detect-tcp-flags.c File Reference
#include "suricata-common.h"
#include "suricata.h"
#include "decode.h"
#include "detect.h"
#include "detect-parse.h"
#include "detect-engine-prefilter.h"
#include "detect-engine-prefilter-common.h"
#include "flow-var.h"
#include "decode-events.h"
#include "detect-tcp-flags.h"
#include "util-unittest.h"
#include "util-debug.h"
Include dependency graph for detect-tcp-flags.c:

Go to the source code of this file.


#define PARSE_REGEX   "^\\s*(?:([\\+\\*!]))?\\s*([SAPRFU120CE\\+\\*!]+)(?:\\s*,\\s*([SAPRFU12CE]+))?\\s*$"
#define MODIFIER_NOT   1
#define MODIFIER_PLUS   2
#define MODIFIER_ANY   3


void DetectFlagsRegister (void)
 Registration function for flags: keyword. More...
int DetectFlagsSignatureNeedsSynPackets (const Signature *s)
int DetectFlagsSignatureNeedsSynOnlyPackets (const Signature *s)
void FlagsRegisterTests (void)
 this function registers unit tests for Flags More...

Detailed Description

Breno Silva

Implements the flags keyword

Definition in file detect-tcp-flags.c.

Macro Definition Documentation


#define MODIFIER_ANY   3

Definition at line 57 of file detect-tcp-flags.c.


#define MODIFIER_NOT   1

Flags args[0] *(3) +(2) !(1)

Definition at line 55 of file detect-tcp-flags.c.


#define MODIFIER_PLUS   2

Definition at line 56 of file detect-tcp-flags.c.


#define PARSE_REGEX   "^\\s*(?:([\\+\\*!]))?\\s*([SAPRFU120CE\\+\\*!]+)(?:\\s*,\\s*([SAPRFU12CE]+))?\\s*$"

Regex (by Brian Rectanus) flags: [!+*](SAPRFU120)[,SAPRFU12]

Definition at line 48 of file detect-tcp-flags.c.

Function Documentation

◆ DetectFlagsRegister()

void DetectFlagsRegister ( void  )

Registration function for flags: keyword.

Registration function for flags: keyword

Definition at line 72 of file detect-tcp-flags.c.

References SigTableElmt_::alias, SigTableElmt_::desc, DETECT_FLAGS, SigTableElmt_::Match, SigTableElmt_::name, sigmatch_table, and SigTableElmt_::url.

Referenced by SigTableSetup().

Here is the caller graph for this function:

◆ DetectFlagsSignatureNeedsSynOnlyPackets()

◆ DetectFlagsSignatureNeedsSynPackets()

int DetectFlagsSignatureNeedsSynPackets ( const Signature s)

◆ FlagsRegisterTests()

void FlagsRegisterTests ( void  )

this function registers unit tests for Flags

This function registers unit tests for Flags

Definition at line 1403 of file detect-tcp-flags.c.

References UtRegisterTest().

Here is the call graph for this function: