suricata
detect-http2.c
Go to the documentation of this file.
1 /* Copyright (C) 2020-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Philippe Antoine <p.antoine@catenacyber.fr>
22  *
23  */
24 
25 #include "suricata-common.h"
26 
27 #include "detect.h"
28 #include "detect-parse.h"
29 #include "detect-content.h"
30 
31 #include "detect-engine.h"
32 #include "detect-engine-buffer.h"
33 #include "detect-engine-uint.h"
34 #include "detect-engine-mpm.h"
37 #include "detect-engine-helper.h"
38 
39 #include "detect-http2.h"
40 #include "util-byte.h"
41 #include "rust.h"
42 #include "util-profiling.h"
43 
44 #ifdef UNITTESTS
51 #endif
52 
53 /* prototypes */
54 static int DetectHTTP2frametypeMatch(DetectEngineThreadCtx *det_ctx,
55  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
56  const SigMatchCtx *ctx);
57 static int DetectHTTP2frametypeSetup (DetectEngineCtx *, Signature *, const char *);
59 
60 static int DetectHTTP2errorcodeMatch(DetectEngineThreadCtx *det_ctx,
61  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
62  const SigMatchCtx *ctx);
63 static int DetectHTTP2errorcodeSetup (DetectEngineCtx *, Signature *, const char *);
65 
66 static int DetectHTTP2priorityMatch(DetectEngineThreadCtx *det_ctx,
67  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
68  const SigMatchCtx *ctx);
69 static int DetectHTTP2prioritySetup (DetectEngineCtx *, Signature *, const char *);
71 
72 static int DetectHTTP2windowMatch(DetectEngineThreadCtx *det_ctx,
73  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
74  const SigMatchCtx *ctx);
75 static int DetectHTTP2windowSetup (DetectEngineCtx *, Signature *, const char *);
76 void DetectHTTP2windowFree (DetectEngineCtx *, void *);
77 
78 static int DetectHTTP2sizeUpdateMatch(DetectEngineThreadCtx *det_ctx,
79  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
80  const SigMatchCtx *ctx);
81 static int DetectHTTP2sizeUpdateSetup (DetectEngineCtx *, Signature *, const char *);
83 
84 static int DetectHTTP2settingsMatch(DetectEngineThreadCtx *det_ctx,
85  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
86  const SigMatchCtx *ctx);
87 static int DetectHTTP2settingsSetup (DetectEngineCtx *, Signature *, const char *);
89 
90 static int DetectHTTP2headerNameSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg);
91 
92 #ifdef UNITTESTS
94 #endif
95 
96 static int g_http2_match_buffer_id = 0;
97 static int g_http2_complete_buffer_id = 0;
98 static int g_http2_header_buffer_id = 0;
99 
100 static void DetectHTTP2frameTypeListValues(SCJsonBuilder *jsb)
101 {
102  SCDetectHTTP2frameTypeListValues(jsb);
103 }
104 
105 static void DetectHTTP2errorcodeListValues(SCJsonBuilder *jsb)
106 {
107  SCDetectHTTP2errorcodeListValues(jsb);
108 }
109 
110 /**
111  * \brief Registration function for HTTP2 keywords
112  */
113 
115 {
116  sigmatch_table[DETECT_HTTP2_FRAMETYPE].name = "http2.frametype";
117  sigmatch_table[DETECT_HTTP2_FRAMETYPE].desc = "match on HTTP2 frame type field";
118  sigmatch_table[DETECT_HTTP2_FRAMETYPE].url = "/rules/http2-keywords.html#http2-frametype";
120  sigmatch_table[DETECT_HTTP2_FRAMETYPE].AppLayerTxMatch = DetectHTTP2frametypeMatch;
121  sigmatch_table[DETECT_HTTP2_FRAMETYPE].Setup = DetectHTTP2frametypeSetup;
125  sigmatch_table[DETECT_HTTP2_FRAMETYPE].JsonAdditionalInfo = DetectHTTP2frameTypeListValues;
126 #ifdef UNITTESTS
128 #endif
129 
130  sigmatch_table[DETECT_HTTP2_ERRORCODE].name = "http2.errorcode";
131  sigmatch_table[DETECT_HTTP2_ERRORCODE].desc = "match on HTTP2 error code field";
132  sigmatch_table[DETECT_HTTP2_ERRORCODE].url = "/rules/http2-keywords.html#http2-errorcode";
134  sigmatch_table[DETECT_HTTP2_ERRORCODE].AppLayerTxMatch = DetectHTTP2errorcodeMatch;
135  sigmatch_table[DETECT_HTTP2_ERRORCODE].Setup = DetectHTTP2errorcodeSetup;
139  sigmatch_table[DETECT_HTTP2_ERRORCODE].JsonAdditionalInfo = DetectHTTP2errorcodeListValues;
140 #ifdef UNITTESTS
142 #endif
143 
144  sigmatch_table[DETECT_HTTP2_PRIORITY].name = "http2.priority";
145  sigmatch_table[DETECT_HTTP2_PRIORITY].desc = "match on HTTP2 priority weight field";
146  sigmatch_table[DETECT_HTTP2_PRIORITY].url = "/rules/http2-keywords.html#http2-priority";
148  sigmatch_table[DETECT_HTTP2_PRIORITY].AppLayerTxMatch = DetectHTTP2priorityMatch;
149  sigmatch_table[DETECT_HTTP2_PRIORITY].Setup = DetectHTTP2prioritySetup;
152 #ifdef UNITTESTS
154 #endif
155 
156  sigmatch_table[DETECT_HTTP2_WINDOW].name = "http2.window";
157  sigmatch_table[DETECT_HTTP2_WINDOW].desc = "match on HTTP2 window update size increment field";
158  sigmatch_table[DETECT_HTTP2_WINDOW].url = "/rules/http2-keywords.html#http2-window";
160  sigmatch_table[DETECT_HTTP2_WINDOW].AppLayerTxMatch = DetectHTTP2windowMatch;
161  sigmatch_table[DETECT_HTTP2_WINDOW].Setup = DetectHTTP2windowSetup;
164 #ifdef UNITTESTS
166 #endif
167 
168  sigmatch_table[DETECT_HTTP2_SIZEUPDATE].name = "http2.size_update";
169  sigmatch_table[DETECT_HTTP2_SIZEUPDATE].desc = "match on HTTP2 dynamic headers table size update";
170  sigmatch_table[DETECT_HTTP2_SIZEUPDATE].url = "/rules/http2-keywords.html#http2-size-update";
172  sigmatch_table[DETECT_HTTP2_SIZEUPDATE].AppLayerTxMatch = DetectHTTP2sizeUpdateMatch;
173  sigmatch_table[DETECT_HTTP2_SIZEUPDATE].Setup = DetectHTTP2sizeUpdateSetup;
176 #ifdef UNITTESTS
178 #endif
179 
180  sigmatch_table[DETECT_HTTP2_SETTINGS].name = "http2.settings";
181  sigmatch_table[DETECT_HTTP2_SETTINGS].desc = "match on HTTP2 settings identifier and value fields";
182  sigmatch_table[DETECT_HTTP2_SETTINGS].url = "/rules/http2-keywords.html#http2-settings";
184  sigmatch_table[DETECT_HTTP2_SETTINGS].AppLayerTxMatch = DetectHTTP2settingsMatch;
185  sigmatch_table[DETECT_HTTP2_SETTINGS].Setup = DetectHTTP2settingsSetup;
187 #ifdef UNITTESTS
189 #endif
190 
191  sigmatch_table[DETECT_HTTP2_HEADERNAME].name = "http2.header_name";
192  sigmatch_table[DETECT_HTTP2_HEADERNAME].desc = "sticky buffer to match on one HTTP2 header name";
193  sigmatch_table[DETECT_HTTP2_HEADERNAME].url = "/rules/http2-keywords.html#http2-header-name";
194  sigmatch_table[DETECT_HTTP2_HEADERNAME].Setup = DetectHTTP2headerNameSetup;
197 
198  /* registration for for Stream Tx Sub State */
200  HTTP2TxTypeStream, HTTP2ProgHeaders, SCHttp2TxGetHeaderName, 2);
202  HTTP2TxTypeStream, HTTP2ProgHeaders, SCHttp2TxGetHeaderName, 2);
203 
204  DetectBufferTypeSupportsMultiInstance("http2:header_name");
205  DetectBufferTypeSetDescriptionByName("http2:header_name", "HTTP2 header name");
206  g_http2_header_buffer_id = DetectBufferTypeGetByName("http2:header_name");
207 
208  g_http2_match_buffer_id = DetectBufferTypeRegister("http2:start");
209  /* registration for for Stream Tx Sub State */
211  HTTP2TxTypeStream, 0, DetectEngineInspectGenericList, NULL);
213  HTTP2TxTypeStream, 0, DetectEngineInspectGenericList, NULL);
214  /* registration for for Global Tx Sub State */
216  HTTP2TxTypeGlobal, 0, DetectEngineInspectGenericList, NULL);
218  HTTP2TxTypeGlobal, 0, DetectEngineInspectGenericList, NULL);
219 
220  g_http2_complete_buffer_id = DetectBufferTypeRegister("http2:complete");
221 
222  /* registration for for Stream Tx Sub State */
224  HTTP2TxTypeStream, HTTP2ProgComplete, DetectEngineInspectGenericList, NULL);
226  HTTP2TxTypeStream, HTTP2ProgComplete, DetectEngineInspectGenericList, NULL);
227  /* registration for for Global Tx Sub State */
229  HTTP2TxTypeGlobal, HTTP2ProgGlobalComplete, DetectEngineInspectGenericList, NULL);
231  HTTP2TxTypeGlobal, HTTP2ProgGlobalComplete, DetectEngineInspectGenericList, NULL);
232 }
233 
234 /**
