suricata
Signature_ Struct Reference

Signature container. More...

#include <detect.h>

Collaboration diagram for Signature_:

Data Fields

uint32_t flags
 
enum SignatureType type
 
AppProto alproto
 
uint16_t dsize_low
 
uint16_t dsize_high
 
uint8_t dsize_mode
 
SignatureMask mask
 
SigIntId iid
 
uint8_t action
 
uint8_t file_flags
 
DetectProto * proto
 
uint8_t action_scope
 
uint16_t addr_dst_match4_cnt
 
uint16_t addr_src_match4_cnt
 
uint16_t addr_dst_match6_cnt
 
uint16_t addr_src_match6_cnt
 
uint16_t class_id
 
uint8_t detect_table
 
uint8_t app_progress_hook
 
uint8_t sub_state
 
DetectMatchAddressIPv4 * addr_dst_match4
 
DetectMatchAddressIPv4 * addr_src_match4
 
DetectMatchAddressIPv6 * addr_dst_match6
 
DetectMatchAddressIPv6 * addr_src_match6
 
uint32_t id
 
uint32_t gid
 
uint32_t rev
 
int prio
 
DetectPort * sp
 
DetectPort * dp
 
DetectEngineAppInspectionEngine * app_inspect
 
DetectEnginePktInspectionEngine * pkt_inspect
 
DetectEngineFrameInspectionEngine * frame_inspect
 
SigMatchData * sm_arrays [DETECT_SM_LIST_MAX]
 
const struct DetectFilestoreData_ * filestore_ctx
 
char * msg
 
char * class_msg
 
DetectReference * references
 
DetectMetadataHead * metadata
 
char * sig_str
 
SignatureInitData * init_data
 
struct Signature_ * next
 

Detailed Description

Signature container.

Definition at line 692 of file detect.h.

Field Documentation

◆ action

uint8_t Signature_::action

inline – action

Definition at line 707 of file detect.h.

Referenced by EngineAnalysisRules2().

◆ action_scope

uint8_t Signature_::action_scope

Definition at line 714 of file detect.h.

Referenced by EngineAnalysisRules2().

◆ addr_dst_match4

DetectMatchAddressIPv4* Signature_::addr_dst_match4

Definition at line 735 of file detect.h.

◆ addr_dst_match4_cnt

uint16_t Signature_::addr_dst_match4_cnt

ipv4 match arrays

Definition at line 717 of file detect.h.

◆ addr_dst_match6

DetectMatchAddressIPv6* Signature_::addr_dst_match6

ipv6 match arrays

Definition at line 738 of file detect.h.

◆ addr_dst_match6_cnt

uint16_t Signature_::addr_dst_match6_cnt

Definition at line 719 of file detect.h.

◆ addr_src_match4

DetectMatchAddressIPv4* Signature_::addr_src_match4

Definition at line 736 of file detect.h.

◆ addr_src_match4_cnt

uint16_t Signature_::addr_src_match4_cnt

Definition at line 718 of file detect.h.

◆ addr_src_match6

DetectMatchAddressIPv6* Signature_::addr_src_match6

Definition at line 739 of file detect.h.

◆ addr_src_match6_cnt

uint16_t Signature_::addr_src_match6_cnt

Definition at line 720 of file detect.h.

◆ alproto

◆ app_inspect

DetectEngineAppInspectionEngine* Signature_::app_inspect

Definition at line 753 of file detect.h.

Referenced by DetectEngineAppInspectionEngineSignatureFree().

◆ app_progress_hook

uint8_t Signature_::app_progress_hook

firewall: progress value for this signature

Definition at line 729 of file detect.h.

Referenced by DetectEngineAppInspectionEngine2Signature().

◆ class_id

uint16_t Signature_::class_id

classification id

Definition at line 723 of file detect.h.

◆ class_msg

char* Signature_::class_msg

classification message

Definition at line 767 of file detect.h.

Referenced by AlertJsonHeader().

◆ detect_table

uint8_t Signature_::detect_table

detect: pseudo table this rule is part of (enum DetectTable)

Definition at line 726 of file detect.h.

◆ dp

DetectPort * Signature_::dp

Definition at line 747 of file detect.h.

◆ dsize_high

uint16_t Signature_::dsize_high

Definition at line 700 of file detect.h.

Referenced by SigParseSetDsizePair().

◆ dsize_low

uint16_t Signature_::dsize_low

Definition at line 699 of file detect.h.

Referenced by SigParseSetDsizePair().

◆ dsize_mode

uint8_t Signature_::dsize_mode

Definition at line 701 of file detect.h.

Referenced by SigParseSetDsizePair().

◆ file_flags

◆ filestore_ctx

const struct DetectFilestoreData_* Signature_::filestore_ctx

Definition at line 762 of file detect.h.

◆ flags

◆ frame_inspect

DetectEngineFrameInspectionEngine* Signature_::frame_inspect

◆ gid

uint32_t Signature_::gid

generator id

Definition at line 742 of file detect.h.

Referenced by AlertJsonHeader(), and EngineAnalysisRules2().

◆ id

◆ iid

SigIntId Signature_::iid

signature internal id

Definition at line 704 of file detect.h.

Referenced by IPOnlyAddSignature(), PostRuleMatchWorkQueueAppend(), SigGroupBuild(), and SigPrepareStage1().

◆ init_data

◆ mask

SignatureMask Signature_::mask

Definition at line 703 of file detect.h.

Referenced by EngineAnalysisRules2().

◆ metadata

DetectMetadataHead* Signature_::metadata

Metadata

Definition at line 771 of file detect.h.

◆ msg

char* Signature_::msg

Definition at line 764 of file detect.h.

Referenced by AlertJsonHeader(), EngineAnalysisRules2(), and IPOnlyAddSignature().

◆ next

struct Signature_* Signature_::next

ptr to the next sig in the list

Definition at line 778 of file detect.h.

Referenced by DetectSetFastPatternAndItsId(), SigCleanSignatures(), SigFindSignatureBySidGid(), SigGroupBuild(), and SigPrepareStage1().

◆ pkt_inspect

◆ prio

int Signature_::prio

Definition at line 744 of file detect.h.

Referenced by AlertJsonHeader(), and SigAlloc().

◆ proto

DetectProto* Signature_::proto

rule protocol: can be NULL if the check can be skipped

Definition at line 711 of file detect.h.

Referenced by DetectProtoFinalizeSignature(), and IPOnlyMatchPacket().

◆ references

DetectReference* Signature_::references

Reference

Definition at line 769 of file detect.h.

◆ rev

uint32_t Signature_::rev

Definition at line 743 of file detect.h.

Referenced by AlertJsonHeader(), and EngineAnalysisRules2().

◆ sig_str

char* Signature_::sig_str

◆ sm_arrays

SigMatchData* Signature_::sm_arrays[DETECT_SM_LIST_MAX]

Definition at line 759 of file detect.h.

Referenced by DetectEngineInspectPacketPayload(), and DetectEnginePktInspectionSetup().

◆ sp

DetectPort* Signature_::sp

port settings for this signature

Definition at line 747 of file detect.h.

◆ sub_state

uint8_t Signature_::sub_state

firewall: sub state (transaction type) of the hook on protocols with sub states (http2 stream/global, DoH2); 0 when the hook has no sub state. Signatures are zero initialized, so unused stays 0.

Definition at line 733 of file detect.h.

◆ type


The documentation for this struct was generated from the following file: