suricata
detect-icmp-id.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2020 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Gerardo Iglesias Galvan <iglesiasg@gmail.com>
22  *
23  * Implements the icmp_id keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-parse.h"
32 #include "detect-engine-build.h"
33 #include "detect-engine-alert.h"
34 #include "detect-engine-uint.h"
35 
36 #include "detect-icmp-id.h"
37 
38 #include "util-byte.h"
39 #include "util-unittest-helper.h"
40 #include "util-debug.h"
41 
42 static int DetectIcmpIdMatch(DetectEngineThreadCtx *, Packet *,
43  const Signature *, const SigMatchCtx *);
44 static int DetectIcmpIdSetup(DetectEngineCtx *, Signature *, const char *);
45 #ifdef UNITTESTS
46 static void DetectIcmpIdRegisterTests(void);
47 #endif
48 void DetectIcmpIdFree(DetectEngineCtx *, void *);
49 static int PrefilterSetupIcmpId(DetectEngineCtx *de_ctx, SigGroupHead *sgh);
50 static bool PrefilterIcmpIdIsPrefilterable(const Signature *s);
51 
52 /**
53  * \brief Registration function for icode: icmp_id
54  */
56 {
57  sigmatch_table[DETECT_ICMP_ID].name = "icmp_id";
58  sigmatch_table[DETECT_ICMP_ID].desc = "check for a ICMP ID";
59  sigmatch_table[DETECT_ICMP_ID].url = "/rules/header-keywords.html#icmp-id";
60  sigmatch_table[DETECT_ICMP_ID].Match = DetectIcmpIdMatch;
61  sigmatch_table[DETECT_ICMP_ID].Setup = DetectIcmpIdSetup;
64 #ifdef UNITTESTS
65  sigmatch_table[DETECT_ICMP_ID].RegisterTests = DetectIcmpIdRegisterTests;
66 #endif
67  sigmatch_table[DETECT_ICMP_ID].SupportsPrefilter = PrefilterIcmpIdIsPrefilterable;
68  sigmatch_table[DETECT_ICMP_ID].SetupPrefilter = PrefilterSetupIcmpId;
69 }
70 
71 static inline bool GetIcmpId(Packet *p, uint16_t *id)
72 {
73  uint16_t pid;
74  if (PacketIsICMPv4(p)) {
75  switch (p->icmp_s.type) {
76  case ICMP_ECHOREPLY:
77  case ICMP_ECHO:
78  case ICMP_TIMESTAMP:
80  case ICMP_INFO_REQUEST:
81  case ICMP_INFO_REPLY:
82  case ICMP_ADDRESS:
83  case ICMP_ADDRESSREPLY:
84  SCLogDebug("ICMPV4_GET_ID(p) %"PRIu16" (network byte order), "
85  "%"PRIu16" (host byte order)", ICMPV4_GET_ID(p),
87 
88  pid = ICMPV4_GET_ID(p);
89  break;
90  default:
91  SCLogDebug("Packet has no id field");
92  return false;
93  }
94  } else if (PacketIsICMPv6(p)) {
95  switch (ICMPV6_GET_TYPE(PacketGetICMPv6(p))) {
96  case ICMP6_ECHO_REQUEST:
97  case ICMP6_ECHO_REPLY:
98  SCLogDebug("ICMPV6_GET_ID(p) %"PRIu16" (network byte order), "
99  "%"PRIu16" (host byte order)", ICMPV6_GET_ID(p),
101 
102  pid = ICMPV6_GET_ID(p);
103  break;
104  default:
105  SCLogDebug("Packet has no id field");
106  return false;
107  }
108  } else {
109  SCLogDebug("Packet not ICMPV4 nor ICMPV6");
110  return false;
111  }
112 
113  *id = SCNtohs(pid);
114  return true;
115 }
116 
117 /**
118  * \brief This function is used to match icmp_id rule option set on a packet
119  *
120  * \param t pointer to thread vars
121  * \param det_ctx pointer to the pattern matcher thread
122  * \param p pointer to the current packet
123  * \param m pointer to the sigmatch that we will cast into DetectIcmpIdData
124  *
125  * \retval 0 no match
126  * \retval 1 match
127  */
128 static int DetectIcmpIdMatch (DetectEngineThreadCtx *det_ctx, Packet *p,
129  const Signature *s, const SigMatchCtx *ctx)
130 {
131  uint16_t pid;
132 
133  if (!GetIcmpId(p, &pid))
134  return 0;
135 
136  const DetectU16Data *iid = (const DetectU16Data *)ctx;
137  return DetectU16Match(pid, iid);
138 }
139 
140 /**
141  * \brief this function is used to add the parsed icmp_id data into the current signature
142  *
143  * \param de_ctx pointer to the Detection Engine Context
144  * \param s pointer to the Current Signature
145  * \param icmpidstr pointer to the user provided icmp_id option
146  *
147  * \retval 0 on Success
148  * \retval -1 on Failure
149  */
150 static int DetectIcmpIdSetup (DetectEngineCtx *de_ctx, Signature *s, const char *icmpidstr)
151 {
152  DetectU16Data *iid = SCDetectU16UnquoteParse(icmpidstr);
153  if (iid == NULL)
154  return -1;
155 
157  de_ctx, s, DETECT_ICMP_ID, (SigMatchCtx *)iid, DETECT_SM_LIST_MATCH) == NULL) {
158  goto error;
159  }
161 
162  return 0;
163 
164 error:
165  DetectIcmpIdFree(de_ctx, iid);
166  return -1;
167 
168 }
169 
170 /**
171  * \brief this function will free memory associated with DetectIcmpIdData
172  *
173  * \param ptr pointer to DetectIcmpIdData
174  */
176 {
177  SCDetectU16Free(ptr);
178 }
179 
180 /* prefilter code */
181 
182 static void
183 PrefilterPacketIcmpIdMatch(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx)
184 {
185  const PrefilterPacketHeaderCtx *ctx = pectx;
186 
187  uint16_t pid;
188  if (!GetIcmpId(p, &pid))
189  return;
190 
191  DetectU16Data du16;
192  du16.mode = ctx->v1.u8[0];
193  du16.arg1 = ctx->v1.u16[1];
194  du16.arg2 = ctx->v1.u16[2];
195  if (DetectU16Match(pid, &du16)) {
196  SCLogDebug("packet matches ICMP ID %u", ctx->v1.u16[0]);
197  PrefilterAddSids(&det_ctx->pmq, ctx->sigs_array, ctx->sigs_cnt);
198  }
199 }
200 
201 static int PrefilterSetupIcmpId(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
202 {
204  PrefilterPacketU16Set, PrefilterPacketU16Compare, PrefilterPacketIcmpIdMatch);
205 }
206 
207 static bool PrefilterIcmpIdIsPrefilterable(const Signature *s)
208 {
209  return PrefilterIsPrefilterableById(s, DETECT_ICMP_ID);
210 }
211 
212 #ifdef UNITTESTS
213 #include "detect-engine.h"
214 #include "detect-engine-mpm.h"
215 
216 /**
217  * \test DetectIcmpIdParseTest01 is a test for setting a valid icmp_id value
218  */
219 static int DetectIcmpIdParseTest01 (void)
220 {
221  DetectU16Data *iid = SCDetectU16UnquoteParse("300");
222  FAIL_IF_NULL(iid);
223  FAIL_IF_NOT(iid->arg1 == 300);
224  DetectIcmpIdFree(NULL, iid);
225  PASS;
226 }
227 
228 /**
229  * \test DetectIcmpIdParseTest02 is a test for setting a valid icmp_id value
230  * with spaces all around
231  */
232 static int DetectIcmpIdParseTest02 (void)
233 {
234  DetectU16Data *iid = SCDetectU16UnquoteParse(" 300 ");
235  FAIL_IF_NULL(iid);
236  FAIL_IF_NOT(iid->arg1 == 300);
237  DetectIcmpIdFree(NULL, iid);
238  PASS;
239 }
240 
241 /**
242  * \test DetectIcmpIdParseTest03 is a test for setting a valid icmp_id value
243  * with quotation marks
244  */
245 static int DetectIcmpIdParseTest03 (void)
246 {
247  DetectU16Data *iid = SCDetectU16UnquoteParse("\"300\"");
248  FAIL_IF_NULL(iid);
249  FAIL_IF_NOT(iid->arg1 == 300);
250  DetectIcmpIdFree(NULL, iid);
251  PASS;
252 }
253 
254 /**
255  * \test DetectIcmpIdParseTest04 is a test for setting a valid icmp_id value
256  * with quotation marks and spaces all around
257  */
258 static int DetectIcmpIdParseTest04 (void)
259 {
260  DetectU16Data *iid = SCDetectU16UnquoteParse(" \" 300 \"");
261  FAIL_IF_NULL(iid);
262  FAIL_IF_NOT(iid->arg1 == 300);
263  DetectIcmpIdFree(NULL, iid);
264  PASS;
265 }
266 
267 /**
268  * \test DetectIcmpIdParseTest05 is a test for setting an invalid icmp_id
269  * value with missing quotation marks
270  */
271 static int DetectIcmpIdParseTest05 (void)
272 {
273  DetectU16Data *iid = SCDetectU16UnquoteParse("\"300");
274  FAIL_IF_NOT_NULL(iid);
275  PASS;
276 }
277 
278 /**
279  * \test DetectIcmpIdMatchTest01 is a test for checking the working of
280  * icmp_id keyword by creating 2 rules and matching a crafted packet
281  * against them. Only the first one shall trigger.