235  * \brief This function is used to match HTTP2 frame type rule option on a transaction with those passed via http2.frametype:
236  *
237  * \retval 0 no match
238  * \retval 1 match
239  */
240 static int DetectHTTP2frametypeMatch(DetectEngineThreadCtx *det_ctx,
241  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
242  const SigMatchCtx *ctx)
243 
244 {
245  return SCHttp2TxHasFrametype(txv, flags, ctx);
246 }
247 
248 /**
249  * \brief this function is used to attach the parsed http2.frametype data into the current signature
250  *
251  * \param de_ctx pointer to the Detection Engine Context
252  * \param s pointer to the Current Signature
253  * \param str pointer to the user provided http2.frametype options
254  *
255  * \retval 0 on Success
256  * \retval -1 on Failure
257  */
258 static int DetectHTTP2frametypeSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
259 {
261  return -1;
262 
263  void *dua8 = SCHttp2ParseFrametype(str);
264  if (dua8 == NULL) {
265  SCLogError("Invalid http2.frametype: %s", str);
266  return -1;
267  }
268 
270  g_http2_complete_buffer_id) == NULL) {
271  DetectHTTP2frametypeFree(NULL, dua8);
272  return -1;
273  }
274 
275  return 0;
276 }
277 
278 /**
279  * \brief this function will free memory associated with uint8_t
280  *
281  * \param ptr pointer to uint8_t
282  */
284 {
285  SCDetectU8ArrayFree(ptr);
286 }
287 
288 /**
289  * \brief This function is used to match HTTP2 error code rule option on a transaction with those passed via http2.errorcode:
290  *
291  * \retval 0 no match
292  * \retval 1 match
293  */
294 static int DetectHTTP2errorcodeMatch(DetectEngineThreadCtx *det_ctx,
295  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
296  const SigMatchCtx *ctx)
297 
298 {
299  return SCHttp2TxHasErrorCode(txv, flags, ctx);
300 }
301 
302 /**
303  * \brief this function is used to attach the parsed http2.errorcode data into the current signature
304  *
305  * \param de_ctx pointer to the Detection Engine Context
306  * \param s pointer to the Current Signature
307  * \param str pointer to the user provided http2.errorcode options
308  *
309  * \retval 0 on Success
310  * \retval -1 on Failure
311  */
312 static int DetectHTTP2errorcodeSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
313 {
315  return -1;
316 
317  void *dua32 = SCHttp2ParseErrorCode(str);
318  if (dua32 == NULL) {
319  SCLogError("Invalid http2.errorcode: %s", str);
320  return -1;
321  }
322 
324  g_http2_complete_buffer_id) == NULL) {
325  DetectHTTP2errorcodeFree(NULL, dua32);
326  return -1;
327  }
328 
329  return 0;
330 }
331 
332 /**
333  * \brief this function will free memory associated with uint32_t
334  *
335  * \param ptr pointer to uint32_t
336  */
338 {
339  SCDetectU32ArrayFree(ptr);
340 }
341 
342 /**
343  * \brief This function is used to match HTTP2 error code rule option on a transaction with those passed via http2.priority:
344  *
345  * \retval 0 no match
346  * \retval 1 match
347  */
348 static int DetectHTTP2priorityMatch(DetectEngineThreadCtx *det_ctx,
349  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
350  const SigMatchCtx *ctx)
351 
352 {
353  return SCHttp2PriorityMatch(txv, flags, ctx);
354 }
355 
356 /**
357  * \brief this function is used to attach the parsed http2.priority data into the current signature
358  *
359  * \param de_ctx pointer to the Detection Engine Context
360  * \param s pointer to the Current Signature
361  * \param str pointer to the user provided http2.priority options
362  *
363  * \retval 0 on Success
364  * \retval -1 on Failure
365  */
366 static int DetectHTTP2prioritySetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
367 {
369  return -1;
370 
371  void *prio = SCDetectU8ArrayParse(str);
372  if (prio == NULL)
