/src/suricata8/src/app-layer-events.h
Line | Count | Source |
1 | | /* Copyright (C) 2014-2022 Open Information Security Foundation |
2 | | * |
3 | | * You can copy, redistribute or modify this Program under the terms of |
4 | | * the GNU General Public License version 2 as published by the Free |
5 | | * Software Foundation. |
6 | | * |
7 | | * This program is distributed in the hope that it will be useful, |
8 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
9 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
10 | | * GNU General Public License for more details. |
11 | | * |
12 | | * You should have received a copy of the GNU General Public License |
13 | | * version 2 along with this program; if not, write to the Free Software |
14 | | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA |
15 | | * 02110-1301, USA. |
16 | | */ |
17 | | |
18 | | /** |
19 | | * \file |
20 | | * |
21 | | * \author Victor Julien <victor@inliniac.net> |
22 | | * \author Anoop Saldanha <anoopsaldanha@gmail.com> |
23 | | */ |
24 | | |
25 | | #ifndef SURICATA_APP_LAYER_EVENTS_H |
26 | | #define SURICATA_APP_LAYER_EVENTS_H |
27 | | |
28 | | /* contains fwd declaration of AppLayerDecoderEvents_ */ |
29 | | #include "decode.h" |
30 | | #include "rust.h" |
31 | | #include "util-enum.h" |
32 | | |
33 | | /** |
34 | | * \brief Data structure to store app layer decoder events. |
35 | | */ |
36 | | struct AppLayerDecoderEvents_ { |
37 | | /* array of events */ |
38 | | uint8_t *events; |
39 | | /* number of events in the above buffer */ |
40 | | uint8_t cnt; |
41 | | /* current event buffer size */ |
42 | | uint8_t events_buffer_size; |
43 | | /* last logged */ |
44 | | uint8_t event_last_logged; |
45 | | }; |
46 | | |
47 | | /* app layer pkt level events */ |
48 | | enum { |
49 | | APPLAYER_MISMATCH_PROTOCOL_BOTH_DIRECTIONS, |
50 | | APPLAYER_WRONG_DIRECTION_FIRST_DATA, |
51 | | APPLAYER_DETECT_PROTOCOL_ONLY_ONE_DIRECTION, |
52 | | APPLAYER_PROTO_DETECTION_SKIPPED, |
53 | | APPLAYER_NO_TLS_AFTER_STARTTLS, |
54 | | APPLAYER_UNEXPECTED_PROTOCOL, |
55 | | }; |
56 | | |
57 | | int AppLayerGetPktEventInfo(const char *event_name, uint8_t *event_id); |
58 | | |
59 | | int AppLayerGetEventInfoById( |
60 | | uint8_t event_id, const char **event_name, AppLayerEventType *event_type); |
61 | | void AppLayerDecoderEventsSetEventRaw(AppLayerDecoderEvents **sevents, uint8_t event); |
62 | | |
63 | | static inline int AppLayerDecoderEventsIsEventSet( |
64 | | const AppLayerDecoderEvents *devents, uint8_t event) |
65 | 17.4k | { |
66 | 17.4k | if (devents == NULL) |
67 | 9.92k | return 0; |
68 | | |
69 | 7.49k | int cnt = devents->cnt; |
70 | 30.1k | for (int i = 0; i < cnt; i++) { |
71 | 22.9k | if (devents->events[i] == event) |
72 | 269 | return 1; |
73 | 22.9k | } |
74 | | |
75 | 7.22k | return 0; |
76 | 7.49k | } Unexecuted instantiation: detect-engine.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: packet.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: stream-tcp-reassemble.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-events.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-ftp.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-htp.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-parser.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-smtp.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-ssl.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer.c:AppLayerDecoderEventsIsEventSet detect-app-layer-event.c:AppLayerDecoderEventsIsEventSet Line | Count | Source | 65 | 17.4k | { | 66 | 17.4k | if (devents == NULL) | 67 | 9.92k | return 0; | 68 | | | 69 | 7.49k | int cnt = devents->cnt; | 70 | 30.1k | for (int i = 0; i < cnt; i++) { | 71 | 22.9k | if (devents->events[i] == event) | 72 | 269 | return 1; | 73 | 22.9k | } | 74 | | | 75 | 7.22k | return 0; | 76 | 7.49k | } |
Unexecuted instantiation: detect-engine-build.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: output-json-anomaly.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: rust-context.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-dnp3.c:AppLayerDecoderEventsIsEventSet Unexecuted instantiation: app-layer-htp-file.c:AppLayerDecoderEventsIsEventSet |
77 | | |
78 | | void AppLayerDecoderEventsResetEvents(AppLayerDecoderEvents *events); |
79 | | void AppLayerDecoderEventsFreeEvents(AppLayerDecoderEvents **events); |
80 | | int DetectEngineGetEventInfo( |
81 | | const char *event_name, uint8_t *event_id, AppLayerEventType *event_type); |
82 | | int SCAppLayerGetEventIdByName(const char *event_name, SCEnumCharMap *table, uint8_t *event_id); |
83 | | |
84 | | #endif /* SURICATA_APP_LAYER_EVENTS_H */ |