Go to the documentation of this file.
52 #define PARSE_REGEX1 "^(!?)([_a-zA-Z0-9]+)(.*)$"
55 #define PARSE_REGEX2 "^(?:\\s*[|,]\\s*(!?)([_a-zA-Z0-9]+))(.*)$"
59 Flow *, uint8_t,
void *,
void *,
63 static void DetectSslStateRegisterTests(
void);
67 static int g_tls_generic_list_id = 0;
91 "generic ssl/tls inspection");
119 Flow *
f, uint8_t
flags,
void *alstate,
void *txv,
124 if (ssl_state == NULL) {
131 if ((ssd->
flags & ssl_flags) ^ ssd->
mask) {
153 uint32_t
flags = 0, mask = 0;
155 pcre2_match_data *match = NULL;
159 "ssl_state keyword.",
164 pcre2len =
sizeof(str1);
165 int res = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)str1, &pcre2len);
167 SCLogError(
"pcre2_substring_copy_bynumber failed");
170 negate = !strcmp(
"!", str1);
172 pcre2len =
sizeof(str1);
173 res = pcre2_substring_copy_bynumber(match, 2, (PCRE2_UCHAR8 *)str1, &pcre2len);
175 SCLogError(
"pcre2_substring_copy_bynumber failed");
179 if (strcmp(
"client_hello", str1) == 0) {
183 }
else if (strcmp(
"server_hello", str1) == 0) {
187 }
else if (strcmp(
"client_keyx", str1) == 0) {
191 }
else if (strcmp(
"server_keyx", str1) == 0) {
195 }
else if (strcmp(
"unknown", str1) == 0) {
201 "in ssl_state keyword.",
206 pcre2len =
sizeof(str1);
207 res = pcre2_substring_copy_bynumber(match, 3, (PCRE2_UCHAR8 *)str1, &pcre2len);
209 SCLogError(
"pcre2_substring_copy_bynumber failed");
212 while (res >= 0 && strlen(str1) > 0) {
213 pcre2_match_data *match2 = NULL;
217 "ssl_state keyword.",
220 pcre2_match_data_free(match2);
225 pcre2len =
sizeof(str2);
226 res = pcre2_substring_copy_bynumber(match2, 1, (PCRE2_UCHAR8 *)str2, &pcre2len);
228 SCLogError(
"pcre2_substring_copy_bynumber failed");
229 pcre2_match_data_free(match2);
232 negate = !strcmp(
"!", str2);
234 pcre2len =
sizeof(str2);
235 res = pcre2_substring_copy_bynumber(match2, 2, (PCRE2_UCHAR8 *)str2, &pcre2len);
237 SCLogError(
"pcre2_substring_copy_bynumber failed");
238 pcre2_match_data_free(match2);
241 if (strcmp(
"client_hello", str2) == 0) {
245 }
else if (strcmp(
"server_hello", str2) == 0) {
249 }
else if (strcmp(
"client_keyx", str2) == 0) {
253 }
else if (strcmp(
"server_keyx", str2) == 0) {
257 }
else if (strcmp(
"unknown", str2) == 0) {
263 "in ssl_state keyword.",
265 pcre2_match_data_free(match2);
269 pcre2len =
sizeof(str2);
270 res = pcre2_substring_copy_bynumber(match2, 3, (PCRE2_UCHAR8 *)str2, &pcre2len);
272 SCLogError(
"pcre2_substring_copy_bynumber failed");
273 pcre2_match_data_free(match2);
277 strlcpy(str1, str2,
sizeof(str1));
278 pcre2_match_data_free(match2);
288 pcre2_match_data_free(match);
293 pcre2_match_data_free(match);
320 DetectSslStateFree(
de_ctx, ssd);
SSLv[2.0|3.[0|1|2|3]] state structure.
SigTableElmt * sigmatch_table
void(* Free)(DetectEngineCtx *, void *)
#define DETECT_SSL_STATE_CLIENT_HELLO
main detection engine ctx
#define DETECT_SSL_STATE_UNKNOWN
int(* AppLayerTxMatch)(DetectEngineThreadCtx *, Flow *, uint8_t flags, void *alstate, void *txv, const Signature *, const SigMatchCtx *)
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
#define SIG_FLAG_TOCLIENT
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
size_t strlcpy(char *dst, const char *src, size_t siz)
void DetectBufferTypeSetRunAlways(const char *name)
#define SIG_FLAG_TOSERVER
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
void DetectSslStateRegister(void)
Registers the keyword handlers for the "ssl_state" keyword.
Data structures and function prototypes for keeping state for the detection engine.
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
int DetectBufferTypeRegister(const char *name)
uint8_t DetectEngineInspectGenericList(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
#define DETECT_SSL_STATE_SERVER_KEYX
#define SCLogError(...)
Macro used to log ERROR messages.
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
#define SIGMATCH_STATEFUL
#define DETECT_SSL_STATE_CLIENT_KEYX
void(* RegisterTests)(void)
#define DETECT_SSL_STATE_SERVER_HELLO