.h
PacketFree
void PacketFree(Packet *p)
Return a malloced packet.
Definition: decode.c:221
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
SigMatch_::ctx
SigMatchCtx * ctx
Definition: detect.h:363
util-profiling.h
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
DecodeThreadVars_::app_tctx
AppLayerThreadCtx * app_tctx
Definition: decode.h:997
PrefilterSetupPacketHeader
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
Definition: detect-engine-prefilter-common.c:470
AppLayerGetCtxThread
AppLayerThreadCtx * AppLayerGetCtxThread(void)
Creates a new app layer thread context.
Definition: app-layer.c:1117
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
SigMatchAlloc
SigMatch * SigMatchAlloc(void)
Definition: detect-parse.c:311
decode-events.h
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
IPV4Hdr_
Definition: decode-ipv4.h:72
FAIL_IF
#define FAIL_IF(expr)
Fail a test if expression evaluates to true.
Definition: util-unittest.h:71
DetectU16Match
int DetectU16Match(const uint16_t parg, const DetectUintData_u16 *du16)
Definition: detect-engine-uint.c:105
PrefilterPacketU16Compare
bool PrefilterPacketU16Compare(PrefilterPacketHeaderValue v, void *smctx)
Definition: detect-engine-uint.c:132
suricata-common.h
SigMatch_::type
uint16_t type
Definition: detect.h:361
FlowShutdown
void FlowShutdown(void)
shutdown the flow engine
Definition: flow.c:718
packet.h
tv
ThreadVars * tv
Definition: fuzz_decodepcapfile.c:34
PacketGetFromAlloc
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
Definition: decode.c:260
SIGMATCH_INFO_BITFLAGS_UINT
#define SIGMATCH_INFO_BITFLAGS_UINT
Definition: detect-engine-register.h:358
SCFree
#define SCFree(p)
Definition: util-mem.h:61
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
SigTableElmt_::SupportsPrefilter
bool(* SupportsPrefilter)(const Signature *s)
Definition: detect.h:1526
AppLayerDestroyCtxThread
void AppLayerDestroyCtxThread(AppLayerThreadCtx *app_tctx)
Destroys the context created by AppLayerGetCtxThread().
Definition: app-layer.c:1138
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
SigMatch_
a single match condition for a signature
Definition: detect.h:360
suricata.h
FLOW_QUIET
#define FLOW_QUIET
Definition: flow.h:43
detect-engine-prefilter-common.h
DetectU16Data
DetectUintData_u16 DetectU16Data
Definition: detect-engine-uint.h:42
flow-var.h
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
DecodeEthernet
int DecodeEthernet(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Definition: decode-ethernet.c:41
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
app-layer.h
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257