373  return -1;
374 
376  g_http2_complete_buffer_id) == NULL) {
377  DetectHTTP2priorityFree(NULL, prio);
378  return -1;
379  }
380 
381  return 0;
382 }
383 
384 /**
385  * \brief this function will free memory associated with uint32_t
386  *
387  * \param ptr pointer to DetectU8Data
388  */
390 {
391  SCDetectU8ArrayFree(ptr);
392 }
393 
394 /**
395  * \brief This function is used to match HTTP2 window rule option on a transaction with those passed via http2.window:
396  *
397  * \retval 0 no match
398  * \retval 1 match
399  */
400 static int DetectHTTP2windowMatch(DetectEngineThreadCtx *det_ctx,
401  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
402  const SigMatchCtx *ctx)
403 
404 {
405  return SCHttp2WindowMatch(txv, flags, ctx);
406 }
407 
408 /**
409  * \brief this function is used to attach the parsed http2.window data into the current signature
410  *
411  * \param de_ctx pointer to the Detection Engine Context
412  * \param s pointer to the Current Signature
413  * \param str pointer to the user provided http2.window options
414  *
415  * \retval 0 on Success
416  * \retval -1 on Failure
417  */
418 static int DetectHTTP2windowSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
419 {
421  return -1;
422 
423  void *wu = SCDetectU32ArrayParse(str);
424  if (wu == NULL)
425  return -1;
426 
427  // use g_http2_complete_buffer_id as we may have window changes in any state
429  g_http2_complete_buffer_id) == NULL) {
430  DetectHTTP2windowFree(NULL, wu);
431  return -1;
432  }
433 
434  return 0;
435 }
436 
437 /**
438  * \brief this function will free memory associated with uint32_t
439  *
440  * \param ptr pointer to DetectU8Data
441  */
443 {
444  SCDetectU32ArrayFree(ptr);
445 }
446 
447 /**
448  * \brief This function is used to match HTTP2 size update rule option on a transaction with those passed via http2.size_update:
449  *
450  * \retval 0 no match
451  * \retval 1 match
452  */
453 static int DetectHTTP2sizeUpdateMatch(DetectEngineThreadCtx *det_ctx,
454  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
455  const SigMatchCtx *ctx)
456 
457 {
458  return SCHttp2DetectSizeUpdateCtxMatch(ctx, txv, flags);
459 }
460 
461 /**
462  * \brief this function is used to attach the parsed http2.size_update data into the current signature
463  *
464  * \param de_ctx pointer to the Detection Engine Context
465  * \param s pointer to the Current Signature
466  * \param str pointer to the user provided http2.size_update options
467  *
468  * \retval 0 on Success
469  * \retval -1 on Failure
470  */
471 static int DetectHTTP2sizeUpdateSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
472 {
474  return -1;
475 
476  DetectU64Data *su = SCDetectU64Parse(str);
477  if (su == NULL)
478  return -1;
479 
481  g_http2_header_buffer_id) == NULL) {
482  DetectHTTP2sizeUpdateFree(NULL, su);
483  return -1;
484  }
485 
486  return 0;
487 }
488 
489 /**
490  * \brief this function will free memory associated with uint32_t
491  *
492  * \param ptr pointer to DetectU8Data
493  */
495 {
496  SCDetectU64Free(ptr);
497 }
498 
499 /**
500  * \brief This function is used to match HTTP2 error code rule option on a transaction with those passed via http2.settings:
501  *
502  * \retval 0 no match
503  * \retval 1 match
504  */
505 static int DetectHTTP2settingsMatch(DetectEngineThreadCtx *det_ctx,
506  Flow *f, uint8_t flags, void *state, void *txv, const Signature *s,
507  const SigMatchCtx *ctx)
508 
509 {
510  return SCHttp2DetectSettingsCtxMatch(ctx, txv, flags);
511 }
512 
513 /**
514  * \brief this function is used to attach the parsed http2.settings data into the current signature
515  *
516  * \param de_ctx pointer to the Detection Engine Context
517  * \param s pointer to the Current Signature
518  * \param str pointer to the user provided http2.settings options
519  *
520  * \retval 0 on Success
521  * \retval -1 on Failure
522  */
523 static int DetectHTTP2settingsSetup (DetectEngineCtx *de_ctx, Signature *s, const char *str)
524 {
526  return -1;
527 
528  void *http2set = SCHttp2DetectSettingsCtxParse(str);
529  if (http2set == NULL)
530  return -1;
531 
533  g_http2_match_buffer_id) == NULL) {
534  DetectHTTP2settingsFree(NULL, http2set);
535  return -1;
536  }
537 
538  return 0;
539 }
540 
541 /**
542  * \brief this function will free memory associated with rust signature context
543  *
544  * \param ptr pointer to rust signature context
545  */
547 {
548  SCHttp2DetectSettingsCtxFree(ptr);
549 }
550 
551 static int DetectHTTP2headerNameSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg)
552 {
553  if (SCDetectBufferSetActiveList(de_ctx, s, g_http2_header_buffer_id) < 0)
554  return -1;
555 
557  return -1;
558 
559  return 0;
560 }
561 
562 #ifdef UNITTESTS
563 #include "tests/detect-http2.c"
564 #endif
SCJsonBuilder
struct SCJsonBuilder SCJsonBuilder
Definition: detect-engine-helper.h:83
util-byte.h
detect-engine-uint.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-content.h
detect-engine.h
SIGMATCH_NOOPT
#define SIGMATCH_NOOPT
Definition: detect-engine-register.h:308
SIGMATCH_INFO_MULTI_UINT
#define SIGMATCH_INFO_MULTI_UINT
Definition: detect-engine-register.h:350
DetectHTTP2priorityRegisterTests
void DetectHTTP2priorityRegisterTests(void)
Definition: detect-http2.c:90
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
DetectHTTP2RegisterTests
void DetectHTTP2RegisterTests(void)
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
SIGMATCH_INFO_UINT8
#define SIGMATCH_INFO_UINT8
Definition: detect-engine-register.h:342
Flow_
Flow data structure.
Definition: flow.h:359
DETECT_HTTP2_SETTINGS
@ DETECT_HTTP2_SETTINGS
Definition: detect-engine-register.h:214
ctx
struct Thresholds ctx
DetectHTTP2priorityFree
void DetectHTTP2priorityFree(DetectEngineCtx *, void *)
this function will free memory associated with uint32_t
Definition: detect-http2.c:389
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DETECT_HTTP2_SIZEUPDATE
@ DETECT_HTTP2_SIZEUPDATE
Definition: detect-engine-register.h:213
DetectBufferTypeSupportsMultiInstance
void DetectBufferTypeSupportsMultiInstance(const char *name)
Definition: detect-engine.c:1402
SigTableElmt_::AppLayerTxMatch
int(* AppLayerTxMatch)(DetectEngineThreadCtx *, Flow *, uint8_t flags, void *alstate, void *txv, const Signature *, const SigMatchCtx *)
Definition: detect.h:1507
DetectAppLayerMultiRegisterSubState
void DetectAppLayerMultiRegisterSubState(const char *name, AppProto alproto, uint32_t dir, uint8_t sub_state, uint8_t progress, InspectionMultiBufferGetDataPtr GetData, int priority)
Definition: detect-engine.c:2317
rust.h
DetectHTTP2sizeUpdateFree
void DetectHTTP2sizeUpdateFree(DetectEngineCtx *, void *)
this function will free memory associated with uint32_t
Definition: detect-http2.c:494
DETECT_HTTP2_HEADERNAME
@ DETECT_HTTP2_HEADERNAME
Definition: detect-engine-register.h:215
SCDetectBufferSetActiveList
int SCDetectBufferSetActiveList(DetectEngineCtx *de_ctx, Signature *s, const int list)
Definition: detect-engine-buffer.c:29
SCDetectSignatureSetAppProto
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
Definition: detect-parse.c:2613
SIG_FLAG_TOCLIENT
#define SIG_FLAG_TOCLIENT
Definition: detect.h:275
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
detect-engine-prefilter.h
DetectBufferTypeGetByName
int DetectBufferTypeGetByName(const char *name)
Definition: detect-engine.c:1452
SIGMATCH_INFO_MULTI_BUFFER
#define SIGMATCH_INFO_MULTI_BUFFER
Definition: detect-engine-register.h:340
SIG_FLAG_TOSERVER
#define SIG_FLAG_TOSERVER
Definition: detect.h:274
