.. |
Makefile.am
|
Add the makefile.am addition that I forgot to add in the previous commit for http_raw_header
|
14 years ago |
action-globals.h
|
…
|
|
alert-debuglog.c
|
support for stats.log configurable and fixed timezone issue in faslog and debuglog
|
14 years ago |
alert-debuglog.h
|
…
|
|
alert-fastlog.c
|
Fix compiler warnings, cleanup counters config code.
|
14 years ago |
alert-fastlog.h
|
…
|
|
alert-prelude.c
|
…
|
|
alert-prelude.h
|
…
|
|
alert-unified-alert.c
|
…
|
|
alert-unified-alert.h
|
…
|
|
alert-unified-log.c
|
Tag engine improvements. Output tags only on unified format. Added atomic counter for tagged hosts/sessions
|
15 years ago |
alert-unified-log.h
|
…
|
|
alert-unified2-alert.c
|
Tag engine improvements. Output tags only on unified format. Added atomic counter for tagged hosts/sessions
|
15 years ago |
alert-unified2-alert.h
|
…
|
|
app-layer-dcerpc-common.h
|
Store the first frag flag in the uuid as the pfc_flags field is overwritten. Part of fixing #206.
|
15 years ago |
app-layer-dcerpc-udp.c
|
Better handle low memory conditions.
|
15 years ago |
app-layer-dcerpc-udp.h
|
…
|
|
app-layer-dcerpc.c
|
Store the first frag flag in the uuid as the pfc_flags field is overwritten. Part of fixing #206.
|
15 years ago |
app-layer-dcerpc.h
|
…
|
|
app-layer-detect-proto.c
|
Many small performance updates.
|
15 years ago |
app-layer-detect-proto.h
|
…
|
|
app-layer-ftp.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
app-layer-ftp.h
|
Many small performance updates.
|
15 years ago |
app-layer-htp.c
|
Fix potential null deref (introduced a few commits ago) found by clang.
|
14 years ago |
app-layer-htp.h
|
Remove dead pcre code.
|
14 years ago |
app-layer-nbss.h
|
…
|
|
app-layer-parser.c
|
…
|
|
app-layer-parser.h
|
Many small performance updates.
|
15 years ago |
app-layer-protos.h
|
…
|
|
app-layer-smb.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
app-layer-smb.h
|
Many small performance updates.
|
15 years ago |
app-layer-smb2.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
app-layer-smb2.h
|
…
|
|
app-layer-ssh.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
app-layer-ssh.h
|
Many small performance updates.
|
15 years ago |
app-layer-ssl.c
|
Comment out broken SSLParserTest03 test.
|
15 years ago |
app-layer-ssl.h
|
Many small performance updates.
|
15 years ago |
app-layer-tls.c
|
…
|
|
app-layer-tls.h
|
Many small performance updates.
|
15 years ago |
app-layer.c
|
Don't stop stream reassembly if protocol detection failed, only stop/prevent app layer parsing.
|
14 years ago |
app-layer.h
|
…
|
|
conf-yaml-loader.c
|
…
|
|
conf-yaml-loader.h
|
define a new conf paramter detect-engine:inspection-recursion-limit; Defines a recursion limit for content inspection code
|
15 years ago |
conf.c
|
…
|
|
conf.h
|
…
|
|
counters.c
|
Fix compiler warning in log-httplog.c & change stats.log to log as mm/dd/yyyy as well.
|
14 years ago |
counters.h
|
…
|
|
cuda-packet-batcher.c
|
cuda-packet-batcher timeout supports float values
|
14 years ago |
cuda-packet-batcher.h
|
make cuda mpm parameters configurable
|
14 years ago |
data-queue.c
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
data-queue.h
|
Many small performance updates.
|
15 years ago |
debug.h
|
…
|
|
decode-ethernet.c
|
…
|
|
decode-ethernet.h
|
…
|
|
decode-events.h
|
…
|
|
decode-gre.c
|
Better handle low memory conditions.
|
15 years ago |
decode-gre.h
|
…
|
|
decode-icmpv4.c
|
…
|
|
decode-icmpv4.h
|
…
|
|
decode-icmpv6.c
|
…
|
|
decode-icmpv6.h
|
…
|
|
decode-ipv4.c
|
Better handle low memory conditions.
|
15 years ago |
decode-ipv4.h
|
…
|
|
decode-ipv6.c
|
…
|
|
decode-ipv6.h
|
…
|
|
decode-ppp.c
|
…
|
|
decode-ppp.h
|
…
|
|
decode-pppoe.c
|
…
|
|
decode-pppoe.h
|
…
|
|
decode-raw.c
|
…
|
|
decode-raw.h
|
…
|
|
decode-sll.c
|
…
|
|
decode-sll.h
|
…
|
|
decode-tcp.c
|
Many small performance updates.
|
15 years ago |
decode-tcp.h
|
fix csum handling for tcp/dup
|
15 years ago |
decode-udp.c
|
…
|
|
decode-udp.h
|
fix csum handling for tcp/dup
|
15 years ago |
decode-vlan.c
|
…
|
|
decode-vlan.h
|
…
|
|
decode.c
|
Disable per second counters as they are unreliable.
|
15 years ago |
decode.h
|
Support for reference.config file
|
15 years ago |
defrag.c
|
…
|
|
defrag.h
|
…
|
|
detect-ack.c
|
Fix unittests after ip_proto keyword change.
|
15 years ago |
detect-ack.h
|
…
|
|
detect-asn1.c
|
Fix valgrind ctx error on asn1 test 06
|
15 years ago |
detect-asn1.h
|
…
|
|
detect-bytejump.c
|
unifying content structure - uricontent now uses DetectContentData
|
14 years ago |
detect-bytejump.h
|
…
|
|
detect-bytetest.c
|
unifying content structure - uricontent now uses DetectContentData
|
14 years ago |
detect-bytetest.h
|
add the support for >= and <= operator for byte_test
|
15 years ago |
detect-classtype.c
|
…
|
|
detect-classtype.h
|
…
|
|
detect-content.c
|
replace all Signature->dmatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_DMATCH]
|
14 years ago |
detect-content.h
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-csum.c
|
replace all sm lists (match, pmatch, dmatch, umatch, amatch, tmatch) with an array Signature->sm_lists[]. Replace all Signature->match instances in the engine with Signature->sm_lists[DETECT_SM_LIST_MATCH]
|
14 years ago |
detect-csum.h
|
…
|
|
detect-dce-iface.c
|
replace all Signature->amatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_AMATCH]
|
14 years ago |
detect-dce-iface.h
|
…
|
|
detect-dce-opnum.c
|
replace all Signature->amatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_AMATCH]
|
14 years ago |
detect-dce-opnum.h
|
…
|
|
detect-dce-stub-data.c
|
replace all Signature->amatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_AMATCH]
|
14 years ago |
detect-dce-stub-data.h
|
…
|
|
detect-decode-event.c
|
Make sure decoder event rules are inspected even if the packet is invalid and has no addesses or proto. Update fast log and alert debug log to display the alerts. Fixes #179.
|
15 years ago |
detect-decode-event.h
|
…
|
|
detect-depth.c
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-depth.h
|
…
|
|
detect-detection-filter.c
|
replace all sm lists (match, pmatch, dmatch, umatch, amatch, tmatch) with an array Signature->sm_lists[]. Replace all Signature->match instances in the engine with Signature->sm_lists[DETECT_SM_LIST_MATCH]
|
14 years ago |
detect-detection-filter.h
|
…
|
|
detect-distance.c
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-distance.h
|
…
|
|
detect-dsize.c
|
Make sure we inspect all outstanding reassembled stream chunks (smsg) if the stream is shutting down. Make sure to do inspect signatures that use dsize against the tcp packet payload, even if that payload was already added to the stream. Likewise, the dsize signatures are not inspected against the reassembled stream.
|
15 years ago |
detect-dsize.h
|
…
|
|
detect-engine-address-ipv4.c
|
Use Address structure in DetectAddress struct.
|
15 years ago |
detect-engine-address-ipv4.h
|
…
|
|
detect-engine-address-ipv6.c
|
Use Address structure in DetectAddress struct.
|
15 years ago |
detect-engine-address-ipv6.h
|
Use Address structure in DetectAddress struct.
|
15 years ago |
detect-engine-address.c
|
Make signature address matching more cache efficient.
|
15 years ago |
detect-engine-address.h
|
Make signature address matching more cache efficient.
|
15 years ago |
detect-engine-alert.c
|
replace all Signature->tmatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_TMATCH]
|
14 years ago |
detect-engine-alert.h
|
Drop streams on inline mode when a drop rule match from a reassembled stream and/or app layer inspection
|
15 years ago |
detect-engine-dcepayload.c
|
replace all Signature->dmatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_DMATCH]
|
14 years ago |
detect-engine-dcepayload.h
|
…
|
|
detect-engine-hcbd.c
|
Change the way the request body limit is enforced.
|
14 years ago |
detect-engine-hcbd.h
|
Change locking of http_header, http_raw_header and http_client_body so that flow isn't accessed without lock anywhere.
|
14 years ago |
detect-engine-hhd.c
|
support relative pcre for http header. All pcre processing for http header moved to hhd engine
|
14 years ago |
detect-engine-hhd.h
|
Change locking of http_header, http_raw_header and http_client_body so that flow isn't accessed without lock anywhere.
|
14 years ago |
detect-engine-hrhd.c
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-engine-hrhd.h
|
don't buffer raw headers. Retrieve them individually from htp_state during mpm stage and content valiadation stage
|
14 years ago |
detect-engine-iponly.c
|
Drop streams on inline mode when a drop rule match from a reassembled stream and/or app layer inspection
|
15 years ago |
detect-engine-iponly.h
|
…
|
|
detect-engine-mpm.c
|
Clean up signature flags creating room for merging flags and mpm_flags. Merge flags and mpm_flags. Move new mpm id's into signature header. Get rid of full signature access in signature prefiltering.
|
14 years ago |
detect-engine-mpm.h
|
adapt fast pattern engine analysis to reflect the new changes made to your mpm design
|
14 years ago |
detect-engine-payload.c
|
remove support for skipping reinspecting fast pattern contents once again during packet payload inspection. Also make some changes to our detection engine
|
14 years ago |
detect-engine-payload.h
|
…
|
|
detect-engine-port.c
|
…
|
|
detect-engine-port.h
|
…
|
|
detect-engine-proto.c
|
Many small performance updates.
|
15 years ago |
detect-engine-proto.h
|
…
|
|
detect-engine-siggroup.c
|
Clean up signature flags creating room for merging flags and mpm_flags. Merge flags and mpm_flags. Move new mpm id's into signature header. Get rid of full signature access in signature prefiltering.
|
14 years ago |
detect-engine-siggroup.h
|
…
|
|
detect-engine-sigorder.c
|
fix sig ordering bugs. Flowvars and pktvars user type retrieval should be from pmatch list, as well as from match list. Also fix lousy unit tests
|
14 years ago |
detect-engine-sigorder.h
|
…
|
|
detect-engine-state.c
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-engine-state.h
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-engine-tag.c
|
Tag engine improvements. Output tags only on unified format. Added atomic counter for tagged hosts/sessions
|
15 years ago |
detect-engine-tag.h
|
Adding tag keyword support
|
15 years ago |
detect-engine-threshold.c
|
replace all sm lists (match, pmatch, dmatch, umatch, amatch, tmatch) with an array Signature->sm_lists[]. Replace all Signature->match instances in the engine with Signature->sm_lists[DETECT_SM_LIST_MATCH]
|
14 years ago |
detect-engine-threshold.h
|
…
|
|
detect-engine-uri.c
|
Manually add unittest by Pablo Rincon from bug #210.
|
14 years ago |
detect-engine-uri.h
|
add pcre with U modifiers to the umatch sigmatch list. fix for bug 155
|
15 years ago |
detect-engine.c
|
Change the way the request body limit is enforced.
|
14 years ago |
detect-engine.h
|
define a new conf paramter detect-engine:inspection-recursion-limit; Defines a recursion limit for content inspection code
|
15 years ago |
detect-fast-pattern.c
|
modify detection engine to carry out uri mpm run before build match array if alproto is http and if sgh has atleast one sig with uri mpm set
|
14 years ago |
detect-fast-pattern.h
|
make some name changes. break PopulateMpm(). Set the avoid mpm double check flags
|
14 years ago |
detect-flags.c
|
…
|
|
detect-flags.h
|
…
|
|
detect-flow.c
|
…
|
|
detect-flow.h
|
…
|
|
detect-flowbits.c
|
Fix FlowBitsTestSig06 test no longer working properly.
|
14 years ago |
detect-flowbits.h
|
Fix for bug 204 (signature ordering with flowbit priority)
|
15 years ago |
detect-flowint.c
|
flowbits, flowvars, pktvars, flow flags and app layer info added to alert-debug.log
|
15 years ago |
detect-flowint.h
|
…
|
|
detect-flowvar.c
|
flowbits, flowvars, pktvars, flow flags and app layer info added to alert-debug.log
|
15 years ago |
detect-flowvar.h
|
…
|
|
detect-fragbits.c
|
…
|
|
detect-fragbits.h
|
…
|
|
detect-fragoffset.c
|
…
|
|
detect-fragoffset.h
|
…
|
|
detect-ftpbounce.c
|
replace all Signature->amatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_AMATCH]
|
14 years ago |
detect-ftpbounce.h
|
…
|
|
detect-gid.c
|
…
|
|
detect-gid.h
|
…
|
|
detect-http-client-body.c
|
support relative pcre for client body. All pcre processing for client body moved to hcbd engine
|
14 years ago |
detect-http-client-body.h
|
unifying content structure - http_client_body now uses DetectContentData
|
14 years ago |
detect-http-cookie.c
|
unifying content structure - http_cookie now uses DetectContentData
|
14 years ago |
detect-http-cookie.h
|
unifying content structure - http_cookie now uses DetectContentData
|
14 years ago |
detect-http-header.c
|
support relative pcre for http header. All pcre processing for http header moved to hhd engine
|
14 years ago |
detect-http-header.h
|
unifying content structure - http_header now uses DetectContentData
|
14 years ago |
detect-http-method.c
|
unifying content structure - http_method now uses DetectContentData
|
14 years ago |
detect-http-method.h
|
unifying content structure - http_method now uses DetectContentData
|
14 years ago |
detect-http-raw-header.c
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-http-raw-header.h
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-http-stat-code.c
|
fix code after fresh rebase. change some pmatch and amatch lists to sm_lists[] format
|
14 years ago |
detect-http-stat-code.h
|
Cleanup http_stat_code unittests, shrink data structure.
|
15 years ago |
detect-http-stat-msg.c
|
unifying content structure - http_stat_msg now uses DetectContentData
|
14 years ago |
detect-http-stat-msg.h
|
unifying content structure - http_stat_msg now uses DetectContentData
|
14 years ago |
detect-http-uri.c
|
allow sigs for http uri of the form content:one; content:two; distance:0; http_uri;
|
14 years ago |
detect-http-uri.h
|
…
|
|
detect-icmp-id.c
|
Fix -Wall -Werror compilation after unittests update.
|
15 years ago |
detect-icmp-id.h
|
…
|
|
detect-icmp-seq.c
|
Fix -Wall -Werror compilation after unittests update.
|
15 years ago |
detect-icmp-seq.h
|
…
|
|
detect-icode.c
|
Fix -Wall -Werror compilation after unittests update.
|
15 years ago |
detect-icode.h
|
…
|
|
detect-id.c
|
…
|
|
detect-id.h
|
…
|
|
detect-ipopts.c
|
…
|
|
detect-ipopts.h
|
…
|
|
detect-ipproto.c
|
…
|
|
detect-ipproto.h
|
…
|
|
detect-isdataat.c
|
unifying content structure - uricontent now uses DetectContentData
|
14 years ago |
detect-isdataat.h
|
…
|
|
detect-itype.c
|
Fix -Wall -Werror compilation after unittests update.
|
15 years ago |
detect-itype.h
|
…
|
|
detect-metadata.c
|
…
|
|
detect-metadata.h
|
…
|
|
detect-msg.c
|
…
|
|
detect-msg.h
|
…
|
|
detect-noalert.c
|
…
|
|
detect-noalert.h
|
…
|
|
detect-nocase.c
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-nocase.h
|
…
|
|
detect-offset.c
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
detect-offset.h
|
…
|
|
detect-parse.c
|
support relative pcre for client body. All pcre processing for client body moved to hcbd engine
|
14 years ago |
detect-parse.h
|
support relative pcre for client body. All pcre processing for client body moved to hcbd engine
|
14 years ago |
detect-pcre.c
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-pcre.h
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-pktvar.c
|
…
|
|
detect-pktvar.h
|
…
|
|
detect-priority.c
|
…
|
|
detect-priority.h
|
…
|
|
detect-rawbytes.c
|
replace all Signature->pmatch instances in the engine with Signature->sm_lists[DETECT_SM_LIST_PMATCH]
|
14 years ago |
detect-rawbytes.h
|
…
|
|
detect-recursive.c
|
…
|
|
detect-recursive.h
|
…
|
|
detect-reference.c
|
Support for reference.config file
|
15 years ago |
detect-reference.h
|
Support for reference.config file
|
15 years ago |
detect-rev.c
|
…
|
|
detect-rev.h
|
…
|
|
detect-rpc.c
|
Fix -Wall -Werror compilation after unittests update.
|
15 years ago |
detect-rpc.h
|
…
|
|
detect-sameip.c
|
Fix unittests after ip_proto keyword change.
|
15 years ago |
detect-sameip.h
|
…
|
|
detect-seq.c
|
More thoroughly cleanup a Packet when we recycle it. Fixes a corner case where we'd have a invalid tcp packet but p->proto would still say IPPROTO_TCP because of a previous run. Fixes bug #187.
|
15 years ago |
detect-seq.h
|
…
|
|
detect-sid.c
|
…
|
|
detect-sid.h
|
…
|
|
detect-ssh-proto-version.c
|
Many small performance updates.
|
15 years ago |
detect-ssh-proto-version.h
|
Adding ssh app layer module with two new keywords: ssh.protoversion and ssh.softwareversion
|
15 years ago |
detect-ssh-software-version.c
|
Many small performance updates.
|
15 years ago |
detect-ssh-software-version.h
|
Adding ssh app layer module with two new keywords: ssh.protoversion and ssh.softwareversion
|
15 years ago |
detect-stream_size.c
|
…
|
|
detect-stream_size.h
|
…
|
|
detect-tag.c
|
Tag engine improvements. Output tags only on unified format. Added atomic counter for tagged hosts/sessions
|
15 years ago |
detect-tag.h
|
Fixing flow cleanup and ctx initialization
|
15 years ago |
detect-threshold.c
|
replace all sm lists (match, pmatch, dmatch, umatch, amatch, tmatch) with an array Signature->sm_lists[]. Replace all Signature->match instances in the engine with Signature->sm_lists[DETECT_SM_LIST_MATCH]
|
14 years ago |
detect-threshold.h
|
…
|
|
detect-tls-version.c
|
Many small performance updates.
|
15 years ago |
detect-tls-version.h
|
…
|
|
detect-ttl.c
|
…
|
|
detect-ttl.h
|
…
|
|
detect-uricontent.c
|
modify detection engine to run hhd mpm before building the match array
|
14 years ago |
detect-uricontent.h
|
unifying content structure - uricontent now uses DetectContentData
|
14 years ago |
detect-urilen.c
|
Many small performance updates.
|
15 years ago |
detect-urilen.h
|
Moving urilen inspection to detect-engine-uri. Adding unittests for pcre /U and urilen, in combination with uricontent
|
15 years ago |
detect-window.c
|
…
|
|
detect-window.h
|
…
|
|
detect-within.c
|
support /D option for pcre - http raw header. Also support relative pcre for http raw header. All pcre processing for http header moved to hrhd engine
|
14 years ago |
detect-within.h
|
…
|
|
detect.c
|
Clean up output.
|
14 years ago |
detect.h
|
Remove flowbits as a mask prefilter as they are dynamic. Add a dynamic check.
|
14 years ago |
flow-alert-sid.c
|
…
|
|
flow-alert-sid.h
|
…
|
|
flow-bit.c
|
…
|
|
flow-bit.h
|
…
|
|
flow-hash.c
|
Fix segv conditions caused by broken flow cleanup code.
|
15 years ago |
flow-hash.h
|
…
|
|
flow-private.h
|
…
|
|
flow-queue.c
|
…
|
|
flow-queue.h
|
Many small performance updates.
|
15 years ago |
flow-util.c
|
…
|
|
flow-util.h
|
Fix segv conditions caused by broken flow cleanup code.
|
15 years ago |
flow-var.c
|
…
|
|
flow-var.h
|
…
|
|
flow.c
|
Many small performance updates.
|
15 years ago |
flow.h
|
Many small performance updates.
|
15 years ago |
host.c
|
…
|
|
host.h
|
…
|
|
log-httplog.c
|
Fix compiler warning in log-httplog.c & change stats.log to log as mm/dd/yyyy as well.
|
14 years ago |
log-httplog.h
|
…
|
|
output.c
|
Clean up output.
|
14 years ago |
output.h
|
…
|
|
packet-queue.c
|
Attempt to work around NULL packets we're seeing ending up in queues when the compiler has optimized our code.
|
15 years ago |
packet-queue.h
|
…
|
|
pkt-var.c
|
…
|
|
pkt-var.h
|
…
|
|
queue.h
|
…
|
|
reputation.c
|
Fix compiler warning about incomplete prototype (2).
|
15 years ago |
reputation.h
|
Fix compiler warning about incomplete prototype (2).
|
15 years ago |
respond-reject-libnet11.c
|
…
|
|
respond-reject-libnet11.h
|
…
|
|
respond-reject.c
|
…
|
|
respond-reject.h
|
…
|
|
runmodes.c
|
Clean up output.
|
14 years ago |
runmodes.h
|
…
|
|
source-erf-dag.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-erf-dag.h
|
…
|
|
source-erf-file.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-erf-file.h
|
…
|
|
source-ipfw.c
|
PacketQueue postp added to TmEcodes for ipfw and pf_ring to silence compiler warnings
|
15 years ago |
source-ipfw.h
|
…
|
|
source-nfq-prototypes.h
|
…
|
|
source-nfq.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-nfq.h
|
…
|
|
source-pcap-file.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-pcap-file.h
|
…
|
|
source-pcap.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-pcap.h
|
…
|
|
source-pfring.c
|
Disable adding to unregistered mbit/s counter.
|
14 years ago |
source-pfring.h
|
…
|
|
stream-tcp-private.h
|
Remove unused stream flag.
|
14 years ago |
stream-tcp-reassemble.c
|
added the counter for tcp.segment_memcap_drop to show the dropped segments count due to memory limit
|
15 years ago |
stream-tcp-reassemble.h
|
added the counter for tcp.segment_memcap_drop to show the dropped segments count due to memory limit
|
15 years ago |
stream-tcp.c
|
Remove unused stream flag.
|
14 years ago |
stream-tcp.h
|
support for several tcp evasion attacks. Thanks to Judy Novak and G2 Inc for reporting them
|
15 years ago |
stream.c
|
Don't scan TCP packet payload if it was added to the stream. Inspect the tcp stream with the correct packet. Should fix #184 and #185.
|
15 years ago |
stream.h
|
Don't scan TCP packet payload if it was added to the stream. Inspect the tcp stream with the correct packet. Should fix #184 and #185.
|
15 years ago |
suricata-common.h
|
always read config.h header file first
|
14 years ago |
suricata.c
|
adapt fast pattern engine analysis to reflect the new changes made to your mpm design
|
14 years ago |
suricata.h
|
renintroduce g_u8_lowercase_table for b2g cuda
|
14 years ago |
threads.c
|
Adding atomic bitwise operations api and rwlocks support
|
15 years ago |
threads.h
|
Adding atomic bitwise operations api and rwlocks support
|
15 years ago |
threadvars.h
|
Fix TmThreadsUnsetFlag not unsetting flag if __sync_fetch_and_nand was used.
|
15 years ago |
tm-modules.c
|
…
|
|
tm-modules.h
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
tm-queuehandlers.c
|
…
|
|
tm-queuehandlers.h
|
…
|
|
tm-queues.c
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
tm-queues.h
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
tm-threads.c
|
Sleep after checking for a thread flag in TmThreadWaitOnThreadInit now that the check is so much cheaper.
|
15 years ago |
tm-threads.h
|
Fix cuda compilation.
|
15 years ago |
tmqh-flow.c
|
…
|
|
tmqh-flow.h
|
…
|
|
tmqh-nfq.c
|
…
|
|
tmqh-nfq.h
|
…
|
|
tmqh-packetpool.c
|
Make malloc errors on initialization stage a fatal error, resulting on a exit() call
|
15 years ago |
tmqh-packetpool.h
|
…
|
|
tmqh-ringbuffer.c
|
Make malloc errors on initialization stage a fatal error, resulting on a exit() call
|
15 years ago |
tmqh-ringbuffer.h
|
…
|
|
tmqh-simple.c
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
tmqh-simple.h
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
util-action.c
|
…
|
|
util-action.h
|
…
|
|
util-atomic.h
|
Adding atomic bitwise operations api and rwlocks support
|
15 years ago |
util-binsearch.c
|
…
|
|
util-binsearch.h
|
…
|
|
util-bloomfilter-counting.c
|
…
|
|
util-bloomfilter-counting.h
|
…
|
|
util-bloomfilter.c
|
…
|
|
util-bloomfilter.h
|
Change BloomFilter structure layout to reflect order of access.
|
15 years ago |
util-byte.c
|
…
|
|
util-byte.h
|
…
|
|
util-cidr.c
|
…
|
|
util-cidr.h
|
…
|
|
util-classification-config.c
|
…
|
|
util-classification-config.h
|
…
|
|
util-clock.h
|
…
|
|
util-cpu.c
|
Clean up output.
|
14 years ago |
util-cpu.h
|
…
|
|
util-cuda-handlers.c
|
cuda handlers support multiple CUmodules per context
|
14 years ago |
util-cuda-handlers.h
|
cuda handlers support multiple CUmodules per context
|
14 years ago |
util-cuda.c
|
add --list-cuda-cards option to list the cuda cards on the system. Add conf parameter to select the cuda device to use. Also change the threshhold limit to 2.4k packets to buffer
|
15 years ago |
util-cuda.h
|
add --list-cuda-cards option to list the cuda cards on the system. Add conf parameter to select the cuda device to use. Also change the threshhold limit to 2.4k packets to buffer
|
15 years ago |
util-daemon.c
|
…
|
|
util-daemon.h
|
…
|
|
util-debug-filters.c
|
…
|
|
util-debug-filters.h
|
…
|
|
util-debug.c
|
always read config.h header file first
|
14 years ago |
util-debug.h
|
…
|
|
util-decode-asn1.c
|
Fix asn1 decoder frame oob mem. Adding max stack frames to suricata.yaml
|
15 years ago |
util-decode-asn1.h
|
Fix asn1 decoder frame oob mem. Adding max stack frames to suricata.yaml
|
15 years ago |
util-enum.c
|
…
|
|
util-enum.h
|
…
|
|
util-error.c
|
Support for reference.config file
|
15 years ago |
util-error.h
|
Print an error if the protocol field of a signature contains a unknown/invalid value.
|
15 years ago |
util-fix_checksum.c
|
…
|
|
util-fix_checksum.h
|
…
|
|
util-fmemopen.c
|
…
|
|
util-fmemopen.h
|
…
|
|
util-hash.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
util-hash.h
|
…
|
|
util-hashlist.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
util-hashlist.h
|
…
|
|
util-host-os-info.c
|
Make malloc errors on initialization stage a fatal error, resulting on a exit() call
|
15 years ago |
util-host-os-info.h
|
…
|
|
util-mem.h
|
Adapt malloc macro's to only display errors during init, not during runtime. At runtime it could make us crawl if the system runs out of memory.
|
15 years ago |
util-memcmp.c
|
Fix retval of SCMemcmp for non-SIMD implementation.
|
15 years ago |
util-memcmp.h
|
support fast pattern for http raw header. Also support relative modifiers for http raw header
|
14 years ago |
util-mpm-ac-gfbs.c
|
fix hash bug in ac-gfbs. Should reduce the no of patterns added for single context ac-gfbs from a million to a couple of thousands. Also support no case handling. \todo support insertion of final state presence into goto_table and failure table state transitions
|
15 years ago |
util-mpm-ac-gfbs.h
|
fix hash bug in ac-gfbs. Should reduce the no of patterns added for single context ac-gfbs from a million to a couple of thousands. Also support no case handling. \todo support insertion of final state presence into goto_table and failure table state transitions
|
15 years ago |
util-mpm-ac.c
|
support cases for ac, where we have a single pattern in 2 different sigs, but one that is case-senstive and the other not. Also remove duplicate pids from the output_table
|
15 years ago |
util-mpm-ac.h
|
support cases for ac, where we have a single pattern in 2 different sigs, but one that is case-senstive and the other not. Also remove duplicate pids from the output_table
|
15 years ago |
util-mpm-b2g-cuda-kernel.cu
|
batching of packets support for cuda b2g mpm. Supported for both 32 and 64 bit platforms
|
15 years ago |
util-mpm-b2g-cuda.c
|
renintroduce g_u8_lowercase_table for b2g cuda
|
14 years ago |
util-mpm-b2g-cuda.h
|
cuda streams support in b2g-cuda MPM
|
14 years ago |
util-mpm-b2g.c
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b2g.h
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b2gc.c
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b2gc.h
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b2gm.c
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b2gm.h
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b3g.c
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-b3g.h
|
Change mpm hash_size config setting highest to higher as highest wasn't the... highest. Max was higher. Leaving highest as an alias to higher for backwards compatibility.
|
15 years ago |
util-mpm-wumanber.c
|
Further improve B2gc. Add B2gm. Improve memory layout.
|
15 years ago |
util-mpm-wumanber.h
|
…
|
|
util-mpm.c
|
add some header files that we missed while rebasing
|
14 years ago |
util-mpm.h
|
cuda streams support in b2g-cuda MPM
|
14 years ago |
util-optimize.h
|
Further improve B2gc. Add B2gm. Improve memory layout.
|
15 years ago |
util-pidfile.c
|
…
|
|
util-pidfile.h
|
…
|
|
util-pool.c
|
…
|
|
util-pool.h
|
…
|
|
util-print.c
|
Make sure decoder event rules are inspected even if the packet is invalid and has no addesses or proto. Update fast log and alert debug log to display the alerts. Fixes #179.
|
15 years ago |
util-print.h
|
Make sure decoder event rules are inspected even if the packet is invalid and has no addesses or proto. Update fast log and alert debug log to display the alerts. Fixes #179.
|
15 years ago |
util-privs.c
|
…
|
|
util-privs.h
|
…
|
|
util-profiling.c
|
Add new profiling sort option, maxticks.
|
15 years ago |
util-profiling.h
|
…
|
|
util-proto-name.c
|
Fix a potential invalid memory read in the protocol name code used by alert-fastlog.
|
15 years ago |
util-proto-name.h
|
Fix a potential invalid memory read in the protocol name code used by alert-fastlog.
|
15 years ago |
util-radix-tree.c
|
Add memcmp api with a plain memcmp function and a SSE3 accelerated memcmp.
|
15 years ago |
util-radix-tree.h
|
Many small performance updates.
|
15 years ago |
util-random.c
|
…
|
|
util-random.h
|
…
|
|
util-reference-config.c
|
compilation fix missing UT ifdef wrapper in reference code
|
15 years ago |
util-reference-config.h
|
Support for reference.config file
|
15 years ago |
util-ringbuffer.c
|
Add unittests for ringbuffer.
|
15 years ago |
util-ringbuffer.h
|
Add unittests for ringbuffer.
|
15 years ago |
util-rule-vars.c
|
…
|
|
util-rule-vars.h
|
…
|
|
util-spm-bm.c
|
Make malloc errors on initialization stage a fatal error, resulting on a exit() call
|
15 years ago |
util-spm-bm.h
|
Make malloc errors on initialization stage a fatal error, resulting on a exit() call
|
15 years ago |
util-spm-bs.c
|
…
|
|
util-spm-bs.h
|
…
|
|
util-spm-bs2bm.c
|
…
|
|
util-spm-bs2bm.h
|
…
|
|
util-spm.c
|
…
|
|
util-spm.h
|
…
|
|
util-strlcatu.c
|
…
|
|
util-strlcpyu.c
|
…
|
|
util-threshold-config.c
|
Clean up output.
|
14 years ago |
util-threshold-config.h
|
…
|
|
util-time.c
|
…
|
|
util-time.h
|
…
|
|
util-unittest-helper.c
|
Small layout update
|
15 years ago |
util-unittest-helper.h
|
…
|
|
util-unittest.c
|
…
|
|
util-unittest.h
|
…
|
|
util-validate.h
|
Add missing util-validate.h
|
15 years ago |
util-var-name.c
|
flowbits, flowvars, pktvars, flow flags and app layer info added to alert-debug.log
|
15 years ago |
util-var-name.h
|
flowbits, flowvars, pktvars, flow flags and app layer info added to alert-debug.log
|
15 years ago |
util-var.c
|
…
|
|
util-var.h
|
…
|
|
win32-misc.c
|
…
|
|
win32-misc.h
|
…
|
|
win32-service.c
|
…
|
|
win32-service.h
|
…
|
|
win32-syslog.h
|
…
|
|