suricata
detect-modbus.h
Go to the documentation of this file.
1 /*
2  * Copyright (C) 2014 ANSSI
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  * notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  * notice, this list of conditions and the following disclaimer in the
12  * documentation and/or other materials provided with the distribution.
13  * 3. The name of the author may not be used to endorse or promote products
14  * derived from this software without specific prior written permission.
15  *
16  * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
17  * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
18  * AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
19  * THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
20  * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
21  * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
22  * OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
23  * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
24  * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
25  * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26  */
27 
28 /**
29  * \file
30  *
31  * \author David DIALLO <diallo@et.esiea.fr>
32  */
33 
34 #ifndef __DETECT_MODBUS_H__
35 #define __DETECT_MODBUS_H__
36 
37 #include "app-layer-modbus.h"
38 
39 typedef enum {
40  DETECT_MODBUS_EQ = 0, /** < EQual operator */
41  DETECT_MODBUS_LT, /** < "Less Than" operator */
42  DETECT_MODBUS_GT, /** < "Greater Than" operator */
43  DETECT_MODBUS_RA, /** < RAnge operator */
45 
46 typedef struct DetectModbusValue_ {
47  uint16_t min; /** < Modbus minimum [range] or equal value to match */
48  uint16_t max; /** < Modbus maximum value [range] to match */
49  DetectModbusMode mode; /** < Modbus operator used in the address/data signature */
51 
52 typedef struct DetectModbus_ {
53  uint8_t category; /** < Modbus function code category to match */
54  uint8_t function; /** < Modbus function code to match */
55  uint16_t *subfunction; /** < Modbus subfunction to match */
56  uint8_t type; /** < Modbus access type to match */
57  DetectModbusValue *unit_id; /** < Modbus unit id to match */
58  DetectModbusValue *address; /** < Modbus address to match */
59  DetectModbusValue *data; /** < Modbus data to match */
60 } DetectModbus;
61 
62 /* prototypes */
63 void DetectModbusRegister(void);
64 
65 #endif /* __DETECT_MODBUS_H__ */
void DetectModbusRegister(void)
Registration function for Modbus keyword.
struct DetectModbusValue_ DetectModbusValue
struct DetectModbus_ DetectModbus
DetectModbusMode mode
Definition: detect-modbus.h:49
DetectModbusValue * data
Definition: detect-modbus.h:59
uint16_t * subfunction
Definition: detect-modbus.h:55
DetectModbusValue * unit_id
Definition: detect-modbus.h:57
DetectModbusMode
Definition: detect-modbus.h:39
uint8_t category
Definition: detect-modbus.h:53
DetectModbusValue * address
Definition: detect-modbus.h:58