suricata
detect-icmp-seq.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2022 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Breno Silva <breno.silva@gmail.com>
22  *
23  * Implements the icmp_seq keyword
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 
29 #include "detect.h"
30 #include "detect-parse.h"
32 #include "detect-engine-build.h"
33 #include "detect-engine-uint.h"
34 
35 #include "detect-icmp-seq.h"
36 
37 #include "util-byte.h"
38 #include "util-unittest-helper.h"
39 #include "util-debug.h"
40 
41 static int DetectIcmpSeqMatch(DetectEngineThreadCtx *, Packet *,
42  const Signature *, const SigMatchCtx *);
43 static int DetectIcmpSeqSetup(DetectEngineCtx *, Signature *, const char *);
44 #ifdef UNITTESTS
45 static void DetectIcmpSeqRegisterTests(void);
46 #endif
47 void DetectIcmpSeqFree(DetectEngineCtx *, void *);
48 static int PrefilterSetupIcmpSeq(DetectEngineCtx *de_ctx, SigGroupHead *sgh);
49 static bool PrefilterIcmpSeqIsPrefilterable(const Signature *s);
50 
51 /**
52  * \brief Registration function for icmp_seq
53  */
55 {
56  sigmatch_table[DETECT_ICMP_SEQ].name = "icmp_seq";
57  sigmatch_table[DETECT_ICMP_SEQ].desc = "check for a ICMP sequence number";
58  sigmatch_table[DETECT_ICMP_SEQ].url = "/rules/header-keywords.html#icmp-seq";
59  sigmatch_table[DETECT_ICMP_SEQ].Match = DetectIcmpSeqMatch;
60  sigmatch_table[DETECT_ICMP_SEQ].Setup = DetectIcmpSeqSetup;
63 #ifdef UNITTESTS
64  sigmatch_table[DETECT_ICMP_SEQ].RegisterTests = DetectIcmpSeqRegisterTests;
65 #endif
66  sigmatch_table[DETECT_ICMP_SEQ].SupportsPrefilter = PrefilterIcmpSeqIsPrefilterable;
67  sigmatch_table[DETECT_ICMP_SEQ].SetupPrefilter = PrefilterSetupIcmpSeq;
68 }
69 
70 static inline bool GetIcmpSeq(Packet *p, uint16_t *seq)
71 {
72  uint16_t seqn;
73 
74  if (PacketIsICMPv4(p)) {
75  switch (p->icmp_s.type) {
76  case ICMP_ECHOREPLY:
77  case ICMP_ECHO:
78  case ICMP_TIMESTAMP:
80  case ICMP_INFO_REQUEST:
81  case ICMP_INFO_REPLY:
82  case ICMP_ADDRESS:
83  case ICMP_ADDRESSREPLY:
84  SCLogDebug("ICMPV4_GET_SEQ(p) %"PRIu16" (network byte order), "
85  "%"PRIu16" (host byte order)", ICMPV4_GET_SEQ(p),
87 
88  seqn = ICMPV4_GET_SEQ(p);
89  break;
90  default:
91  SCLogDebug("Packet has no seq field");
92  return false;
93  }
94  } else if (PacketIsICMPv6(p)) {
95  switch (ICMPV6_GET_TYPE(PacketGetICMPv6(p))) {
96  case ICMP6_ECHO_REQUEST:
97  case ICMP6_ECHO_REPLY:
98  SCLogDebug("ICMPV6_GET_SEQ(p) %"PRIu16" (network byte order), "
99  "%"PRIu16" (host byte order)", ICMPV6_GET_SEQ(p),
101 
102  seqn = ICMPV6_GET_SEQ(p);
103  break;
104  default:
105  SCLogDebug("Packet has no seq field");
106  return false;
107  }
108  } else {
109  SCLogDebug("Packet not ICMPV4 nor ICMPV6");
110  return false;
111  }
112 
113  *seq = SCNtohs(seqn);
114  return true;
115 }
116 
117 /**
118  * \brief This function is used to match icmp_seq rule option set on a packet
119  *
120  * \param t pointer to thread vars
121  * \param det_ctx pointer to the pattern matcher thread
122  * \param p pointer to the current packet
123  * \param m pointer to the sigmatch that we will cast into DetectU16Data
124  *
125  * \retval 0 no match
126  * \retval 1 match
127  */
128 static int DetectIcmpSeqMatch (DetectEngineThreadCtx *det_ctx, Packet *p,
129  const Signature *s, const SigMatchCtx *ctx)
130 {
132  uint16_t seqn;
133 
134  if (!GetIcmpSeq(p, &seqn))
135  return 0;
136 
137  const DetectU16Data *iseq = (const DetectU16Data *)ctx;
138  return DetectU16Match(seqn, iseq);
139 }
140 
141 /**
142  * \brief this function is used to add the parsed icmp_seq data into the current signature
143  *
144  * \param de_ctx pointer to the Detection Engine Context
145  * \param s pointer to the Current Signature
146  * \param icmpseqstr pointer to the user provided icmp_seq option
147  *
148  * \retval 0 on Success
149  * \retval -1 on Failure
150  */
151 static int DetectIcmpSeqSetup (DetectEngineCtx *de_ctx, Signature *s, const char *icmpseqstr)
152 {
153  DetectU16Data *iseq = SCDetectU16UnquoteParse(icmpseqstr);
154  if (iseq == NULL)
155  return -1;
156 
158  de_ctx, s, DETECT_ICMP_SEQ, (SigMatchCtx *)iseq, DETECT_SM_LIST_MATCH) == NULL) {
159  goto error;
160  }
162 
163  return 0;
164 
165 error:
166  DetectIcmpSeqFree(de_ctx, iseq);
167  return -1;
168 
169 }
170 
171 /**
172  * \brief this function will free memory associated with DetectU16Data
173  *
174  * \param ptr pointer to DetectU16Data
175  */
177 {
178  SCDetectU16Free(ptr);
179 }
180 
181 /* prefilter code */
182 
183 static void
184 PrefilterPacketIcmpSeqMatch(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx)
185 {
187 
188  const PrefilterPacketHeaderCtx *ctx = pectx;
189  uint16_t seqn;
190 
191  if (!GetIcmpSeq(p, &seqn))
192  return;
193 
194  DetectU16Data du16;
195  du16.mode = ctx->v1.u8[0];
196  du16.arg1 = ctx->v1.u16[1];
197  du16.arg2 = ctx->v1.u16[2];
198  if (DetectU16Match(seqn, &du16)) {
199  SCLogDebug("packet matches ICMP SEQ %u", ctx->v1.u16[0]);
200  PrefilterAddSids(&det_ctx->pmq, ctx->sigs_array, ctx->sigs_cnt);
201  }
202 }
203 
204 static int PrefilterSetupIcmpSeq(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
205 {
207  PrefilterPacketU16Set, PrefilterPacketU16Compare, PrefilterPacketIcmpSeqMatch);
208 }
209 
210 static bool PrefilterIcmpSeqIsPrefilterable(const Signature *s)
211 {
212  return PrefilterIsPrefilterableById(s, DETECT_ICMP_SEQ);
213 }
214 
215 #ifdef UNITTESTS
216 #include "detect-engine.h"
217 #include "detect-engine-mpm.h"
218 #include "detect-engine-alert.h"
219 
220 /**
221  * \test DetectIcmpSeqParseTest01 is a test for setting a valid icmp_seq value
222  */
223 static int DetectIcmpSeqParseTest01 (void)
224 {
225  DetectU16Data *iseq = NULL;
226  iseq = SCDetectU16UnquoteParse("300");
227  FAIL_IF_NULL(iseq);
228  FAIL_IF_NOT(iseq->arg1 == 300);
229  DetectIcmpSeqFree(NULL, iseq);
230  PASS;
231 }
232 
233 /**
234  * \test DetectIcmpSeqParseTest02 is a test for setting a valid icmp_seq value
235  * with spaces all around
236  */
237 static int DetectIcmpSeqParseTest02 (void)
238 {
239  DetectU16Data *iseq = NULL;
240  iseq = SCDetectU16UnquoteParse(" 300 ");
241  FAIL_IF_NULL(iseq);
242  FAIL_IF_NOT(iseq->arg1 == 300);
243  DetectIcmpSeqFree(NULL, iseq);
244  PASS;
245 }
246 
247 /**
248  * \test DetectIcmpSeqParseTest03 is a test for setting an invalid icmp_seq value
249  */
250 static int DetectIcmpSeqParseTest03 (void)
251 {
252  DetectU16Data *iseq = SCDetectU16UnquoteParse("badc");
253  FAIL_IF_NOT_NULL(iseq);
254  PASS;
255 }
256 
257 static void DetectIcmpSeqRegisterTests (void)
258 {
259  UtRegisterTest("DetectIcmpSeqParseTest01", DetectIcmpSeqParseTest01);
260  UtRegisterTest("DetectIcmpSeqParseTest02", DetectIcmpSeqParseTest02);
261  UtRegisterTest("DetectIcmpSeqParseTest03", DetectIcmpSeqParseTest03);
262 }
263 #endif /* UNITTESTS */
util-byte.h
detect-engine-uint.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
detect-engine.h
FAIL_IF_NULL
#define FAIL_IF_NULL(expr)
Fail a test if expression evaluates to NULL.
