suricata
detect-ssl-state.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2025 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
22  *
23  * Implements support for ssl_state keyword.
24  */
25 
26 #include "suricata-common.h"
27 #include "threads.h"
28 #include "decode.h"
29 
30 #include "detect.h"
31 #include "detect-parse.h"
32 
33 #include "detect-engine.h"
34 #include "detect-engine-mpm.h"
35 #include "detect-engine-state.h"
36 
37 #include "flow.h"
38 #include "flow-var.h"
39 #include "flow-util.h"
40 
41 #include "util-debug.h"
42 #include "util-unittest-helper.h"
43 
44 #include "app-layer.h"
45 #include "app-layer-parser.h"
46 
47 #include "detect-ssl-state.h"
48 
49 #include "stream-tcp.h"
50 #include "app-layer-ssl.h"
51 
52 #define PARSE_REGEX1 "^(!?)([_a-zA-Z0-9]+)(.*)$"
53 static DetectParseRegex parse_regex1;
54 
55 #define PARSE_REGEX2 "^(?:\\s*[|,]\\s*(!?)([_a-zA-Z0-9]+))(.*)$"
56 static DetectParseRegex parse_regex2;
57 
58 static int DetectSslStateMatch(DetectEngineThreadCtx *,
59  Flow *, uint8_t, void *, void *,
60  const Signature *, const SigMatchCtx *);
61 static int DetectSslStateSetup(DetectEngineCtx *, Signature *, const char *);
62 #ifdef UNITTESTS
63 static void DetectSslStateRegisterTests(void);
64 #endif
65 static void DetectSslStateFree(DetectEngineCtx *, void *);
66 
67 static int g_tls_generic_list_id = 0;
68 
69 /**
70  * \brief Registers the keyword handlers for the "ssl_state" keyword.
71  */
73 {
74  sigmatch_table[DETECT_SSL_STATE].name = "ssl_state";
75  sigmatch_table[DETECT_SSL_STATE].desc = "match the state of the SSL connection";
76  sigmatch_table[DETECT_SSL_STATE].url = "/rules/tls-keywords.html#ssl-state";
77  sigmatch_table[DETECT_SSL_STATE].AppLayerTxMatch = DetectSslStateMatch;
78  /* the value follows the handshake state */
80  sigmatch_table[DETECT_SSL_STATE].Setup = DetectSslStateSetup;
81  sigmatch_table[DETECT_SSL_STATE].Free = DetectSslStateFree;
82 #ifdef UNITTESTS
83  sigmatch_table[DETECT_SSL_STATE].RegisterTests = DetectSslStateRegisterTests;
84 #endif
85  DetectSetupParseRegexes(PARSE_REGEX1, &parse_regex1);
86  DetectSetupParseRegexes(PARSE_REGEX2, &parse_regex2);
87 
88  g_tls_generic_list_id = DetectBufferTypeRegister("tls_generic");
89 
91  "generic ssl/tls inspection");
92 
93  /* ssl_state reads live handshake state, so its engine must be revisited
94  * as the transaction advances (a miss at the started state must not be
95  * final): run it on every update. */
96  DetectBufferTypeSetRunAlways("tls_generic");
97 
102 }
103 
104 /**
105  * \brief App layer match function ssl_state keyword.
106  *
107  * \param tv Pointer to threadvars.
108  * \param det_ctx Pointer to the thread's detection context.
109  * \param f Pointer to the flow.
110  * \param flags Flags.
111  * \param state App layer state.
112  * \param s Sig we are currently inspecting.
113  * \param m SigMatch we are currently inspecting.
114  *
115  * \retval 1 Match.
116  * \retval 0 No match.
