|
|
|
/* Copyright (C) 2007-2010 Open Information Security Foundation
|
|
|
|
*
|
|
|
|
* You can copy, redistribute or modify this Program under the terms of
|
|
|
|
* the GNU General Public License version 2 as published by the Free
|
|
|
|
* Software Foundation.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* version 2 along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
|
|
|
* 02110-1301, USA.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* \file
|
|
|
|
*
|
|
|
|
* \author Victor Julien <victor@inliniac.net>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef __DETECT_ENGINE_H__
|
|
|
|
#define __DETECT_ENGINE_H__
|
|
|
|
|
|
|
|
#include "detect.h"
|
Add per packet profiling.
Per packet profiling uses tick based accounting. It has 2 outputs, a summary
and a csv file that contains per packet stats.
Stats per packet include:
1) total ticks spent
2) ticks spent per individual thread module
3) "threading overhead" which is simply calculated by subtracting (2) of (1).
A number of changes were made to integrate the new code in a clean way:
a number of generic enums are now placed in tm-threads-common.h so we can
include them from any part of the engine.
Code depends on --enable-profiling just like the rule profiling code.
New yaml parameters:
profiling:
# packet profiling
packets:
# Profiling can be disabled here, but it will still have a
# performance impact if compiled in.
enabled: yes
filename: packet_stats.log
append: yes
# per packet csv output
csv:
# Output can be disabled here, but it will still have a
# performance impact if compiled in.
enabled: no
filename: packet_stats.csv
Example output of summary stats:
IP ver Proto cnt min max avg
------ ----- ------ ------ ---------- -------
IPv4 6 19436 11448 5404365 32993
IPv4 256 4 11511 49968 30575
Per Thread module stats:
Thread Module IP ver Proto cnt min max avg
------------------------ ------ ----- ------ ------ ---------- -------
TMM_DECODEPCAPFILE IPv4 6 19434 1242 47889 1770
TMM_DETECT IPv4 6 19436 1107 137241 1504
TMM_ALERTFASTLOG IPv4 6 19436 90 1323 155
TMM_ALERTUNIFIED2ALERT IPv4 6 19436 108 1359 138
TMM_ALERTDEBUGLOG IPv4 6 19436 90 1134 154
TMM_LOGHTTPLOG IPv4 6 19436 414 5392089 7944
TMM_STREAMTCP IPv4 6 19434 828 1299159 19438
The proto 256 is a counter for handling of pseudo/tunnel packets.
Example output of csv:
pcap_cnt,ipver,ipproto,total,TMM_DECODENFQ,TMM_VERDICTNFQ,TMM_RECEIVENFQ,TMM_RECEIVEPCAP,TMM_RECEIVEPCAPFILE,TMM_DECODEPCAP,TMM_DECODEPCAPFILE,TMM_RECEIVEPFRING,TMM_DECODEPFRING,TMM_DETECT,TMM_ALERTFASTLOG,TMM_ALERTFASTLOG4,TMM_ALERTFASTLOG6,TMM_ALERTUNIFIEDLOG,TMM_ALERTUNIFIEDALERT,TMM_ALERTUNIFIED2ALERT,TMM_ALERTPRELUDE,TMM_ALERTDEBUGLOG,TMM_ALERTSYSLOG,TMM_LOGDROPLOG,TMM_ALERTSYSLOG4,TMM_ALERTSYSLOG6,TMM_RESPONDREJECT,TMM_LOGHTTPLOG,TMM_LOGHTTPLOG4,TMM_LOGHTTPLOG6,TMM_PCAPLOG,TMM_STREAMTCP,TMM_DECODEIPFW,TMM_VERDICTIPFW,TMM_RECEIVEIPFW,TMM_RECEIVEERFFILE,TMM_DECODEERFFILE,TMM_RECEIVEERFDAG,TMM_DECODEERFDAG,threading
1,4,6,172008,0,0,0,0,0,0,47889,0,0,48582,1323,0,0,0,0,1359,0,1134,0,0,0,0,0,8028,0,0,0,49356,0,0,0,0,0,0,0,14337
First line of the file contains labels.
2 example gnuplot scripts added to plot the data.
14 years ago
|
|
|
#include "tm-threads.h"
|
App layer API rewritten. The main files in question are:
app-layer.[ch], app-layer-detect-proto.[ch] and app-layer-parser.[ch].
Things addressed in this commit:
- Brings out a proper separation between protocol detection phase and the
parser phase.
- The dns app layer now is registered such that we don't use "dnstcp" and
"dnsudp" in the rules. A user who previously wrote a rule like this -
"alert dnstcp....." or
"alert dnsudp....."
would now have to use,
alert dns (ipproto:tcp;) or
alert udp (app-layer-protocol:dns;) or
alert ip (ipproto:udp; app-layer-protocol:dns;)
The same rules extend to other another such protocol, dcerpc.
- The app layer parser api now takes in the ipproto while registering
callbacks.
- The app inspection/detection engine also takes an ipproto.
- All app layer parser functions now take direction as STREAM_TOSERVER or
STREAM_TOCLIENT, as opposed to 0 or 1, which was taken by some of the
functions.
- FlowInitialize() and FlowRecycle() now resets proto to 0. This is
needed by unittests, which would try to clean the flow, and that would
call the api, AppLayerParserCleanupParserState(), which would try to
clean the app state, but the app layer now needs an ipproto to figure
out which api to internally call to clean the state, and if the ipproto
is 0, it would return without trying to clean the state.
- A lot of unittests are now updated where if they are using a flow and
they need to use the app layer, we would set a flow ipproto.
- The "app-layer" section in the yaml conf has also been updated as well.
12 years ago
|
|
|
#include "flow-private.h"
|
|
|
|
|
|
|
|
typedef struct DetectEngineAppInspectionEngine_ {
|
|
|
|
uint8_t ipproto;
|
|
|
|
AppProto alproto;
|
|
|
|
uint16_t dir;
|
|
|
|
|
|
|
|
int32_t sm_list;
|
|
|
|
uint32_t inspect_flags;
|
|
|
|
|
|
|
|
/* \retval 0 No match. Don't discontinue matching yet. We need more data.
|
|
|
|
* 1 Match.
|
|
|
|
* 2 Sig can't match.
|
|
|
|
* 3 Special value used by filestore sigs to indicate disabling
|
|
|
|
* filestore for the tx.
|
|
|
|
*/
|
|
|
|
int (*Callback)(ThreadVars *tv,
|
|
|
|
DetectEngineCtx *de_ctx, DetectEngineThreadCtx *det_ctx,
|
|
|
|
Signature *sig, Flow *f, uint8_t flags, void *alstate,
|
|
|
|
void *tx, uint64_t tx_id);
|
|
|
|
|
|
|
|
struct DetectEngineAppInspectionEngine_ *next;
|
|
|
|
} DetectEngineAppInspectionEngine;
|
|
|
|
|
App layer API rewritten. The main files in question are:
app-layer.[ch], app-layer-detect-proto.[ch] and app-layer-parser.[ch].
Things addressed in this commit:
- Brings out a proper separation between protocol detection phase and the
parser phase.
- The dns app layer now is registered such that we don't use "dnstcp" and
"dnsudp" in the rules. A user who previously wrote a rule like this -
"alert dnstcp....." or
"alert dnsudp....."
would now have to use,
alert dns (ipproto:tcp;) or
alert udp (app-layer-protocol:dns;) or
alert ip (ipproto:udp; app-layer-protocol:dns;)
The same rules extend to other another such protocol, dcerpc.
- The app layer parser api now takes in the ipproto while registering
callbacks.
- The app inspection/detection engine also takes an ipproto.
- All app layer parser functions now take direction as STREAM_TOSERVER or
STREAM_TOCLIENT, as opposed to 0 or 1, which was taken by some of the
functions.
- FlowInitialize() and FlowRecycle() now resets proto to 0. This is
needed by unittests, which would try to clean the flow, and that would
call the api, AppLayerParserCleanupParserState(), which would try to
clean the app state, but the app layer now needs an ipproto to figure
out which api to internally call to clean the state, and if the ipproto
is 0, it would return without trying to clean the state.
- A lot of unittests are now updated where if they are using a flow and
they need to use the app layer, we would set a flow ipproto.
- The "app-layer" section in the yaml conf has also been updated as well.
12 years ago
|
|
|
extern DetectEngineAppInspectionEngine *app_inspection_engine[FLOW_PROTO_DEFAULT][ALPROTO_MAX][2];
|
|
|
|
|
|
|
|
/* prototypes */
|
|
|
|
void DetectEngineRegisterAppInspectionEngines(void);
|
|
|
|
DetectEngineCtx *DetectEngineCtxInitWithPrefix(const char *prefix);
|
|
|
|
DetectEngineCtx *DetectEngineCtxInit(void);
|
|
|
|
DetectEngineCtx *DetectEngineCtxInitMinimal(void);
|
|
|
|
void DetectEngineCtxFree(DetectEngineCtx *);
|
|
|
|
|
|
|
|
TmEcode DetectEngineThreadCtxInit(ThreadVars *, void *, void **);
|
|
|
|
TmEcode DetectEngineThreadCtxDeinit(ThreadVars *, void *);
|
|
|
|
//inline uint32_t DetectEngineGetMaxSigId(DetectEngineCtx *);
|
|
|
|
/* faster as a macro than a inline function on my box -- VJ */
|
|
|
|
#define DetectEngineGetMaxSigId(de_ctx) ((de_ctx)->signum)
|
|
|
|
void DetectEngineResetMaxSigId(DetectEngineCtx *);
|
|
|
|
void DetectEngineRegisterTests(void);
|
|
|
|
const char *DetectSigmatchListEnumToString(enum DetectSigmatchListEnum type);
|
|
|
|
|
|
|
|
int DetectEngineAddToMaster(DetectEngineCtx *de_ctx);
|
|
|
|
DetectEngineCtx *DetectEngineGetCurrent(void);
|
|
|
|
DetectEngineCtx *DetectEngineGetByTenantId(int tenant_id);
|
|
|
|
void DetectEnginePruneFreeList(void);
|
|
|
|
int DetectEngineMoveToFreeList(DetectEngineCtx *de_ctx);
|
|
|
|
DetectEngineCtx *DetectEngineReference(DetectEngineCtx *);
|
|
|
|
void DetectEngineDeReference(DetectEngineCtx **de_ctx);
|
|
|
|
int DetectEngineReload(const char *filename, SCInstance *suri);
|
|
|
|
int DetectEngineEnabled(void);
|
|
|
|
int DetectEngineMTApply(void);
|
|
|
|
int DetectEngineMultiTenantEnabled(void);
|
|
|
|
int DetectEngineMultiTenantSetup(void);
|
|
|
|
|
|
|
|
int DetectEngineReloadStart(void);
|
|
|
|
int DetectEngineReloadIsStart(void);
|
|
|
|
void DetectEngineReloadSetDone(void);
|
|
|
|
int DetectEngineReloadIsDone(void);
|
|
|
|
|
|
|
|
int DetectEngineLoadTenantBlocking(uint32_t tenant_id, const char *yaml);
|
|
|
|
int DetectEngineReloadTenantBlocking(uint32_t tenant_id, const char *yaml, int reload_cnt);
|
|
|
|
|
|
|
|
int DetectEngineTentantRegisterVlanId(uint32_t tenant_id, uint16_t vlan_id);
|
|
|
|
int DetectEngineTentantUnregisterVlanId(uint32_t tenant_id, uint16_t vlan_id);
|
|
|
|
int DetectEngineTentantRegisterPcapFile(uint32_t tenant_id);
|
|
|
|
int DetectEngineTentantUnregisterPcapFile(uint32_t tenant_id);
|
|
|
|
|
|
|
|
/**
|
|
|
|
* \brief Registers an app inspection engine.
|
|
|
|
*
|
|
|
|
* \param alproto App layer protocol for which we will register the engine.
|
|
|
|
* \param direction The direction for the engine. 0 - toserver; 1- toclient.
|
|
|
|
* \param sm_list The SigMatch list against which the engine works.
|
|
|
|
* \param inspect_flags The inspection flags to be used by de_state
|
|
|
|
* against the engine.
|
|
|
|
* \param match_flags The match flags to be used by de_state in tandem with
|
|
|
|
* the inpsect_flags.
|
|
|
|
* \param Callback The engine callback.
|
|
|
|
*/
|
|
|
|
void DetectEngineRegisterAppInspectionEngine(uint8_t ipproto,
|
|
|
|
AppProto alproto,
|
|
|
|
uint16_t direction,
|
|
|
|
int32_t sm_list,
|
|
|
|
uint32_t inspect_flags,
|
|
|
|
int (*Callback)(ThreadVars *tv,
|
|
|
|
DetectEngineCtx *de_ctx,
|
|
|
|
DetectEngineThreadCtx *det_ctx,
|
|
|
|
Signature *sig, Flow *f,
|
|
|
|
uint8_t flags, void *alstate,
|
|
|
|
void *tx, uint64_t tx_id),
|
App layer API rewritten. The main files in question are:
app-layer.[ch], app-layer-detect-proto.[ch] and app-layer-parser.[ch].
Things addressed in this commit:
- Brings out a proper separation between protocol detection phase and the
parser phase.
- The dns app layer now is registered such that we don't use "dnstcp" and
"dnsudp" in the rules. A user who previously wrote a rule like this -
"alert dnstcp....." or
"alert dnsudp....."
would now have to use,
alert dns (ipproto:tcp;) or
alert udp (app-layer-protocol:dns;) or
alert ip (ipproto:udp; app-layer-protocol:dns;)
The same rules extend to other another such protocol, dcerpc.
- The app layer parser api now takes in the ipproto while registering
callbacks.
- The app inspection/detection engine also takes an ipproto.
- All app layer parser functions now take direction as STREAM_TOSERVER or
STREAM_TOCLIENT, as opposed to 0 or 1, which was taken by some of the
functions.
- FlowInitialize() and FlowRecycle() now resets proto to 0. This is
needed by unittests, which would try to clean the flow, and that would
call the api, AppLayerParserCleanupParserState(), which would try to
clean the app state, but the app layer now needs an ipproto to figure
out which api to internally call to clean the state, and if the ipproto
is 0, it would return without trying to clean the state.
- A lot of unittests are now updated where if they are using a flow and
they need to use the app layer, we would set a flow ipproto.
- The "app-layer" section in the yaml conf has also been updated as well.
12 years ago
|
|
|
DetectEngineAppInspectionEngine *list[][ALPROTO_MAX][2]);
|
|
|
|
#endif /* __DETECT_ENGINE_H__ */
|