Commit Graph

18213 Commits (497a69c5a80c33bf1e4c3bc4f408adfc7a243d92)
 

Author SHA1 Message Date
Victor Julien 497a69c5a8 clang-format: support clang 17
Update Github CI runner to use it.

Bump to Ubuntu 24.04 as well.

(cherry picked from commit 781bd5184e)
3 months ago
Victor Julien c1dbdaddf2 detect: cleanup last tx logic
Move into DetectTransaction.

(cherry picked from commit e0b501a4b7)
3 months ago
Victor Julien eddff49ebc detect: make progress values uint8_t
Also reflect that it can be >= 48, like in prefilter.

(cherry picked from commit 3d00e73d91)
3 months ago
Victor Julien 28f1b6b15f detect/firewall: minor code cleanup
(cherry picked from commit a9b3ad49ea)
3 months ago
Victor Julien 4a75eb9d4d detect/firewall: clean up apply accept logic
Use end state from tx.

Handle flow control from inside the function consistently.

(cherry picked from commit 4db84cfa28)
3 months ago
Victor Julien af8e861a2a detect/firewall: refactor per tx rule result handling
Break out the 3 options: match, partial match, no match for firewall
into separate functions.

Additionally, handle the re-match case for matches on a hook where the
progress value didn't yet progress further. In this case the continue
inspection logic revisits the rule and the accept needs to be
re-applied.

(cherry picked from commit 68885e75e1)
3 months ago
Victor Julien d095860fa1 detect/firewall: further simplify flow control
For the last for progress case we can just break on a firewall drop.

For the accept:flow and accept:tx cases the next sig (if any) will check
the flow/tx flag and manage flow control from there.

(cherry picked from commit 9c76480ac3)
3 months ago
Victor Julien 48ab24cba8 doc/userguide: add new constructs to firewall examples
(cherry picked from commit 0a84015214)
3 months ago
Victor Julien 05b9fd6969 doc/userguide: document firewall lte rule support
(cherry picked from commit 8728f9ffc0)
3 months ago
Victor Julien 166707f2f2 doc/userguide: fix default policies for pre_* hooks
Minor other cleanups.

(cherry picked from commit ac59883c26)
3 months ago
Victor Julien b0004fb7e1 doc: update firewall design
Bring in line with recent changes.

(cherry picked from commit da6af0879e)
3 months ago
Victor Julien b9aedae021 detect/firewall: clean up per rule run check
(cherry picked from commit bb6dc93789)
3 months ago
Victor Julien a1e3f90285 detect/firewall: minor flow control cleanup
(cherry picked from commit 035e8bc851)
3 months ago
Victor Julien c23e028369 detect/firewall: simplify pre-check flow
Simplify pre-check logic. Pre-check takes care of enforcing
FLOW_ACTION_ACCEPT, APP_LAYER_TX_ACCEPT and default policy enforcement
before the current rule's hook. This should be done in firewall mode for
each rule regardless whether it is a firewall or TD rule.

No need to track verdict state anymore.

(cherry picked from commit bb7aff36a8)
3 months ago
Victor Julien d74f9537c3 detect/firewall: clean up tx inspection loop
(cherry picked from commit 68f73302ce)
3 months ago
Victor Julien a97aa1a402 detect/firewall: consolidate action handling
Step towards consolidating all action handling into a central location.

(cherry picked from commit a86fe01cc3)
3 months ago
Victor Julien a39e36ce25 detect/firewall: clean up pre-check policy logic
(cherry picked from commit 1ad9c3ec29)
3 months ago
Victor Julien fa5ecdddec detect/firewall: fix accept:tx,alert in default policy
(cherry picked from commit 52967c69ec)
3 months ago
Victor Julien 22c3fb2ad0 detect/firewall: inject alert before default policy
If default policy is invoked because of missing rules for next hooks,
make sure to inject an alert before the next hook policies might do so.

(cherry picked from commit 247c6a2333)
3 months ago
Victor Julien 08376ae63a detect/firewall: update discarded logic
Only count alert queue overflow here, not alerts in the queue after a drop.

(cherry picked from commit 90a837cef3)
3 months ago
Victor Julien 8c94f108bc detect/firewall: drop in fw mode does not include alert
In TD mode the drop action also includes alert.

In firewall mode it should not to stay in line with accept.

Ticket: #8601.
(cherry picked from commit 57b16c964e)
3 months ago
Victor Julien 816e70029e detect/firewall: log alert for app default with alert
Fix missing alert on drop:flow,alert

(cherry picked from commit f1090da254)
3 months ago
Victor Julien ea666020d1 detect/firewall: improve handle fw alert handling
More clearly define the relationship between PacketAlerts for firewall
and threat detection events.

Also no longer count firewall_discarded if drop rule came before a
another rule, causing the later rule to not be evaluated/alerted.

When packet:filter and app:filter alert appear in a single alert queue,
handle accept:hook by keeping track of the detect_table.

(cherry picked from commit 485f5243d5)
3 months ago
Victor Julien f5ee931d6b detect/alert: fix suppressed drop handling
If drop was issued for suppressed rule, still consider it for the
next alert.

(cherry picked from commit 7e9402a2e0)
3 months ago
Victor Julien 9bd0ce75d6 detect: minor action handling cleanup
Don't run exact same check twice.

(cherry picked from commit 508bb71d78)
3 months ago
Victor Julien ca79a30b97 detect/firewall: fix TD drop:flow after FW accept:flow
Threat detection can drop a flow that is but in accept:flow by the
firewall.

(cherry picked from commit 9bcf0f332b)
3 months ago
Victor Julien 3670b36296 detect/firewall: fixup debug message
(cherry picked from commit ecf2161f3b)
3 months ago
Victor Julien 24736ed8ff detect/firewall: minor code cleanup
(cherry picked from commit fb9747df8e)
3 months ago
Victor Julien 5868e54fca eve/alert: firewall default policy logging improvements
Add firewall.hook to indicate the hook that the policy was set on.

Ticket: #8566.
(cherry picked from commit 8572088b0f)
3 months ago
Victor Julien 2b09cb8ab4 detect/firewall: support alert in packet default policy
Support `alert` as a secondary action in packet firewall policies.

To implement this a Signature object is created per policy that uses
alert, and this is stored in a array table. When the policy is applied
the signature is looked up and used in the PacketAlert.

Ticket: #8566.
(cherry picked from commit dc4c22e906)
3 months ago
Victor Julien 6440d4486c detect/firewall: support alert in default app policy
Support `alert` as a secondary action in app-layer firewall policies.

To implement this a Signature object is created per policy that uses
alert, and this is stored in a hash table. When the policy is applied
the signature is looked up and used in the PacketAlert.

Ticket: #8566.
(cherry picked from commit 2d4f1968b8)
3 months ago
Victor Julien 97e774bd6c detect/analyzer: log firewall lte rule for prior states as well
(cherry picked from commit 6e037d9783)
3 months ago
Victor Julien 74c2233e22 detect/firewall: limit auto accept notation
Limit to accept:flow, accept:tx and accept:hook.

(cherry picked from commit 71a6a9a746)
3 months ago
Victor Julien 85f2685388 detect/firewall: implement initial state range support
Allow a single rule to accept a hook and the hooks prior to it.

Example:

        accept:flow tls:<client_hello_done ... \
                tls.sni; content:"suricata.io"; endswith;

This will evaluate the SNI at the client_hello_done hook, but will
act as if there is a `accept:hook tls:client_in_progress ...` as well.

Implementation is currently specific to this `<` operator. During
parsing the sig gets flagged for this case. During setup this has 3 main
effects:

1. prefilter is disabled as we need to eval this right at the first
   state (0)
2. for state 0 a non-PF "prefilter" engine is setup to make sure the
   rule is flagged for evaluation
3. In the Signature::app_inspect list a dummy inspect engine is
   registered per state before Signature::app_progress_hook

The matching logic is building on the stateful rule handling. The
stateful rule handling can now tell the inspection loop that a partial
match occured. For this rule type the partial match will act as a match
with action accept:hook.

Next app updates will then use the continue detection logic to continue
the stateful match. When that fully matches, the final actions are
applied, like accept:flow or accept:tx.

Ticket: #8472.
(cherry picked from commit 651afba883)
3 months ago
Victor Julien c82e5ddf01 detect/firewall: fix last for progress handling
In last_for_progress handling set accept only on packet if it was also
triggered on the last tx.

If there are more transactions, the accept can be set later (if policy
allows).

(cherry picked from commit f6dc772677)
3 months ago
Juliana Fajardini a68bc82dd0 detect/parse: convert Notice Log into Debug
(cherry picked from commit 6933602050)
3 months ago
Victor Julien a0382a9fdf qa: add script to test firewall bridge mode
(cherry picked from commit 1c66eec656)

Removed the bridge script as arp isn't supported in 8.0.x.
3 months ago
Juliana Fajardini 6f6d18492e exceptions: add dedicated flow drop reason
To better control stats counters.

(cherry picked from commit 8a8574b149)

Cherry-pick note: moved PKT_DROP_REASON_EP_FLOW_DROP to the last
non fw stop to keep the non-fw values the same.
3 months ago
Juliana Fajardini a261229aaf detect: add flow drop by firewall as drop reason
To track flow drops triggered by the firewall.
Add flow drop by firewall as drop reason.

As part of
Ticket #7699

(cherry picked from commit 312967f291)
3 months ago
Juliana Fajardini 680b54fa6f schema: expand stats.ips.replaced explanation
As this is a less obvious counter.

(cherry picked from commit 0acb136b40)
3 months ago
Juliana Fajardini d950432d2e docs: add firewall stats doc
Related to
Ticket #7699

(cherry picked from commit 234172a93c)
3 months ago
Juliana Fajardini e3a6f29836 detect/firewall: add dedicated stats counters
Add a `firewall` stats counter aggregator for all firewall-related
stats.
De-overload "detect.alert_queue_overflow", by adding
"firewall.discarded_alerts" to account for discarded drops in
Firewall mode.
Add Debug statements for tracking corner cases where it can be
difficult to know where a drop is coming from.

Added counters:
- stats.firewall.blocked
- stats.firewall.accepted
- stats.firewall.rejected
- stats.firewall.drop_reason.default_app_policy
- stats.firewall.drop_reason.default_packet_policy
- stats.firewall.drop_reason.flow_drop
- stats.firewall.drop_reason.pre_flow_hook
- stats.firewall.drop_reason.pre_stream_hook
- stats.firewall.drop_reason.rules
- stats.firewall.discarded_alerts

Ticket #7699

(cherry picked from commit 5b488feef5)

Cherry-pick notes:

- moved counter to keep struct layout the same as much as possible.
- moved the FLOW_ACTION_BY_FIREWALL to aux_flags and renamed to
  FLOW_AUX_ACTION_BY_FIREWALL
3 months ago
Victor Julien b7b9720503 flow: add aux flags
Flow::flags field ran out of space, and for ABI compatibility the move
to u64 like in main isn't possible. So add a `aux_flags` field in an
alignment hole to facilitate the coming flags.
3 months ago
Juliana Fajardini 1664b0960e docs/configuration: add firewall mode settings
Partly related to
Ticket #7699

(cherry picked from commit 32d89072d2)
3 months ago
Victor Julien 314dce88d9 detect/tx: minor debug additions and fixes
(cherry picked from commit 367ca7f430)
3 months ago
Victor Julien bac8ebf225 firewall/analyzer: include all hooks
For protocols using default 0-1 states, add support.

For others, print 'unknown' if no name is yet supported.

Ticket: #8514.
(cherry picked from commit b29226c7ea)
3 months ago
Victor Julien 017a28b6ac detect/analyzer: log actual policy for app firewall
(cherry picked from commit f7c44c4c23)
3 months ago
Victor Julien 1444de0eb4 detect/firewall: configurable default policies
Allow configurable policies, including accept. For app-layer this
requires looping all available hooks to apply the policies.

Support configurable policies for packet-filter, pre-stream, pre-flow.

If there are no rules there is also no rule group (sgh). Make sure
the app hooks policies are correctly handled in this case by allowing
a NULL sgh to be handled as well.

For tx rule match actually apply drop directly. Previously this was
always handled by the default drop:flow policy.

Ticket: #7701.
(cherry picked from commit 7134592fea)

Cherry-pick note: moved the DetectEngineCtx member to the end of the
struct to keep the struct layout the same.
3 months ago
Victor Julien 1fb2f0bfa3 firewall: support multi-action statements in rules
For firewall rules, allow multiple actions to be specified in a list

        accept:flow,pass:flow,alert
        accept:flow,alert
        accept:flow,pass:flow

It is mandatory to make the first action the primary firewall policy
action: accept, drop, reject.

Ticket: #8480.
(cherry picked from commit e76728a536)
3 months ago
Victor Julien c17728c5e7 firewall: accept:flow no longer implies pass:flow
Previously a `accept:flow` action would act as both a firewall "accept" and
a threat detection "pass" for the rest of the flow.

This patch changes that. The `accept:flow` action now only accepts the
rest of the packets for the firewall ruleset, but does still continue
threat detection rule evaluation.

Ticket: #8444.
(cherry picked from commit eaacb41aaf)
3 months ago