suricata
reputation.c File Reference
#include "suricata-common.h"
#include "util-error.h"
#include "util-debug.h"
#include "util-ip.h"
#include "util-radix-tree.h"
#include "util-unittest.h"
#include "threads.h"
#include "util-print.h"
#include "host.h"
#include "conf.h"
#include "detect.h"
#include "reputation.h"
#include "tests/reputation.c"
Include dependency graph for reputation.c:

Go to the source code of this file.

Macros

#define SREP_SHORTNAME_LEN   32
 

Functions

 SC_ATOMIC_DECLARE (uint32_t, srep_eversion)
 
void SRepResetVersion (void)
 
uint8_t SRepCIDRGetIPRepSrc (SRepCIDRTree *cidr_ctx, Packet *p, uint8_t cat, uint32_t version)
 
uint8_t SRepCIDRGetIPRepDst (SRepCIDRTree *cidr_ctx, Packet *p, uint8_t cat, uint32_t version)
 
void SRepReloadComplete (void)
 Increment effective reputation version after a rule/reputatio reload is complete. More...
 
int SRepHostTimedOut (Host *h)
 Check if a Host is timed out wrt ip rep, meaning a new version is in place. More...
 
uint8_t SRepCatGetByShortname (char *shortname)
 
int SRepLoadCatFileFromFD (FILE *fp)
 
int SRepLoadFileFromFD (SRepCIDRTree *cidr_ctx, FILE *fp)
 
int SRepInit (DetectEngineCtx *de_ctx)
 init reputation More...
 
void SRepDestroy (DetectEngineCtx *de_ctx)
 

Detailed Description

Author
Pablo Rincon Crespo pablo.nosp@m..rin.nosp@m.con.c.nosp@m.resp.nosp@m.o@gma.nosp@m.il.c.nosp@m.om
Victor Julien victo.nosp@m.r@in.nosp@m.linia.nosp@m.c.ne.nosp@m.t Original Idea by Matt Jonkman

IP Reputation Module, initial API for IPV4 and IPV6 feed

Definition in file reputation.c.

Macro Definition Documentation

#define SREP_SHORTNAME_LEN   32

Definition at line 337 of file reputation.c.

Referenced by SRepLoadCatFileFromFD().

Function Documentation

SC_ATOMIC_DECLARE ( uint32_t  ,
srep_eversion   
)

effective reputation version, atomic as the host time out code will use it to check if a host's reputation info is outdated.

uint8_t SRepCatGetByShortname ( char *  shortname)

Definition at line 340 of file reputation.c.

References SC_ERR_OPENING_RULE_FILE, SCLogError, SREP_MAX_CATS, and SRepLoadCatFileFromFD().

Referenced by DetectIPRepRegister().

Here is the call graph for this function:

Here is the caller graph for this function:

uint8_t SRepCIDRGetIPRepDst ( SRepCIDRTree cidr_ctx,
Packet p,
uint8_t  cat,
uint32_t  version 
)

Definition at line 158 of file reputation.c.

References GET_IPV4_DST_ADDR_PTR, GET_IPV6_DST_ADDR, PKT_IS_IPV4, and PKT_IS_IPV6.

Referenced by DetectIPRepRegister().

Here is the caller graph for this function:

uint8_t SRepCIDRGetIPRepSrc ( SRepCIDRTree cidr_ctx,
Packet p,
uint8_t  cat,
uint32_t  version 
)

Definition at line 146 of file reputation.c.

References GET_IPV4_SRC_ADDR_PTR, GET_IPV6_SRC_ADDR, PKT_IS_IPV4, and PKT_IS_IPV6.

Referenced by DetectIPRepRegister().

Here is the caller graph for this function:

void SRepDestroy ( DetectEngineCtx de_ctx)

Definition at line 662 of file reputation.c.

References SCFree, SCRadixReleaseRadixTree(), SREP_MAX_CATS, DetectEngineCtx_::srepCIDR_ctx, SRepCIDRTree_::srepIPV4_tree, and SRepCIDRTree_::srepIPV6_tree.

Referenced by DetectEngineCtxFree().

Here is the call graph for this function:

Here is the caller graph for this function:

int SRepHostTimedOut ( Host h)

Check if a Host is timed out wrt ip rep, meaning a new version is in place.

We clean up the old version here.

Parameters
hhost
Return values
0not timed out
1timed out

Definition at line 196 of file reputation.c.

References Address_::address, BUG_ON, Address_::family, HostDecrUsecnt, Host_::iprep, SCFree, SCLogDebug, SREP_MAX_CATS, SREP_MAX_VAL, strlcpy(), and SReputation_::version.

Referenced by HostGetActiveCount().

Here is the call graph for this function:

Here is the caller graph for this function:

int SRepInit ( DetectEngineCtx de_ctx)

init reputation

Parameters
de_ctxdetection engine ctx for tracking iprep version
Return values
0ok
-1error

If this function is called more than once, the category file is not reloaded.

Definition at line 579 of file reputation.c.

References ConfGet(), ConfGetNode(), DetectEngineCtx_::failure_fatal, HostPrintStats(), next, SC_ATOMIC_INIT, SC_ERR_NO_REPUTATION, SCFree, SCLogDebug, SCLogError, SCLogInfo, SCMalloc, SREP_MAX_CATS, DetectEngineCtx_::srep_version, DetectEngineCtx_::srepCIDR_ctx, SRepCIDRTree_::srepIPV4_tree, SRepCIDRTree_::srepIPV6_tree, TAILQ_FOREACH, and ConfNode_::val.

Referenced by DetectEngineInspectPktBufferGeneric(), and DetectIPRepFree().

Here is the call graph for this function:

Here is the caller graph for this function:

int SRepLoadCatFileFromFD ( FILE *  fp)

Definition at line 368 of file reputation.c.

References BUG_ON, Address_::family, len, SC_ERR_NO_REPUTATION, SC_ERR_OPENING_RULE_FILE, SCLogDebug, SCLogError, SREP_MAX_CATS, SREP_SHORTNAME_LEN, SRepLoadFileFromFD(), and strlcpy().

Referenced by DetectIPRepFree(), and SRepCatGetByShortname().

Here is the call graph for this function:

Here is the caller graph for this function:

int SRepLoadFileFromFD ( SRepCIDRTree cidr_ctx,
FILE *  fp 
)
void SRepReloadComplete ( void  )

Increment effective reputation version after a rule/reputatio reload is complete.

Definition at line 172 of file reputation.c.

References SC_ATOMIC_ADD, SC_ATOMIC_SET, and SCLogDebug.

Referenced by DetectEngineInspectPktBufferGeneric().

Here is the caller graph for this function: