suricata
detect-tcp-seq.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2010 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Brian Rectanus <brectanu@gmail.com>
22  *
23  * Implements the seq keyword.
24  */
25 
26 #include "suricata-common.h"
27 #include "decode.h"
28 #include "detect.h"
29 
30 #include "detect-parse.h"
31 #include "detect-engine.h"
34 #include "detect-engine-build.h"
35 #include "detect-engine-uint.h"
36 
37 #include "detect-tcp-seq.h"
38 
39 #include "util-byte.h"
40 #include "util-unittest-helper.h"
41 #include "util-debug.h"
42 
43 static int DetectSeqSetup(DetectEngineCtx *, Signature *, const char *);
44 static int DetectSeqMatch(DetectEngineThreadCtx *,
45  Packet *, const Signature *, const SigMatchCtx *);
46 #ifdef UNITTESTS
47 static void DetectSeqRegisterTests(void);
48 #endif
49 static void DetectSeqFree(DetectEngineCtx *, void *);
50 static int PrefilterSetupTcpSeq(DetectEngineCtx *de_ctx, SigGroupHead *sgh);
51 static bool PrefilterTcpSeqIsPrefilterable(const Signature *s);
52 
54 {
55  sigmatch_table[DETECT_SEQ].name = "tcp.seq";
57  sigmatch_table[DETECT_SEQ].desc = "check for a specific TCP sequence number";
58  sigmatch_table[DETECT_SEQ].url = "/rules/header-keywords.html#seq";
59  sigmatch_table[DETECT_SEQ].Match = DetectSeqMatch;
60  sigmatch_table[DETECT_SEQ].Setup = DetectSeqSetup;
61  sigmatch_table[DETECT_SEQ].Free = DetectSeqFree;
63 #ifdef UNITTESTS
64  sigmatch_table[DETECT_SEQ].RegisterTests = DetectSeqRegisterTests;
65 #endif
66  sigmatch_table[DETECT_SEQ].SupportsPrefilter = PrefilterTcpSeqIsPrefilterable;
67  sigmatch_table[DETECT_SEQ].SetupPrefilter = PrefilterSetupTcpSeq;
68 }
69 
70 /**
71  * \internal
72  * \brief This function is used to match packets with a given Seq number
73  *
74  * \param t pointer to thread vars
75  * \param det_ctx pointer to the pattern matcher thread
76  * \param p pointer to the current packet
77  * \param m pointer to the sigmatch that we will cast into DetectSeqData
78  *
79  * \retval 0 no match
80  * \retval 1 match
81  */
82 static int DetectSeqMatch(DetectEngineThreadCtx *det_ctx,
83  Packet *p, const Signature *s, const SigMatchCtx *ctx)
84 {
85  const DetectU32Data *data = (const DetectU32Data *)ctx;
86 
88  /* This is only needed on TCP packets */
89  if (!(PacketIsTCP(p))) {
90  return 0;
91  }
92 
93  return DetectU32Match(TCP_GET_RAW_SEQ(PacketGetTCP(p)), data);
94 }
95 
96 /**
97  * \internal
98  * \brief this function is used to add the seq option into the signature
99  *
100  * \param de_ctx pointer to the Detection Engine Context
101  * \param s pointer to the Current Signature
102  * \param optstr pointer to the user provided options
103  *
104  * \retval 0 on Success
105  * \retval -1 on Failure
106  */
107 static int DetectSeqSetup (DetectEngineCtx *de_ctx, Signature *s, const char *optstr)
108 {
109  DetectU32Data *data = SCDetectU32Parse(optstr);
110  if (data == NULL)
111  return -1;
112 
114  de_ctx, s, DETECT_SEQ, (SigMatchCtx *)data, DETECT_SM_LIST_MATCH) == NULL) {
115  DetectSeqFree(de_ctx, data);
116  return -1;
117  }
119  return 0;
120 }
121 
122 /**
123  * \internal
124  * \brief this function will free memory associated with seq option
125  *
126  * \param data pointer to seq configuration data
127  */
128 static void DetectSeqFree(DetectEngineCtx *de_ctx, void *ptr)
129 {
130  SCDetectU32Free(ptr);
131 }
132 
133 /* prefilter code */
134 
135 static void
136 PrefilterPacketSeqMatch(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx)
137 {
138  const PrefilterPacketHeaderCtx *ctx = pectx;
139 
141  if (!PrefilterPacketHeaderExtraMatch(ctx, p))
142  return;
143 
144  if (p->proto == IPPROTO_TCP && PacketIsTCP(p)) {
145  DetectU32Data du32;
146  du32.mode = ctx->v1.u8[0];
147  du32.arg1 = ctx->v1.u32[1];
148  du32.arg2 = ctx->v1.u32[2];
149  if (DetectU32Match(TCP_GET_RAW_SEQ(PacketGetTCP(p)), &du32)) {
150  SCLogDebug("packet matches TCP seq %u", ctx->v1.u32[0]);
151  PrefilterAddSids(&det_ctx->pmq, ctx->sigs_array, ctx->sigs_cnt);
152  }
153  }
154 }
155 
156 static int PrefilterSetupTcpSeq(DetectEngineCtx *de_ctx, SigGroupHead *sgh)
157 {
159  PrefilterPacketU32Set, PrefilterPacketU32Compare, PrefilterPacketSeqMatch);
160 }
161 
162 static bool PrefilterTcpSeqIsPrefilterable(const Signature *s)
163 {
164  return PrefilterIsPrefilterableById(s, DETECT_SEQ);
165 }
166 
167 
168 #ifdef UNITTESTS
169 
170 /**
171  * \test DetectSeqSigTest01 tests parses
172  */
173 static int DetectSeqSigTest01(void)
174 {
175  int result = 0;
177  if (de_ctx == NULL)
178  goto end;
179 
180  /* These three are crammed in here as there is no Parse */
181  if (SigInit(de_ctx,
182  "alert tcp any any -> any any "
183  "(msg:\"Testing seq\";seq:foo;sid:1;)") != NULL)
184  {
185  printf("invalid seq accepted: ");
186  goto cleanup;
187  }
188  if (SigInit(de_ctx,
189  "alert tcp any any -> any any "
190  "(msg:\"Testing seq\";seq:9999999999;sid:1;)") != NULL)
191  {
192  printf("overflowing seq accepted: ");
193  goto cleanup;
194  }
195  if (SigInit(de_ctx,
196  "alert tcp any any -> any any "
197  "(msg:\"Testing seq\";seq:-100;sid:1;)") != NULL)
198  {
199  printf("negative seq accepted: ");
200  goto cleanup;
201  }
202  result = 1;
203 
204 cleanup:
205  if (de_ctx) {
209  }
210 end:
211  return result;
212 }
213 
214 /**
215  * \test DetectSeqSigTest02 tests seq keyword
216  */
217 static int DetectSeqSigTest02(void)
218 {
219  int result = 0;
220  uint8_t *buf = (uint8_t *)"Hi all!";
221  uint16_t buflen = strlen((char *)buf);
222  Packet *p[3];
223  p[0] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
224  p[1] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_TCP);
225  p[2] = UTHBuildPacket((uint8_t *)buf, buflen, IPPROTO_ICMP);
226  if (p[0] == NULL || p[1] == NULL ||p[2] == NULL)
227  goto end;
228 
229  /* TCP w/seq=42 */
230  p[0]->l4.hdrs.tcph->th_seq = htonl(42);
231 
232  /* TCP w/seq=100 */
233  p[1]->l4.hdrs.tcph->th_seq = htonl(100);
234 
235  const char *sigs[2];
236  sigs[0]= "alert tcp any any -> any any (msg:\"Testing seq\"; seq:41; sid:1;)";
237  sigs[1]= "alert tcp any any -> any any (msg:\"Testing seq\"; seq:42; sid:2;)";