Definition: util-unittest.h:89
SIG_MASK_REQUIRE_REAL_PKT
#define SIG_MASK_REQUIRE_REAL_PKT
Definition: detect.h:320
PrefilterPacketU16Set
void PrefilterPacketU16Set(PrefilterPacketHeaderValue *v, void *smctx)
Definition: detect-engine-uint.c:124
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
ICMP_INFO_REQUEST
#define ICMP_INFO_REQUEST
Definition: decode-icmpv4.h:66
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
PKT_IS_PSEUDOPKT
#define PKT_IS_PSEUDOPKT(p)
return 1 if the packet is a pseudo packet
Definition: decode.h:1364
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
seq
uint32_t seq
Definition: stream-tcp-private.h:2
ICMPV6_GET_SEQ
#define ICMPV6_GET_SEQ(p)
Definition: decode-icmpv6.h:109
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
p
Packet * p
Definition: fuzz_dataset.c:30
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
util-unittest-helper.h
FAIL_IF_NOT
#define FAIL_IF_NOT(expr)
Fail a test if expression evaluates to false.
Definition: util-unittest.h:82
ICMP6_ECHO_REQUEST
#define ICMP6_ECHO_REQUEST
Definition: decode-icmpv6.h:42
ICMP_ECHO
#define ICMP_ECHO
Definition: decode-icmpv4.h:45
Packet_::icmp_s
struct Packet_::@32::@39 icmp_s
ICMPV4_GET_SEQ
#define ICMPV4_GET_SEQ(p)
Definition: decode-icmpv4.h:238
SigTableElmt_::SetupPrefilter
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
Definition: detect.h:1527
ICMP_ADDRESSREPLY
#define ICMP_ADDRESSREPLY
Definition: decode-icmpv4.h:75
ICMP_ADDRESS
#define ICMP_ADDRESS
Definition: decode-icmpv4.h:72
PrefilterPacketHeaderCtx_
Definition: detect-engine-prefilter-common.h:35
decode.h
FAIL_IF_NOT_NULL
#define FAIL_IF_NOT_NULL(expr)
Fail a test if expression evaluates to non-NULL.
Definition: util-unittest.h:96
util-debug.h
SIGMATCH_INFO_UINT16
#define SIGMATCH_INFO_UINT16
Definition: detect-engine-register.h:344
PASS
#define PASS
Pass the test.
Definition: util-unittest.h:105
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
ICMP6_ECHO_REPLY
#define ICMP6_ECHO_REPLY
Definition: decode-icmpv6.h:43
DetectEngineThreadCtx_
Definition: detect.h:1316
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
DetectIcmpSeqRegister
void DetectIcmpSeqRegister(void)
Registration function for icmp_seq.
Definition: detect-icmp-seq.c:54
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
detect-engine-build.h
ICMP_INFO_REPLY
#define ICMP_INFO_REPLY
Definition: decode-icmpv4.h:69
detect-engine-alert.h
PrefilterSetupPacketHeader
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
Definition: detect-engine-prefilter-common.c:470
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
ICMP_ECHOREPLY
#define ICMP_ECHOREPLY
Definition: decode-icmpv4.h:33
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
DetectU16Match
int DetectU16Match(const uint16_t parg, const DetectUintData_u16 *du16)
Definition: detect-engine-uint.c:105
PrefilterPacketU16Compare
bool PrefilterPacketU16Compare(PrefilterPacketHeaderValue v, void *smctx)
Definition: detect-engine-uint.c:132
SCNtohs
#define SCNtohs(x)
Definition: suricata-common.h:436
suricata-common.h
DETECT_ICMP_SEQ
@ DETECT_ICMP_SEQ
Definition: detect-engine-register.h:50
SigTableElmt_::SupportsPrefilter
bool(* SupportsPrefilter)(const Signature *s)
Definition: detect.h:1526
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
ICMP_TIMESTAMPREPLY
#define ICMP_TIMESTAMPREPLY
Definition: decode-icmpv4.h:63
ICMPV6_GET_TYPE
#define ICMPV6_GET_TYPE(icmp6h)
Definition: decode-icmpv6.h:101
ICMP_TIMESTAMP
#define ICMP_TIMESTAMP
Definition: decode-icmpv4.h:60
detect-engine-prefilter-common.h
DetectU16Data
DetectUintData_u16 DetectU16Data
Definition: detect-engine-uint.h:42
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
DetectIcmpSeqFree
void DetectIcmpSeqFree(DetectEngineCtx *, void *)
this function will free memory associated with DetectU16Data
Definition: detect-icmp-seq.c:176
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
detect-icmp-seq.h
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257