-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
detect-flowbits: adding details for flowbits v5 #9971
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -45,6 +45,8 @@ | |
#include "util-time.h" | ||
#include "util-validate.h" | ||
#include "util-conf.h" | ||
#include "detect-flowbits.h" | ||
#include "util-var-name.h" | ||
|
||
static int rule_warnings_only = 0; | ||
|
||
|
@@ -861,6 +863,45 @@ static void DumpMatches(RuleAnalyzer *ctx, JsonBuilder *js, const SigMatchData * | |
jb_close(js); | ||
break; | ||
} | ||
case DETECT_FLOWBITS: { | ||
const DetectFlowbitsData *cd = (const DetectFlowbitsData *)smd->ctx; | ||
|
||
jb_open_object(js, "flowbits"); | ||
switch (cd->cmd) { | ||
case DETECT_FLOWBITS_CMD_NOALERT: | ||
jb_set_string(js, "action", "noalert"); | ||
// jb_set_string(js,"name", NULL); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Please remove the commented our line There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. yep, don't know how I missed that. I'll remove it right away. |
||
break; | ||
case DETECT_FLOWBITS_CMD_ISSET: | ||
jb_set_string(js, "cmd", "isset"); | ||
break; | ||
case DETECT_FLOWBITS_CMD_ISNOTSET: | ||
jb_set_string(js, "cmd", "isnotset"); | ||
break; | ||
case DETECT_FLOWBITS_CMD_SET: | ||
jb_set_string(js, "cmd", "set"); | ||
break; | ||
case DETECT_FLOWBITS_CMD_UNSET: | ||
jb_set_string(js, "cmd", "unset"); | ||
break; | ||
case DETECT_FLOWBITS_CMD_TOGGLE: | ||
jb_set_string(js, "cmd", "toggle"); | ||
break; | ||
} | ||
jb_open_array(js, "names"); | ||
if (cd->or_list_size == 0) { | ||
jb_append_string(js, VarNameStoreSetupLookup(cd->idx, VAR_TYPE_FLOW_BIT)); | ||
} else if (cd->or_list_size > 0) { | ||
for (uint8_t i = 0; i < cd->or_list_size; i++) { | ||
const char *varname = | ||
VarNameStoreSetupLookup(cd->or_list[i], VAR_TYPE_FLOW_BIT); | ||
jb_append_string(js, varname); | ||
} | ||
} | ||
jb_close(js); // array | ||
Comment on lines
+891
to
+901
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Considering that for There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. (btw, my guess is that that's what's causing the last check in the SV test to fail. this double close when nothing was added to the json object is leading to suricata not having the json object with the flowbits info, in the |
||
jb_close(js); // object | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Considering the discussion here - #9691 (comment) -, we are missing the There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. For this, I was thinking about creating an operator array that stores "or" if it encounters '|' in the the list, but I'm not sure on how to store "and" yet. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'd say skip and for now, multiple flowbit objs in the output for a rule for the same |
||
break; | ||
} | ||
} | ||
jb_close(js); | ||
|
||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Leftover? :P
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah, I must have missed the commented out code. Sorry!