Go to the documentation of this file.
65 #define KEYWORD_NAME "http.start"
66 #define KEYWORD_NAME_LEGACY "http_start"
67 #define KEYWORD_DOC "http-keywords.html#http-start"
68 #define BUFFER_NAME "http_start"
69 #define BUFFER_DESC "http start: request/response line + headers"
70 static int g_buffer_id = 0;
71 static int g_keyword_thread_id = 0;
73 #define BUFFER_SIZE_STEP 2048
76 static uint8_t *GetBufferForTX(
87 const bstr *line = NULL;
88 const htp_headers_t *headers;
89 if (
flags & STREAM_TOSERVER) {
91 HTP_REQUEST_PROGRESS_HEADERS)
93 line = htp_tx_request_line(tx);
94 headers = htp_tx_request_headers(tx);
97 HTP_RESPONSE_PROGRESS_HEADERS)
99 headers = htp_tx_response_headers(tx);
100 line = htp_tx_response_line(tx);
102 if (line == NULL || headers == NULL)
105 size_t line_size = bstr_len(line) + 2;
106 if (line_size + buf->
len > buf->
size) {
111 memcpy(buf->
buffer + buf->
len, bstr_ptr(line), bstr_size(line));
112 buf->
len += bstr_size(line);
117 size_t no_of_headers = htp_headers_size(headers);
118 for (; i < no_of_headers; i++) {
119 const htp_header_t *h = htp_headers_get_index(headers, i);
120 size_t size1 = htp_header_name_len(h);
121 size_t size2 = htp_header_value_len(h);
122 size_t size = size1 + size2 + 4;
123 if (i + 1 == no_of_headers)
125 if (size + buf->
len > buf->
size) {
131 memcpy(buf->
buffer + buf->
len, htp_header_name_ptr(h), htp_header_name_len(h));
132 buf->
len += htp_header_name_len(h);
135 memcpy(buf->
buffer + buf->
len, htp_header_value_ptr(h), htp_header_value_len(h));
136 buf->
len += htp_header_value_len(h);
139 if (i + 1 == no_of_headers) {
145 *buffer_len = buf->
len;
155 uint32_t rawdata_len = 0;
156 uint8_t *rawdata = GetBufferForTX(txv, det_ctx, flow_flags, &rawdata_len);
157 if (rawdata_len == 0)
161 det_ctx, list_id, buffer, rawdata, rawdata_len, transforms);
191 GetBuffer1ForTX,
ALPROTO_HTTP1, HTP_REQUEST_PROGRESS_HEADERS);
193 GetBuffer1ForTX,
ALPROTO_HTTP1, HTP_RESPONSE_PROGRESS_HEADERS);
208 SCLogDebug(
"keyword %s registered. Thread id %d. "
209 "Buffer %s registered. Buffer id %d",
SigTableElmt * sigmatch_table
uint8_t DetectEngineInspectBufferGeneric(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const DetectEngineAppInspectionEngine *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Do the content inspection & validation for a signature.
#define KEYWORD_NAME_LEGACY
InspectionBuffer * SCInspectionBufferGet(DetectEngineThreadCtx *det_ctx, const int list_id)
void DetectHttpStartRegister(void)
Registers the keyword handlers for the "http_start" keyword.
main detection engine ctx
void SCInspectionBufferSetupAndApplyTransforms(DetectEngineThreadCtx *det_ctx, const int list_id, InspectionBuffer *buffer, const uint8_t *data, const uint32_t data_len, const DetectEngineTransforms *transforms)
setup the buffer with our initial data
HttpHeaderBuffer * HttpHeaderGetBufferSpace(DetectEngineThreadCtx *det_ctx, uint8_t flags, const int keyword_id, HttpHeaderThreadData **ret_hdr_td)
int SCDetectBufferSetActiveList(DetectEngineCtx *de_ctx, Signature *s, const int list)
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
#define SIG_FLAG_TOCLIENT
int HttpHeaderExpandBuffer(HttpHeaderThreadData *td, HttpHeaderBuffer *buf, size_t size)
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
int DetectBufferTypeGetByName(const char *name)
#define SIG_FLAG_TOSERVER
int PrefilterGenericMpmRegister(DetectEngineCtx *de_ctx, SigGroupHead *sgh, MpmCtx *mpm_ctx, const DetectBufferMpmRegistry *mpm_reg, int list_id)
int AppLayerParserGetStateProgress(uint8_t ipproto, AppProto alproto, void *tx, uint8_t flags)
get the progress value for a tx/protocol
Data structures and function prototypes for keeping state for the detection engine.
void * HttpHeaderThreadDataInit(void *data)
void DetectAppLayerMpmRegister(const char *name, int direction, int priority, PrefilterRegisterFunc PrefilterRegister, InspectionBufferGetDataPtr GetData, AppProto alproto, uint8_t tx_min_progress)
register an app layer keyword for mpm
#define SIGMATCH_INFO_STICKY_BUFFER
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
int SCDetectRegisterThreadCtxGlobalFuncs(const char *name, void *(*InitFunc)(void *), void *data, void(*FreeFunc)(void *))
Register Thread keyword context Funcs (Global)
void HttpHeaderThreadDataFree(void *data)