282  */
283 static int DetectIcmpIdMatchTest01 (void)
284 {
285  int result = 0;
286  Packet *p = NULL;
287  Signature *s = NULL;
289  DetectEngineThreadCtx *det_ctx = NULL;
290 
291  memset(&th_v, 0, sizeof(ThreadVars));
293 
294  p = UTHBuildPacket(NULL, 0, IPPROTO_ICMP);
295  p->l4.vars.icmpv4.id = htons(21781);
296 
298  if (de_ctx == NULL) {
299  goto end;
300  }
301 
302  de_ctx->flags |= DE_QUIET;
303 
304  s = de_ctx->sig_list = SigInit(de_ctx, "alert icmp any any -> any any (icmp_id:21781; sid:1;)");
305  if (s == NULL) {
306  goto end;
307  }
308 
309  s = s->next = SigInit(de_ctx, "alert icmp any any -> any any (icmp_id:21782; sid:2;)");
310  if (s == NULL) {
311  goto end;
312  }
313 
315  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
316 
317  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
318  if (PacketAlertCheck(p, 1) == 0) {
319  printf("sid 1 did not alert, but should have: ");
320  goto cleanup;
321  } else if (PacketAlertCheck(p, 2)) {
322  printf("sid 2 alerted, but should not have: ");
323  goto cleanup;
324  }
325 
326  result = 1;
327 
328 cleanup:
329  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
331 
332  UTHFreePackets(&p, 1);
333 end:
335  return result;
336 
337 }
338 
339 /**
340  * \test DetectIcmpIdMatchTest02 is a test for checking the working of
341  * icmp_id keyword by creating 1 rule and matching a crafted packet
342  * against them. The packet is an ICMP packet with no "id" field,
343  * therefore the rule should not trigger.
344  */
345 static int DetectIcmpIdMatchTest02 (void)
346 {
347  int result = 0;
348 
349  uint8_t raw_icmpv4[] = {
350  0x0b, 0x00, 0x8a, 0xdf, 0x00, 0x00, 0x00, 0x00,
351  0x45, 0x00, 0x00, 0x14, 0x25, 0x0c, 0x00, 0x00,
352  0xff, 0x11, 0x00, 0x00, 0x85, 0x64, 0xea, 0x5b,
353  0x51, 0xa6, 0xbb, 0x35, 0x59, 0x8a, 0x5a, 0xe2,
354  0x00, 0x14, 0x00, 0x00 };
355 
357  if (unlikely(p == NULL))
358  return 0;
359  Signature *s = NULL;
362  DetectEngineThreadCtx *det_ctx = NULL;
363  IPV4Hdr ip4h;
364 
365  memset(&ip4h, 0, sizeof(IPV4Hdr));
366  memset(&dtv, 0, sizeof(DecodeThreadVars));
367  memset(&th_v, 0, sizeof(ThreadVars));
369 
371 
372  p->src.addr_data32[0] = 0x01020304;
373  p->dst.addr_data32[0] = 0x04030201;
374 
375  ip4h.s_ip_src.s_addr = p->src.addr_data32[0];
376  ip4h.s_ip_dst.s_addr = p->dst.addr_data32[0];
377  UTHSetIPV4Hdr(p, &ip4h);
378 
379  DecodeICMPV4(&th_v, &dtv, p, raw_icmpv4, sizeof(raw_icmpv4));
380 
382  if (de_ctx == NULL) {
383  goto end;
384  }
385 
386  de_ctx->flags |= DE_QUIET;
387 
388  s = de_ctx->sig_list = SigInit(de_ctx, "alert icmp any any -> any any (icmp_id:0; sid:1;)");
389  if (s == NULL) {
390  goto end;
391  }
392 
394  DetectEngineThreadCtxInit(&th_v, (void *)de_ctx, (void *)&det_ctx);
395 
396  SigMatchSignatures(&th_v, de_ctx, det_ctx, p);
397  if (PacketAlertCheck(p, 1)) {
398  printf("sid 1 alerted, but should not have: ");
399  goto cleanup;
400  }
401 
402  result = 1;
403 
404 cleanup:
405  DetectEngineThreadCtxDeinit(&th_v, (void *)det_ctx);
407 
408  FlowShutdown();
409 end:
410  PacketFree(p);
412  return result;
413 }
414 
415 static void DetectIcmpIdRegisterTests (void)
416 {
417  UtRegisterTest("DetectIcmpIdParseTest01", DetectIcmpIdParseTest01);
418  UtRegisterTest("DetectIcmpIdParseTest02", DetectIcmpIdParseTest02);
419  UtRegisterTest("DetectIcmpIdParseTest03", DetectIcmpIdParseTest03);
420  UtRegisterTest("DetectIcmpIdParseTest04", DetectIcmpIdParseTest04);
421  UtRegisterTest("DetectIcmpIdParseTest05", DetectIcmpIdParseTest05);
422  UtRegisterTest("DetectIcmpIdMatchTest01", DetectIcmpIdMatchTest01);
423  UtRegisterTest("DetectIcmpIdMatchTest02", DetectIcmpIdMatchTest02);
424 }
425 #endif /* UNITTESTS */
util-byte.h
detect-engine-uint.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
SIG_MASK_REQUIRE_REAL_PKT
#define SIG_MASK_REQUIRE_REAL_PKT
Definition: detect.h:320
PrefilterPacketU16Set
void PrefilterPacketU16Set(PrefilterPacketHeaderValue *v, void *smctx)
Definition: detect-engine-uint.c:124
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
ICMP_INFO_REQUEST
#define ICMP_INFO_REQUEST
Definition: decode-icmpv4.h:66
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
PacketAlertCheck
int PacketAlertCheck(Packet *p, uint32_t sid)
Check if a certain sid alerted, this is used in the test functions.
Definition: detect-engine-alert.c:144
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
UTHSetIPV4Hdr
void UTHSetIPV4Hdr(Packet *p, IPV4Hdr *ip4h)
Definition: util-unittest-helper.c:251
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
DE_QUIET
#define DE_QUIET
Definition: detect.h:334
ICMPV6_GET_ID
#define ICMPV6_GET_ID(p)
Definition: decode-icmpv6.h:107
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
SigMatchSignatures
void SigMatchSignatures(ThreadVars *tv, DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, Packet *p)
wrapper for old tests
Definition: detect.c:3305
p
Packet * p
Definition: fuzz_dataset.c:30
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
ICMP6_ECHO_REQUEST
#define ICMP6_ECHO_REQUEST
Definition: decode-icmpv6.h:42
ICMP_ECHO
#define ICMP_ECHO
Definition: decode-icmpv4.h:45
Packet_::icmp_s
struct Packet_::@32::@39 icmp_s
SigTableElmt_::SetupPrefilter
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
Definition: detect.h:1527
Signature_::next
struct Signature_ * next
Definition: detect.h:778
ICMP_ADDRESSREPLY
#define ICMP_ADDRESSREPLY
Definition: decode-icmpv4.h:75
FlowInitConfig
void FlowInitConfig(bool quiet)
initialize the configuration
Definition: flow.c:574
ICMP_ADDRESS
#define ICMP_ADDRESS
Definition: decode-icmpv4.h:72
PrefilterPacketHeaderCtx_
Definition: detect-engine-prefilter-common.h:35
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
SIGMATCH_INFO_UINT16
#define SIGMATCH_INFO_UINT16
Definition: detect-engine-register.h:344
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
ICMP6_ECHO_REPLY
#define ICMP6_ECHO_REPLY
Definition: decode-icmpv6.h:43
DetectEngineThreadCtx_
Definition: detect.h:1316
PacketL4::L4Vars::icmpv4
ICMPV4Vars icmpv4
Definition: decode.h:492
detect-engine-mpm.h
DetectIcmpIdRegister
void DetectIcmpIdRegister(void)
Registration function for icode: icmp_id.
Definition: detect-icmp-id.c:55
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
ThreadVars_
Per thread variable structure.
Definition: threadvars.h:57
DetectEngineThreadCtxInit
TmEcode DetectEngineThreadCtxInit(ThreadVars *tv, void *initdata, void **data)
initialize thread specific detection engine context
Definition: detect-engine.c:3660
PacketFree
void PacketFree(Packet *p)
Return a malloced packet.
Definition: decode.c:221
DETECT_ICMP_ID
@ DETECT_ICMP_ID
Definition: detect-engine-register.h:49
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
ICMPV4Vars_::id
uint16_t id
Definition: decode-icmpv4.h:186
SigInit
Signature * SigInit(DetectEngineCtx *de_ctx, const char *sigstr)
Parses a signature and adds it to the Detection Engine Context.
Definition: detect-parse.c:3618
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
detect-engine-build.h
ICMP_INFO_REPLY
#define ICMP_INFO_REPLY
Definition: decode-icmpv4.h:69
detect-engine-alert.h
Packet_::l4
struct PacketL4 l4
Definition: decode.h:616
PrefilterSetupPacketHeader
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
Definition: detect-engine-prefilter-common.c:470
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
ICMP_ECHOREPLY
#define ICMP_ECHOREPLY
Definition: decode-icmpv4.h:33
SigGroupBuild
int SigGroupBuild(DetectEngineCtx *de_ctx)
Convert the signature list into the runtime match structure.
Definition: detect-engine-build.c:2300
dtv
DecodeThreadVars * dtv
Definition: fuzz_decodepcapfile.c:35
StatsThreadInit
void StatsThreadInit(StatsThreadContext *stats)
Definition: counters.c:1332
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
IPV4Hdr_
Definition: decode-ipv4.h:72
ICMPV4_GET_ID
#define ICMPV4_GET_ID(p)
Definition: decode-icmpv4.h:236
th_v
ThreadVars * th_v
Definition: fuzz_dataset.c:29
DetectU16Match
int DetectU16Match(const uint16_t parg, const DetectUintData_u16 *du16)
Definition: detect-engine-uint.c:105
PrefilterPacketU16Compare
bool PrefilterPacketU16Compare(PrefilterPacketHeaderValue v, void *smctx)
Definition: detect-engine-uint.c:132
SCNtohs
#define SCNtohs(x)
Definition: suricata-common.h:436
suricata-common.h
FlowShutdown
void FlowShutdown(void)
shutdown the flow engine
Definition: flow.c:718
DetectEngineThreadCtxDeinit
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *tv, void *data)
Definition: detect-engine.c:3905
DetectEngineCtx_::sig_list
Signature * sig_list
Definition: detect.h:1005
PacketGetFromAlloc
Packet * PacketGetFromAlloc(void)
Get a malloced packet.
Definition: decode.c:260
DecodeThreadVars_
Structure to hold thread specific data for all decode modules.
Definition: decode.h:995
SigTableElmt_::SupportsPrefilter
bool(* SupportsPrefilter)(const Signature *s)
Definition: detect.h:1526
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
DetectIcmpIdFree
void DetectIcmpIdFree(DetectEngineCtx *, void *)
this function will free memory associated with DetectIcmpIdData
Definition: detect-icmp-id.c:175
ICMP_TIMESTAMPREPLY
#define ICMP_TIMESTAMPREPLY
Definition: decode-icmpv4.h:63
ICMPV6_GET_TYPE
#define ICMPV6_GET_TYPE(icmp6h)
Definition: decode-icmpv6.h:101
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
detect-icmp-id.h
Packet_::dst
Address dst
Definition: decode.h:521
FLOW_QUIET
#define FLOW_QUIET
Definition: flow.h:43
ICMP_TIMESTAMP
#define ICMP_TIMESTAMP
Definition: decode-icmpv4.h:60
DetectEngineCtx_::flags
uint8_t flags
Definition: detect.h:997
detect-engine-prefilter-common.h
DetectU16Data
DetectUintData_u16 DetectU16Data
Definition: detect-engine-uint.h:42
ThreadVars_::stats
StatsThreadContext stats
Definition: threadvars.h:120
StatsThreadCleanup
void StatsThreadCleanup(StatsThreadContext *stats)
Definition: counters.c:1428
Packet_::src
Address src
Definition: decode.h:520
PacketL4::vars
union PacketL4::L4Vars vars
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
DecodeICMPV4
int DecodeICMPV4(ThreadVars *tv, DecodeThreadVars *dtv, Packet *p, const uint8_t *pkt, uint32_t len)
Main ICMPv4 decoding function.
Definition: decode-icmpv4.c:142
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257
UTHFreePackets
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:453