suricata
detect-gid.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2010 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Breno Silva <breno.silva@gmail.com>
22  *
23  * Implements the gid keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "suricata.h"
28 #include "decode.h"
29 #include "detect.h"
30 #include "detect-engine.h"
31 #include "detect-parse.h"
32 #include "flow-var.h"
33 #include "decode-events.h"
34 
35 #include "detect-gid.h"
36 #include "util-unittest.h"
37 #include "util-debug.h"
38 
39 static int DetectGidSetup (DetectEngineCtx *, Signature *, const char *);
40 
41 /**
42  * \brief Registration function for gid: keyword
43  */
44 
45 void DetectGidRegister (void)
46 {
48  sigmatch_table[DETECT_GID].desc = "give different groups of signatures another id value";
49  sigmatch_table[DETECT_GID].url = DOC_URL DOC_VERSION "/rules/meta.html#gid-group-id";
51  sigmatch_table[DETECT_GID].Setup = DetectGidSetup;
54 }
55 
56 /**
57  * \internal
58  * \brief this function is used to add the parsed gid into the current signature
59  *
60  * \param de_ctx pointer to the Detection Engine Context
61  * \param s pointer to the Current Signature
62  * \param rawstr pointer to the user provided gid options
63  *
64  * \retval 0 on Success
65  * \retval -1 on Failure
66  */
67 static int DetectGidSetup (DetectEngineCtx *de_ctx, Signature *s, const char *rawstr)
68 {
69  unsigned long gid = 0;
70  char *endptr = NULL;
71  gid = strtoul(rawstr, &endptr, 10);
72  if (endptr == NULL || *endptr != '\0') {
73  SCLogError(SC_ERR_INVALID_SIGNATURE, "invalid character as arg "
74  "to gid keyword");
75  goto error;
76  }
77  if (gid >= UINT_MAX) {
78  SCLogError(SC_ERR_INVALID_NUMERIC_VALUE, "gid value to high, max %u", UINT_MAX);
79  goto error;
80  }
81 
82  s->gid = (uint32_t)gid;
83 
84  return 0;
85 
86  error:
87  return -1;
88 }
89 
90 /*
91  * ONLY TESTS BELOW THIS COMMENT
92  */
93 
94 #ifdef UNITTESTS
95 /**
96  * \test GidTestParse01 is a test for a valid gid value
97  *
98  * \retval 1 on succces
99  * \retval 0 on failure
100  */
101 static int GidTestParse01 (void)
102 {
103  int result = 0;
104  Signature *s = NULL;
105 
107  if (de_ctx == NULL)
108  goto end;
109 
110  s = DetectEngineAppendSig(de_ctx, "alert tcp 1.2.3.4 any -> any any (sid:1; gid:1;)");
111  if (s == NULL || s->gid != 1)
112  goto end;
113 
114  result = 1;
115 end:
116  if (de_ctx != NULL)
117  DetectEngineCtxFree(de_ctx);
118  return result;
119 }
120 
121 /**
122  * \test GidTestParse02 is a test for an invalid gid value
123  *
124  * \retval 1 on succces
125  * \retval 0 on failure
126  */
127 static int GidTestParse02 (void)
128 {
129  int result = 0;
130 
132  if (de_ctx == NULL)
133  goto end;
134 
135  if (DetectEngineAppendSig(de_ctx, "alert tcp 1.2.3.4 any -> any any (sid:1; gid:a;)") != NULL)
136  goto end;
137 
138  result = 1;
139 end:
140  if (de_ctx != NULL)
141  DetectEngineCtxFree(de_ctx);
142  return result;
143 }
144 
145 /**
146  * \test Test a gid consisting of a single quote.
147  *
148  * \retval 1 on succces
149  * \retval 0 on failure
150  */
151 static int GidTestParse03 (void)
152 {
153  int result = 0;
154 
156  if (de_ctx == NULL)
157  goto end;
158 
159  if (DetectEngineAppendSig(de_ctx,
160  "alert tcp any any -> any any (content:\"ABC\"; gid:\";)") != NULL)
161  goto end;
162 
163  result = 1;
164 end:
165  if (de_ctx != NULL)
166  DetectEngineCtxFree(de_ctx);
167  return result;
168 }
169 #endif /* UNITTESTS */
170 
171 /**
172  * \brief this function registers unit tests for Gid
173  */
175 {
176 #ifdef UNITTESTS
177  UtRegisterTest("GidTestParse01", GidTestParse01);
178  UtRegisterTest("GidTestParse02", GidTestParse02);
179  UtRegisterTest("GidTestParse03", GidTestParse03);
180 #endif /* UNITTESTS */
181 }
Signature * DetectEngineAppendSig(DetectEngineCtx *de_ctx, const char *sigstr)
Parse and append a Signature into the Detection Engine Context signature list.
void DetectGidRegister(void)
Registration function for gid: keyword.
Definition: detect-gid.c:45
SigTableElmt sigmatch_table[DETECT_TBLSIZE]
Definition: detect.h:1409
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1150
const char * name
Definition: detect.h:1164
Signature container.
Definition: detect.h:496
main detection engine ctx
Definition: detect.h:724
void(* Free)(void *)
Definition: detect.h:1155
#define SCLogError(err_code,...)
Macro used to log ERROR messages.
Definition: util-debug.h:294
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
uint32_t gid
Definition: detect.h:530
const char * desc
Definition: detect.h:1166
int(* Match)(ThreadVars *, DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1133
const char * url
Definition: detect.h:1167
#define DOC_URL
Definition: suricata.h:86
void GidRegisterTests(void)
this function registers unit tests for Gid
Definition: detect-gid.c:174
#define DOC_VERSION
Definition: suricata.h:91
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
void(* RegisterTests)(void)
Definition: detect.h:1156
DetectEngineCtx * DetectEngineCtxInit(void)