suricata
reputation.c File Reference
#include "suricata-common.h"
#include "detect.h"
#include "reputation.h"
#include "threads.h"
#include "conf.h"
#include "util-byte.h"
#include "util-debug.h"
#include "util-error.h"
#include "util-ip.h"
#include "util-path.h"
#include "util-print.h"
#include "util-unittest.h"
#include "util-validate.h"
#include "tests/reputation.c"
Include dependency graph for reputation.c:

Go to the source code of this file.

Macros

#define SREP_SHORTNAME_LEN   32
 

Functions

 SC_ATOMIC_DECLARE (uint32_t, srep_eversion)
 
void SRepResetVersion (void)
 
uint8_t SRepCIDRGetIPRepSrc (SRepCIDRTree *cidr_ctx, Packet *p, uint8_t cat, uint32_t version)
 
uint8_t SRepCIDRGetIPRepDst (SRepCIDRTree *cidr_ctx, Packet *p, uint8_t cat, uint32_t version)
 
void SRepReloadComplete (void)
 Increment effective reputation version after a rule/reputation reload is complete. More...
 
void SRepFreeHostData (Host *h)
 
int SRepHostTimedOut (Host *h)
 Check if a Host is timed out wrt ip rep, meaning a new version is in place. More...
 
uint8_t SRepCatGetByShortname (char *shortname)
 
int SRepLoadCatFileFromFD (FILE *fp)
 
int SRepLoadFileFromFD (SRepCIDRTree *cidr_ctx, FILE *fp)
 
int SRepInit (DetectEngineCtx *de_ctx)
 init reputation More...
 
void SRepDestroy (DetectEngineCtx *de_ctx)
 

Detailed Description

Author
Pablo Rincon Crespo pablo.nosp@m..rin.nosp@m.con.c.nosp@m.resp.nosp@m.o@gma.nosp@m.il.c.nosp@m.om
Victor Julien victo.nosp@m.r@in.nosp@m.linia.nosp@m.c.ne.nosp@m.t Original Idea by Matt Jonkman

IP Reputation Module, initial API for IPV4 and IPV6 feed

Definition in file reputation.c.

Macro Definition Documentation

◆ SREP_SHORTNAME_LEN

#define SREP_SHORTNAME_LEN   32

Definition at line 341 of file reputation.c.

Function Documentation

◆ SC_ATOMIC_DECLARE()

SC_ATOMIC_DECLARE ( uint32_t  ,
srep_eversion   
)

effective reputation version, atomic as the host time out code will use it to check if a host's reputation info is outdated.

◆ SRepCatGetByShortname()

uint8_t SRepCatGetByShortname ( char *  shortname)

Definition at line 343 of file reputation.c.

References SREP_MAX_CATS.

◆ SRepCIDRGetIPRepDst()

uint8_t SRepCIDRGetIPRepDst ( SRepCIDRTree cidr_ctx,
Packet p,
uint8_t  cat,
uint32_t  version 
)

Definition at line 160 of file reputation.c.

References PKT_IS_IPV4.

◆ SRepCIDRGetIPRepSrc()

uint8_t SRepCIDRGetIPRepSrc ( SRepCIDRTree cidr_ctx,
Packet p,
uint8_t  cat,
uint32_t  version 
)

Definition at line 148 of file reputation.c.

References PKT_IS_IPV4.

◆ SRepDestroy()

void SRepDestroy ( DetectEngineCtx de_ctx)

Definition at line 664 of file reputation.c.

References de_ctx, SCFree, SCRadixReleaseRadixTree(), SREP_MAX_CATS, DetectEngineCtx_::srepCIDR_ctx, SRepCIDRTree_::srepIPV4_tree, and SRepCIDRTree_::srepIPV6_tree.

Here is the call graph for this function:

◆ SRepFreeHostData()

void SRepFreeHostData ( Host h)

Definition at line 180 of file reputation.c.

References DEBUG_VALIDATE_BUG_ON, HostDecrUsecnt, Host_::iprep, SC_ATOMIC_GET, and SCFree.

Referenced by HostClearMemory().

Here is the caller graph for this function:

◆ SRepHostTimedOut()

int SRepHostTimedOut ( Host h)

Check if a Host is timed out wrt ip rep, meaning a new version is in place.

We clean up the old version here.

Parameters
hhost
Return values
0not timed out
1timed out

Definition at line 206 of file reputation.c.

References BUG_ON, and Host_::iprep.

◆ SRepInit()

int SRepInit ( DetectEngineCtx de_ctx)

init reputation

Parameters
de_ctxdetection engine ctx for tracking iprep version
Return values
0ok
-1error

If this function is called more than once, the category file is not reloaded.

Definition at line 581 of file reputation.c.

References de_ctx, SCCalloc, SREP_MAX_CATS, DetectEngineCtx_::srepCIDR_ctx, SRepCIDRTree_::srepIPV4_tree, and SRepCIDRTree_::srepIPV6_tree.

◆ SRepLoadCatFileFromFD()

int SRepLoadCatFileFromFD ( FILE *  fp)

Definition at line 371 of file reputation.c.

References Address_::family.

◆ SRepLoadFileFromFD()

int SRepLoadFileFromFD ( SRepCIDRTree cidr_ctx,
FILE *  fp 
)

Definition at line 438 of file reputation.c.

References Address_::family, and len.

◆ SRepReloadComplete()

void SRepReloadComplete ( void  )

Increment effective reputation version after a rule/reputation reload is complete.

Definition at line 174 of file reputation.c.

References SC_ATOMIC_ADD, and SCLogDebug.

◆ SRepResetVersion()

void SRepResetVersion ( void  )

Definition at line 62 of file reputation.c.