suricata
detect-modbus.h
Go to the documentation of this file.
1 /*
2  * Copyright (C) 2014 ANSSI
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  * notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  * notice, this list of conditions and the following disclaimer in the
12  * documentation and/or other materials provided with the distribution.
13  * 3. The name of the author may not be used to endorse or promote products
14  * derived from this software without specific prior written permission.
15  *
16  * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
17  * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
18  * AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
19  * THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
20  * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
21  * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
22  * OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
23  * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
24  * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
25  * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
26  */
27 
28 /**
29  * \file
30  *
31  * \author David DIALLO <diallo@et.esiea.fr>
32  */
33 
34 #ifndef __DETECT_MODBUS_H__
35 #define __DETECT_MODBUS_H__
36 
37 #include "app-layer-modbus.h"
38 
39 typedef enum {
40  DETECT_MODBUS_EQ = 0, /** < EQual operator */
41  DETECT_MODBUS_LT, /** < "Less Than" operator */
42  DETECT_MODBUS_GT, /** < "Greater Than" operator */
43  DETECT_MODBUS_RA, /** < RAnge operator */
45 
46 typedef struct DetectModbusValue_ {
47  uint16_t min; /** < Modbus minimum [range] or equal value to match */
48  uint16_t max; /** < Modbus maximum value [range] to match */
49  DetectModbusMode mode; /** < Modbus operator used in the address/data signature */
51 
52 typedef struct DetectModbus_ {
53  uint8_t category; /** < Modbus function code category to match */
54  uint8_t function; /** < Modbus function code to match */
55  uint16_t subfunction; /** < Modbus subfunction to match */
56  bool has_subfunction; /** < Modbus subfunction indicator */
57  uint8_t type; /** < Modbus access type to match */
58  DetectModbusValue *unit_id; /** < Modbus unit id to match */
59  DetectModbusValue *address; /** < Modbus address to match */
60  DetectModbusValue *data; /** < Modbus data to match */
62 
63 /* prototypes */
64 void DetectModbusRegister(void);
65 
66 #endif /* __DETECT_MODBUS_H__ */
DetectModbus_::subfunction
uint16_t subfunction
Definition: detect-modbus.h:55
DetectModbus_::address
DetectModbusValue * address
Definition: detect-modbus.h:59
DetectModbusRegister
void DetectModbusRegister(void)
Registration function for Modbus keyword.
Definition: detect-modbus.c:550
DetectModbus_
Definition: detect-modbus.h:52
DetectModbusValue_::mode
DetectModbusMode mode
Definition: detect-modbus.h:49
DetectModbus_::has_subfunction
bool has_subfunction
Definition: detect-modbus.h:56
DETECT_MODBUS_EQ
@ DETECT_MODBUS_EQ
Definition: detect-modbus.h:40
DetectModbusValue_::max
uint16_t max
Definition: detect-modbus.h:48
DetectModbus_::category
uint8_t category
Definition: detect-modbus.h:53
DetectModbus
struct DetectModbus_ DetectModbus
DetectModbusValue_
Definition: detect-modbus.h:46
DetectModbusValue
struct DetectModbusValue_ DetectModbusValue
DetectModbus_::type
uint8_t type
Definition: detect-modbus.h:57
DETECT_MODBUS_LT
@ DETECT_MODBUS_LT
Definition: detect-modbus.h:41
app-layer-modbus.h
DetectModbusMode
DetectModbusMode
Definition: detect-modbus.h:39
DetectModbusValue_::min
uint16_t min
Definition: detect-modbus.h:47
DetectModbus_::data
DetectModbusValue * data
Definition: detect-modbus.h:60
DETECT_MODBUS_GT
@ DETECT_MODBUS_GT
Definition: detect-modbus.h:42
DETECT_MODBUS_RA
@ DETECT_MODBUS_RA
Definition: detect-modbus.h:43
DetectModbus_::unit_id
DetectModbusValue * unit_id
Definition: detect-modbus.h:58