238 
239  uint32_t sid[2] = {1, 2};
240 
241  uint32_t results[3][2] = {
242  /* packet 0 match sid 1 but should not match sid 2 */
243  {0, 1},
244  /* packet 1 should not match */
245  {0, 0},
246  /* packet 2 should not match */
247  {0, 0} };
248 
249  result = UTHGenericTest(p, 3, sigs, sid, (uint32_t *) results, 2);
250  UTHFreePackets(p, 3);
251 end:
252  return result;
253 }
254 
255 /**
256  * \internal
257  * \brief This function registers unit tests for DetectSeq
258  */
259 static void DetectSeqRegisterTests(void)
260 {
261  UtRegisterTest("DetectSeqSigTest01", DetectSeqSigTest01);
262  UtRegisterTest("DetectSeqSigTest02", DetectSeqSigTest02);
263 }
264 #endif /* UNITTESTS */
TCP_GET_RAW_SEQ
#define TCP_GET_RAW_SEQ(tcph)
Definition: decode-tcp.h:80
util-byte.h
detect-engine-uint.h
SigTableElmt_::url
const char * url
Definition: detect.h:1545
Packet_::proto
uint8_t proto
Definition: decode.h:538
detect-engine.h
SIG_MASK_REQUIRE_REAL_PKT
#define SIG_MASK_REQUIRE_REAL_PKT
Definition: detect.h:320
DetectU32Match
int DetectU32Match(const uint32_t parg, const DetectUintData_u32 *du32)
Definition: detect-engine-uint.c:31
SigTableElmt_::desc
const char * desc
Definition: detect.h:1544
sigmatch_table
SigTableElmt * sigmatch_table
Definition: detect-parse.c:78
SigTableElmt_::Free
void(* Free)(DetectEngineCtx *, void *)
Definition: detect.h:1529
SigTableElmt_::name
const char * name
Definition: detect.h:1542
PKT_IS_PSEUDOPKT
#define PKT_IS_PSEUDOPKT(p)
return 1 if the packet is a pseudo packet
Definition: decode.h:1364
SigGroupHead_
Container for matching data for a signature group.
Definition: detect.h:1730
UtRegisterTest
void UtRegisterTest(const char *name, int(*TestFn)(void))
Register unit test.
Definition: util-unittest.c:101
SigTableElmt_::flags
uint32_t flags
Definition: detect.h:1533
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
PrefilterPacketU32Set
void PrefilterPacketU32Set(PrefilterPacketHeaderValue *v, void *smctx)
Definition: detect-engine-uint.c:51
DetectEngineThreadCtx_::pmq
PrefilterRuleStore pmq
Definition: detect.h:1429
ctx
struct Thresholds ctx
DetectEngineCtx_
main detection engine ctx
Definition: detect.h:995
DetectEngineCtxFree
void DetectEngineCtxFree(DetectEngineCtx *)
Free a DetectEngineCtx::
Definition: detect-engine.c:2912
detect-tcp-seq.h
UTHBuildPacket
Packet * UTHBuildPacket(uint8_t *payload, uint16_t payload_len, uint8_t ipproto)
UTHBuildPacket is a wrapper that build packets with default ip and port fields.
Definition: util-unittest-helper.c:241
p
Packet * p
Definition: fuzz_dataset.c:30
SigCleanSignatures
void SigCleanSignatures(DetectEngineCtx *de_ctx)
Definition: detect-engine-build.c:56
SigTableElmt_::Setup
int(* Setup)(DetectEngineCtx *, Signature *, const char *)
Definition: detect.h:1524
detect-engine-prefilter.h
util-unittest-helper.h
SigTableElmt_::SetupPrefilter
int(* SetupPrefilter)(DetectEngineCtx *de_ctx, struct SigGroupHead_ *sgh)
Definition: detect.h:1527
DetectSeqRegister
void DetectSeqRegister(void)
Registration function for ack: keyword.
Definition: detect-tcp-seq.c:53
PrefilterPacketHeaderCtx_
Definition: detect-engine-prefilter-common.h:35
decode.h
util-debug.h
de_ctx
DetectEngineCtx * de_ctx
Definition: fuzz_siginit.c:22
DetectEngineThreadCtx_
Definition: detect.h:1316
TCPHdr_::th_seq
uint32_t th_seq
Definition: decode-tcp.h:152
SCSigMatchAppendSMToList
SigMatch * SCSigMatchAppendSMToList(DetectEngineCtx *de_ctx, Signature *s, uint16_t type, SigMatchCtx *ctx, const int list)
Append a SigMatch to the list type.
Definition: detect-parse.c:424
detect.h
DETECT_SM_LIST_MATCH
@ DETECT_SM_LIST_MATCH
Definition: detect.h:118
SigInit
Signature * SigInit(DetectEngineCtx *de_ctx, const char *sigstr)
Parses a signature and adds it to the Detection Engine Context.
Definition: detect-parse.c:3618
DETECT_SEQ
@ DETECT_SEQ
Definition: detect-engine-register.h:37
SigGroupCleanup
int SigGroupCleanup(DetectEngineCtx *de_ctx)
Definition: detect-engine-build.c:2371
Signature_::flags
uint32_t flags
Definition: detect.h:693
Packet_
Definition: decode.h:516
detect-engine-build.h
Packet_::l4
struct PacketL4 l4
Definition: decode.h:616
PrefilterSetupPacketHeader
int PrefilterSetupPacketHeader(DetectEngineCtx *de_ctx, SigGroupHead *sgh, int sm_type, SignatureMask mask, void(*Set)(PrefilterPacketHeaderValue *v, void *), bool(*Compare)(PrefilterPacketHeaderValue v, void *), void(*Match)(DetectEngineThreadCtx *det_ctx, Packet *p, const void *pectx))
Definition: detect-engine-prefilter-common.c:470
PrefilterPacketU32Compare
bool PrefilterPacketU32Compare(PrefilterPacketHeaderValue v, void *smctx)
Definition: detect-engine-uint.c:60
SigTableElmt_::Match
int(* Match)(DetectEngineThreadCtx *, Packet *, const Signature *, const SigMatchCtx *)
Definition: detect.h:1504
SigMatchCtx_
Used to start a pointer to SigMatch context Should never be dereferenced without casting to something...
Definition: detect.h:355
SigTableElmt_::alias
const char * alias
Definition: detect.h:1543
suricata-common.h
DetectU32Data
DetectUintData_u32 DetectU32Data
Definition: detect-engine-uint.h:41
UTHGenericTest
int UTHGenericTest(Packet **pkt, int numpkts, const char *sigs[], uint32_t sids[], uint32_t *results, int numsigs)
UTHGenericTest: function that perform a generic check taking care of as maximum common unittest eleme...
Definition: util-unittest-helper.c:578
PacketL4::L4Hdrs::tcph
TCPHdr * tcph
Definition: decode.h:481
SigTableElmt_::SupportsPrefilter
bool(* SupportsPrefilter)(const Signature *s)
Definition: detect.h:1526
SIGMATCH_INFO_UINT32
#define SIGMATCH_INFO_UINT32
Definition: detect-engine-register.h:346
detect-parse.h
Signature_
Signature container.
Definition: detect.h:692
PacketL4::hdrs
union PacketL4::L4Hdrs hdrs
DetectEngineCtxInit
DetectEngineCtx * DetectEngineCtxInit(void)
Definition: detect-engine.c:2873
detect-engine-prefilter-common.h
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
SigTableElmt_::RegisterTests
void(* RegisterTests)(void)
Definition: detect.h:1531
SIG_FLAG_REQUIRE_PACKET
#define SIG_FLAG_REQUIRE_PACKET
Definition: detect.h:257
UTHFreePackets
void UTHFreePackets(Packet **p, int numpkts)
UTHFreePackets: function to release the allocated data from UTHBuildPacket and the packet itself.
Definition: util-unittest-helper.c:453