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
detect-http2.h
DetectEngineThreadCtx_
Definition: detect.h:1316
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
SIGMATCH_INFO_UINT64
#define SIGMATCH_INFO_UINT64
Definition: detect-engine-register.h:348
DetectHTTP2sizeUpdateRegisterTests
void DetectHTTP2sizeUpdateRegisterTests(void)
Definition: detect-http2.c:158
DetectHTTP2settingsFree
void DetectHTTP2settingsFree(DetectEngineCtx *, void *)
this function will free memory associated with rust signature context
Definition: detect-http2.c:546
detect-engine-helper.h
DetectHTTP2settingsRegisterTests
void DetectHTTP2settingsRegisterTests(void)
Definition: detect-http2.c:135
util-profiling.h
SigTableElmt_::JsonAdditionalInfo
void(* JsonAdditionalInfo)(struct SCJsonBuilder *)
Definition: detect.h:1551
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
ALPROTO_HTTP2
@ ALPROTO_HTTP2
Definition: app-layer-protos.h:69
DetectHTTP2windowRegisterTests
void DetectHTTP2windowRegisterTests(void)
Definition: detect-http2.c:112
detect-engine-content-inspection.h
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
DetectBufferTypeRegister
int DetectBufferTypeRegister(const char *name)
Definition: detect-engine.c:1388
flags
uint8_t flags
Definition: decode-gre.h:0
suricata-common.h
DetectHTTP2windowFree
void DetectHTTP2windowFree(DetectEngineCtx *, void *)
this function will free memory associated with uint32_t
Definition: detect-http2.c:442
DETECT_HTTP2_ERRORCODE
@ DETECT_HTTP2_ERRORCODE
Definition: detect-engine-register.h:210
detect-engine-buffer.h
DetectHttp2Register
void DetectHttp2Register(void)
Registration function for HTTP2 keywords.
Definition: detect-http2.c:114
DetectEngineInspectGenericList
uint8_t DetectEngineInspectGenericList(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Definition: detect-engine.c:2155
DetectAppLayerInspectEngineRegisterSubState
void DetectAppLayerInspectEngineRegisterSubState(const char *name, AppProto alproto, uint32_t dir, uint8_t sub_state, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
register an app inspection engine for a tx type
Definition: detect-engine.c:298
SIGMATCH_INFO_ENUM_UINT
#define SIGMATCH_INFO_ENUM_UINT
Definition: detect-engine-register.h:352
str
#define str(s)
Definition: suricata-common.h:313
DetectU64Data
DetectUintData_u64 DetectU64Data
Definition: detect-engine-uint.h:40
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
DetectHTTP2errorCodeRegisterTests
void DetectHTTP2errorCodeRegisterTests(void)
Definition: detect-http2.c:68
SIGMATCH_INFO_UINT32
#define SIGMATCH_INFO_UINT32
Definition: detect-engine-register.h:346
DETECT_HTTP2_WINDOW
@ DETECT_HTTP2_WINDOW
Definition: detect-engine-register.h:212
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
SIGMATCH_INFO_STICKY_BUFFER
#define SIGMATCH_INFO_STICKY_BUFFER
Definition: detect-engine-register.h:330
DETECT_HTTP2_PRIORITY
@ DETECT_HTTP2_PRIORITY
Definition: detect-engine-register.h:211
detect-http2.c
DetectBufferTypeSetDescriptionByName
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
Definition: detect-engine.c:1549
DetectHTTP2frameTypeRegisterTests
void DetectHTTP2frameTypeRegisterTests(void)
this function registers unit tests for DetectHTTP2frameType
Definition: detect-http2.c:46
DetectHTTP2errorcodeFree
void DetectHTTP2errorcodeFree(DetectEngineCtx *, void *)
this function will free memory associated with uint32_t
Definition: detect-http2.c:337
DetectHTTP2frametypeFree
void DetectHTTP2frametypeFree(DetectEngineCtx *, void *)
this function will free memory associated with uint8_t
Definition: detect-http2.c:283
DETECT_HTTP2_FRAMETYPE
@ DETECT_HTTP2_FRAMETYPE
Definition: detect-engine-register.h:209
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
f
Flow f
Definition: fuzz_dataset.c:32