117  */
118 static int DetectSslStateMatch(DetectEngineThreadCtx *det_ctx,
119  Flow *f, uint8_t flags, void *alstate, void *txv,
120  const Signature *s, const SigMatchCtx *m)
121 {
122  const DetectSslStateData *ssd = (const DetectSslStateData *)m;
123  const SSLState *ssl_state = (SSLState *)alstate;
124  if (ssl_state == NULL) {
125  SCLogDebug("no app state, no match");
126  return 0;
127  }
128 
129  const uint32_t ssl_flags = ssl_state->current_flags;
130 
131  if ((ssd->flags & ssl_flags) ^ ssd->mask) {
132  return 1;
133  }
134 
135  return 0;
136 }
137 
138 /**
139  * \brief Parse the arg supplied with ssl_state and return it in a
140  * DetectSslStateData instance.
141  *
142  * \param arg Pointer to the string to be parsed.
143  *
144  * \retval ssd Pointer to DetectSslStateData on success.
145  * \retval NULL On failure.
146  */
147 static DetectSslStateData *DetectSslStateParse(const char *arg)
148 {
149  size_t pcre2len;
150  char str1[64];
151  char str2[64];
152  int negate = 0;
153  uint32_t flags = 0, mask = 0;
154 
155  pcre2_match_data *match = NULL;
156  int ret = DetectParsePcreExec(&parse_regex1, &match, arg, 0, 0);
157  if (ret < 1) {
158  SCLogError("Invalid arg \"%s\" supplied to "
159  "ssl_state keyword.",
160  arg);
161  goto error;
162  }
163 
164  pcre2len = sizeof(str1);
165  int res = pcre2_substring_copy_bynumber(match, 1, (PCRE2_UCHAR8 *)str1, &pcre2len);
166  if (res < 0) {
167  SCLogError("pcre2_substring_copy_bynumber failed");
168  goto error;
169  }
170  negate = !strcmp("!", str1);
171 
172  pcre2len = sizeof(str1);
173  res = pcre2_substring_copy_bynumber(match, 2, (PCRE2_UCHAR8 *)str1, &pcre2len);
174  if (res < 0) {
175  SCLogError("pcre2_substring_copy_bynumber failed");
176  goto error;
177  }
178 
179  if (strcmp("client_hello", str1) == 0) {
181  if (negate)
183  } else if (strcmp("server_hello", str1) == 0) {
185  if (negate)
187  } else if (strcmp("client_keyx", str1) == 0) {
189  if (negate)
191  } else if (strcmp("server_keyx", str1) == 0) {
193  if (negate)
195  } else if (strcmp("unknown", str1) == 0) {
197  if (negate)
198  mask |= DETECT_SSL_STATE_UNKNOWN;
199  } else {
200  SCLogError("Found invalid option \"%s\" "
201  "in ssl_state keyword.",
202  str1);
203  goto error;
204  }
205 
206  pcre2len = sizeof(str1);
207  res = pcre2_substring_copy_bynumber(match, 3, (PCRE2_UCHAR8 *)str1, &pcre2len);
208  if (res < 0) {
209  SCLogError("pcre2_substring_copy_bynumber failed");
210  goto error;
211  }
212  while (res >= 0 && strlen(str1) > 0) {
213  pcre2_match_data *match2 = NULL;
214  ret = DetectParsePcreExec(&parse_regex2, &match2, str1, 0, 0);
215  if (ret < 1) {
216  SCLogError("Invalid arg \"%s\" supplied to "
217  "ssl_state keyword.",
218  arg);
219  if (match2) {
220  pcre2_match_data_free(match2);
221  }
222  goto error;
223  }
224 
225  pcre2len = sizeof(str2);
226  res = pcre2_substring_copy_bynumber(match2, 1, (PCRE2_UCHAR8 *)str2, &pcre2len);
227  if (res < 0) {
228  SCLogError("pcre2_substring_copy_bynumber failed");
229  pcre2_match_data_free(match2);
230  goto error;
231  }
232  negate = !strcmp("!", str2);
233 
234  pcre2len = sizeof(str2);
235  res = pcre2_substring_copy_bynumber(match2, 2, (PCRE2_UCHAR8 *)str2, &pcre2len);
236  if (res < 0) {
237  SCLogError("pcre2_substring_copy_bynumber failed");
238  pcre2_match_data_free(match2);
239  goto error;
240  }
241  if (strcmp("client_hello", str2) == 0) {
243  if (negate)
245  } else if (strcmp("server_hello", str2) == 0) {
247  if (negate)
249  } else if (strcmp("client_keyx", str2) == 0) {
251  if (negate)
253  } else if (strcmp("server_keyx", str2) == 0) {
255  if (negate)
257  } else if (strcmp("unknown", str2) == 0) {
259  if (negate)
260  mask |= DETECT_SSL_STATE_UNKNOWN;
261  } else {
262  SCLogError("Found invalid option \"%s\" "
263  "in ssl_state keyword.",
264  str2);
265  pcre2_match_data_free(match2);
266  goto error;
267  }
268 
269  pcre2len = sizeof(str2);
270  res = pcre2_substring_copy_bynumber(match2, 3, (PCRE2_UCHAR8 *)str2, &pcre2len);
271  if (res < 0) {
272  SCLogError("pcre2_substring_copy_bynumber failed");
273  pcre2_match_data_free(match2);
274  goto error;
275  }
276 
277  strlcpy(str1, str2, sizeof(str1));
278  pcre2_match_data_free(match2);
279  }
280 
282  if (ssd == NULL) {
283  goto error;
284  }
285  ssd->flags = flags;
286  ssd->mask = mask;
287 
288  pcre2_match_data_free(match);
289  return ssd;
290 
291 error:
292  if (match) {
293  pcre2_match_data_free(match);
294  }
295  return NULL;
296 }
297 
298  /**
299  * \internal
300  * \brief Setup function for ssl_state keyword.
301  *
302  * \param de_ctx Pointer to the Detection Engine Context.
303  * \param s Pointer to the Current Signature
304  * \param arg String holding the arg.
305  *
306  * \retval 0 On success.
307  * \retval -1 On failure.
308  */
309 static int DetectSslStateSetup(DetectEngineCtx *de_ctx, Signature *s, const char *arg)
310 {
312  return -1;
313 
314  DetectSslStateData *ssd = DetectSslStateParse(arg);
315  if (ssd == NULL)
316  return -1;
317 
319  de_ctx, s, DETECT_SSL_STATE, (SigMatchCtx *)ssd, g_tls_generic_list_id) == NULL) {
320  DetectSslStateFree(de_ctx, ssd);
321  return -1;
322  }
323  return 0;
324 }
325 
326 /**
327  * \brief Free memory associated with DetectSslStateData.
328  *
329  * \param ptr pointer to the data to be freed.
330  */
331 static void DetectSslStateFree(DetectEngineCtx *de_ctx, void *ptr)
332 {
333  if (ptr != NULL)
334  SCFree(ptr);
335 }
336 
337 #ifdef UNITTESTS
338 #include "tests/detect-ssl-state.c"
339 #endif
DETECT_SSL_STATE
@ DETECT_SSL_STATE
Definition: detect-engine-register.h:203
SigTableElmt_::url
const char * url
Definition: detect.h:1545
SSLState_
SSLv[2.0|3.[0|1|2|3]] state structure.
Definition: app-layer-ssl.h:263
detect-engine.h
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
flow-util.h
DetectParseRegex
Definition: detect-parse.h:94
SigTableElmt_::name
const char * name
Definition: detect.h:1542
stream-tcp.h
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
ALPROTO_TLS
@ ALPROTO_TLS
Definition: app-layer-protos.h:39
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
threads.h
Flow_
Flow data structure.
Definition: flow.h:359
DETECT_SSL_STATE_CLIENT_HELLO
#define DETECT_SSL_STATE_CLIENT_HELLO
Definition: detect-ssl-state.h:28
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DETECT_SSL_STATE_UNKNOWN
#define DETECT_SSL_STATE_UNKNOWN
Definition: detect-ssl-state.h:32
SigTableElmt_::AppLayerTxMatch
int(* AppLayerTxMatch)(DetectEngineThreadCtx *, Flow *, uint8_t flags, void *alstate, void *txv, const Signature *, const SigMatchCtx *)
Definition: detect.h:1507
DetectParsePcreExec
int DetectParsePcreExec(DetectParseRegex *parse_regex, pcre2_match_data **match, const char *str, int start_offset, int options)
Definition: detect-parse.c:4019
m
SCMutex m
Definition: flow-hash.h:6
DetectSslStateData_::mask
uint32_t mask
Definition: detect-ssl-state.h:36
SCDetectSignatureSetAppProto
int SCDetectSignatureSetAppProto(Signature *s, AppProto alproto)
Definition: detect-parse.c:2613
SIG_FLAG_TOCLIENT
#define SIG_FLAG_TOCLIENT
Definition: detect.h:275
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
DetectAppLayerInspectEngineRegister
void DetectAppLayerInspectEngineRegister(const char *name, AppProto alproto, uint32_t dir, uint8_t progress, InspectEngineFuncPtr Callback, InspectionBufferGetDataPtr GetData)
Registers an app inspection engine.
Definition: detect-engine.c:275
util-unittest-helper.h
strlcpy
size_t strlcpy(char *dst, const char *src, size_t siz)
Definition: util-strlcpyu.c:43
DetectBufferTypeSetRunAlways
void DetectBufferTypeSetRunAlways(const char *name)
Definition: detect-engine.c:1560
SSLState_::current_flags
uint32_t current_flags
Definition: app-layer-ssl.h:277
SIG_FLAG_TOSERVER
#define SIG_FLAG_TOSERVER
Definition: detect.h:274
decode.h
util-debug.h
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
detect-ssl-state.c
DetectSetupParseRegexes
void DetectSetupParseRegexes(const char *parse_str, DetectParseRegex *detect_parse)
Definition: detect-parse.c:4145
detect-engine-mpm.h
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
DetectSslStateRegister
void DetectSslStateRegister(void)
Registers the keyword handlers for the "ssl_state" keyword.
Definition: detect-ssl-state.c:72
app-layer-parser.h
detect-engine-state.h
Data structures and function prototypes for keeping state for the detection engine.
DetectSslStateData_::flags
uint32_t flags
Definition: detect-ssl-state.h:35
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
DetectBufferTypeRegister
int DetectBufferTypeRegister(const char *name)
Definition: detect-engine.c:1388
flags
uint8_t flags
Definition: decode-gre.h:0
suricata-common.h
DetectEngineInspectGenericList
uint8_t DetectEngineInspectGenericList(DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx, const struct DetectEngineAppInspectionEngine_ *engine, const Signature *s, Flow *f, uint8_t flags, void *alstate, void *txv, uint64_t tx_id)
Definition: detect-engine.c:2155
DETECT_SSL_STATE_SERVER_KEYX
#define DETECT_SSL_STATE_SERVER_KEYX
Definition: detect-ssl-state.h:31
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
PARSE_REGEX2
#define PARSE_REGEX2
Definition: detect-ssl-state.c:55
PARSE_REGEX1
#define PARSE_REGEX1
Definition: detect-ssl-state.c:52
detect-ssl-state.h
DetectBufferTypeSetDescriptionByName
void DetectBufferTypeSetDescriptionByName(const char *name, const char *desc)
Definition: detect-engine.c:1549
DetectSslStateData_
Definition: detect-ssl-state.h:34
flow.h
SIGMATCH_STATEFUL
#define SIGMATCH_STATEFUL
Definition: detect-engine-register.h:356
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
flow-var.h
app-layer-ssl.h
DETECT_SSL_STATE_CLIENT_KEYX
#define DETECT_SSL_STATE_CLIENT_KEYX
Definition: detect-ssl-state.h:30
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
app-layer.h
f
Flow f
Definition: fuzz_dataset.c:32
DETECT_SSL_STATE_SERVER_HELLO
#define DETECT_SSL_STATE_SERVER_HELLO
Definition: detect-ssl-state.h:29