mirror of https://github.com/OISF/suricata
parent
262abbb49f
commit
4f8e1f59a6
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@ -1,110 +0,0 @@
|
||||
/* Copyright (C) 2007-2014 Open Information Security Foundation
|
||||
*
|
||||
* You can copy, redistribute or modify this Program under the terms of
|
||||
* the GNU General Public License version 2 as published by the Free
|
||||
* Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* version 2 along with this program; if not, write to the Free Software
|
||||
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
||||
* 02110-1301, USA.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* \author Anoop Saldanha <anoopsaldanha@gmail.com>
|
||||
*
|
||||
*/
|
||||
|
||||
#define SC_AC_GFBS_STATE_TYPE_U16 uint16_t
|
||||
#define SC_AC_GFBS_STATE_TYPE_U32 uint32_t
|
||||
|
||||
typedef struct SCACGfbsPattern_ {
|
||||
/* length of the pattern */
|
||||
uint16_t len;
|
||||
/* flags decribing the pattern */
|
||||
uint8_t flags;
|
||||
/* holds the original pattern that was added */
|
||||
uint8_t *original_pat;
|
||||
/* case sensitive */
|
||||
uint8_t *cs;
|
||||
/* case INsensitive */
|
||||
uint8_t *ci;
|
||||
/* pattern id */
|
||||
uint32_t id;
|
||||
|
||||
/* sid(s) for this pattern */
|
||||
uint32_t sids_size;
|
||||
SigIntId *sids;
|
||||
|
||||
struct SCACGfbsPattern_ *next;
|
||||
} SCACGfbsPattern;
|
||||
|
||||
typedef struct SCACGfbsPatternList_ {
|
||||
uint8_t *cs;
|
||||
uint16_t patlen;
|
||||
|
||||
/* sid(s) for this pattern */
|
||||
uint32_t sids_size;
|
||||
SigIntId *sids;
|
||||
} SCACGfbsPatternList;
|
||||
|
||||
typedef struct SCACGfbsOutputTable_ {
|
||||
/* list of pattern sids */
|
||||
uint32_t *pids;
|
||||
/* no of entries we have in pids */
|
||||
uint32_t no_of_entries;
|
||||
} SCACGfbsOutputTable;
|
||||
|
||||
typedef struct SCACGfbsGotoTableMod_ {
|
||||
/* each of these below declarations will be of type uint32_t, if the state
|
||||
* count exceeds 65535, the maximum value a 16 bit unsigned var can hold */
|
||||
|
||||
/* no of entries stored below */
|
||||
uint16_t no_of_entries;
|
||||
|
||||
/* the ascii codes over which we have state transitions */
|
||||
uint16_t *ascii_codes;
|
||||
/* the states that correspond to the ascii_codes above */
|
||||
uint16_t *states;
|
||||
} SCACGfbsGotoTableMod_;
|
||||
|
||||
typedef struct SCACGfbsCtx_ {
|
||||
/* hash used during ctx initialization */
|
||||
SCACGfbsPattern **init_hash;
|
||||
|
||||
/* pattern arrays. We need this only during the goto table creation phase */
|
||||
SCACGfbsPattern **parray;
|
||||
|
||||
/* no of states used by ac */
|
||||
int32_t state_count;
|
||||
/* the modified goto_table */
|
||||
uint8_t *goto_table_mod;
|
||||
uint8_t **goto_table_mod_pointers;
|
||||
|
||||
/* goto_table, failure table and output table. Needed to create state_table.
|
||||
* Will be freed, once we have created the goto_table_mod */
|
||||
int32_t (*goto_table)[256];
|
||||
int32_t *failure_table;
|
||||
SCACGfbsOutputTable *output_table;
|
||||
SCACGfbsPatternList *pid_pat_list;
|
||||
|
||||
/* the size of each state */
|
||||
uint16_t single_state_size;
|
||||
uint32_t max_pat_id;
|
||||
} SCACGfbsCtx;
|
||||
|
||||
typedef struct SCACGfbsThreadCtx_ {
|
||||
/* the total calls we make to the search function */
|
||||
uint32_t total_calls;
|
||||
/* the total patterns that we ended up matching against */
|
||||
uint64_t total_matches;
|
||||
} SCACGfbsThreadCtx;
|
||||
|
||||
void MpmACGfbsRegister(void);
|
File diff suppressed because it is too large
Load Diff
@ -1,127 +0,0 @@
|
||||
/* Copyright (C) 2007-2010 Open Information Security Foundation
|
||||
*
|
||||
* You can copy, redistribute or modify this Program under the terms of
|
||||
* the GNU General Public License version 2 as published by the Free
|
||||
* Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* version 2 along with this program; if not, write to the Free Software
|
||||
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
||||
* 02110-1301, USA.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* \author Victor Julien <victor@inliniac.net>
|
||||
*/
|
||||
|
||||
#ifndef __UTIL_MPM_B2G_H__
|
||||
#define __UTIL_MPM_B2G_H__
|
||||
|
||||
#include "util-mpm.h"
|
||||
#include "util-bloomfilter.h"
|
||||
|
||||
#define B2G_HASHSHIFT_MAX 8
|
||||
#define B2G_HASHSHIFT_HIGHER 7
|
||||
#define B2G_HASHSHIFT_HIGH 6
|
||||
#define B2G_HASHSHIFT_MEDIUM 5
|
||||
#define B2G_HASHSHIFT_LOW 4
|
||||
#define B2G_HASHSHIFT_LOWEST 3
|
||||
|
||||
//#define B2G_TYPE uint64_t
|
||||
#define B2G_TYPE uint32_t
|
||||
//#define B2G_TYPE uint16_t
|
||||
//#define B2G_TYPE uint8_t
|
||||
//#define B2G_WORD_SIZE 64
|
||||
#define B2G_WORD_SIZE 32
|
||||
//#define B2G_WORD_SIZE 16
|
||||
//#define B2G_WORD_SIZE 8
|
||||
|
||||
#define B2G_Q 2
|
||||
|
||||
#define B2G_SEARCHFUNC B2gSearchBNDMq
|
||||
//#define B2G_SEARCHFUNC B2gSearch
|
||||
|
||||
//#define B2G_SEARCH2
|
||||
//#define B2G_COUNTERS
|
||||
|
||||
typedef struct B2gPattern_ {
|
||||
uint16_t len; /**< \todo we're limited to 32/64 byte lengths, uint8_t would be fine here */
|
||||
uint8_t flags;
|
||||
uint8_t pad0;
|
||||
uint32_t id;
|
||||
uint8_t *original_pat;
|
||||
uint8_t *ci; /* case INsensitive */
|
||||
uint8_t *cs; /* case sensitive */
|
||||
|
||||
/* sid(s) for this pattern */
|
||||
uint32_t sids_size;
|
||||
SigIntId *sids;
|
||||
|
||||
struct B2gPattern_ *next;
|
||||
} B2gPattern;
|
||||
|
||||
typedef struct B2gCtx_ {
|
||||
B2G_TYPE *B2G;
|
||||
B2G_TYPE m;
|
||||
BloomFilter **bloom;
|
||||
uint8_t *pminlen; /* array containing the minimal length
|
||||
of the patters in a hash bucket. Used
|
||||
for the BloomFilter. */
|
||||
/* pattern arrays */
|
||||
B2gPattern **parray;
|
||||
|
||||
uint16_t pat_1_cnt;
|
||||
#ifdef B2G_SEARCH2
|
||||
uint16_t pat_2_cnt;
|
||||
#endif
|
||||
uint16_t pat_x_cnt;
|
||||
|
||||
uint32_t hash_size;
|
||||
B2gPattern **hash;
|
||||
B2gPattern hash1[256];
|
||||
#ifdef B2G_SEARCH2
|
||||
B2gHashItem **hash2;
|
||||
#endif
|
||||
|
||||
/* hash used during ctx initialization */
|
||||
B2gPattern **init_hash;
|
||||
|
||||
uint8_t s0;
|
||||
|
||||
/* we store our own multi byte search func ptr here for B2gSearch1 */
|
||||
uint32_t (*Search)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
|
||||
/* we store our own multi byte search func ptr here for B2gSearch1 */
|
||||
uint32_t (*MBSearch2)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
uint32_t (*MBSearch)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
} B2gCtx;
|
||||
|
||||
typedef struct B2gThreadCtx_ {
|
||||
#ifdef B2G_COUNTERS
|
||||
uint32_t stat_pminlen_calls;
|
||||
uint32_t stat_pminlen_total;
|
||||
uint32_t stat_bloom_calls;
|
||||
uint32_t stat_bloom_hits;
|
||||
uint32_t stat_calls;
|
||||
uint32_t stat_m_total;
|
||||
uint32_t stat_d0;
|
||||
uint32_t stat_d0_hashloop;
|
||||
uint32_t stat_loop_match;
|
||||
uint32_t stat_loop_no_match;
|
||||
uint32_t stat_num_shift;
|
||||
uint32_t stat_total_shift;
|
||||
#endif /* B2G_COUNTERS */
|
||||
} B2gThreadCtx;
|
||||
|
||||
void MpmB2gRegister(void);
|
||||
|
||||
|
||||
#endif
|
||||
|
File diff suppressed because it is too large
Load Diff
@ -1,130 +0,0 @@
|
||||
/* Copyright (C) 2007-2010 Open Information Security Foundation
|
||||
*
|
||||
* You can copy, redistribute or modify this Program under the terms of
|
||||
* the GNU General Public License version 2 as published by the Free
|
||||
* Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* version 2 along with this program; if not, write to the Free Software
|
||||
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
||||
* 02110-1301, USA.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* \author Victor Julien <victor@inliniac.net>
|
||||
*/
|
||||
|
||||
#ifndef __UTIL_MPM_B3G_H__
|
||||
#define __UTIL_MPM_B3G_H__
|
||||
|
||||
#include "util-mpm.h"
|
||||
#include "util-bloomfilter.h"
|
||||
|
||||
#define B3G_HASHSHIFT_MAX 8
|
||||
#define B3G_HASHSHIFT_MAX2 5
|
||||
#define B3G_HASHSHIFT_HIGHER 7
|
||||
#define B3G_HASHSHIFT_HIGHER2 4
|
||||
#define B3G_HASHSHIFT_HIGH 6
|
||||
#define B3G_HASHSHIFT_HIGH2 3
|
||||
#define B3G_HASHSHIFT_MEDIUM 5
|
||||
#define B3G_HASHSHIFT_MEDIUM2 2
|
||||
#define B3G_HASHSHIFT_LOW 4
|
||||
#define B3G_HASHSHIFT_LOW2 1
|
||||
#define B3G_HASHSHIFT_LOWEST 3
|
||||
#define B3G_HASHSHIFT_LOWEST2 1
|
||||
|
||||
#define B3G_TYPE uint32_t
|
||||
//#define B3G_TYPE uint16_t
|
||||
//#define B3G_TYPE uint8_t
|
||||
//#define B3G_WORD_SIZE 16
|
||||
//#define B3G_WORD_SIZE 8
|
||||
#define B3G_WORD_SIZE 32
|
||||
|
||||
#define B3G_Q 3
|
||||
|
||||
//#define B3G_SEARCHFUNC B3gSearch
|
||||
#define B3G_SEARCHFUNC B3gSearchBNDMq
|
||||
|
||||
//#define B3G_COUNTERS
|
||||
|
||||
typedef struct B3gPattern_ {
|
||||
uint8_t *cs; /* case sensitive */
|
||||
uint8_t *ci; /* case INsensitive */
|
||||
uint16_t len;
|
||||
uint8_t flags;
|
||||
uint32_t id;
|
||||
|
||||
/* sid(s) for this pattern */
|
||||
uint32_t sids_size;
|
||||
SigIntId *sids;
|
||||
|
||||
struct B3gPattern_ *next;
|
||||
|
||||
} B3gPattern;
|
||||
|
||||
typedef struct B3gHashItem_ {
|
||||
uint8_t flags;
|
||||
uint16_t idx;
|
||||
struct B3gHashItem_ *nxt;
|
||||
} B3gHashItem;
|
||||
|
||||
typedef struct B3gCtx_ {
|
||||
/* hash used during ctx initialization */
|
||||
B3gPattern **init_hash;
|
||||
|
||||
B3G_TYPE m;
|
||||
B3G_TYPE *B3G;
|
||||
|
||||
uint8_t s0;
|
||||
|
||||
uint16_t pat_1_cnt;
|
||||
uint16_t pat_2_cnt;
|
||||
uint16_t pat_x_cnt;
|
||||
|
||||
uint32_t hash_size;
|
||||
B3gHashItem **hash;
|
||||
BloomFilter **bloom;
|
||||
uint8_t *pminlen; /* array containing the minimal length
|
||||
of the patters in a hash bucket. Used
|
||||
for the BloomFilter. */
|
||||
B3gHashItem hash1[256];
|
||||
B3gHashItem **hash2;
|
||||
|
||||
uint32_t (*Search)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
|
||||
/* we store our own multi byte search func ptr here for B3gSearch1 */
|
||||
uint32_t (*MBSearch2)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
uint32_t (*MBSearch)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
|
||||
/* pattern arrays */
|
||||
B3gPattern **parray;
|
||||
} B3gCtx;
|
||||
|
||||
typedef struct B3gThreadCtx_ {
|
||||
#ifdef B3G_COUNTERS
|
||||
uint32_t stat_pminlen_calls;
|
||||
uint32_t stat_pminlen_total;
|
||||
uint32_t stat_bloom_calls;
|
||||
uint32_t stat_bloom_hits;
|
||||
uint32_t stat_calls;
|
||||
uint32_t stat_m_total;
|
||||
uint32_t stat_d0;
|
||||
uint32_t stat_d0_hashloop;
|
||||
uint32_t stat_loop_match;
|
||||
uint32_t stat_loop_no_match;
|
||||
uint32_t stat_num_shift;
|
||||
uint32_t stat_total_shift;
|
||||
#endif /* B3G_COUNTERS */
|
||||
} B3gThreadCtx;
|
||||
|
||||
void MpmB3gRegister(void);
|
||||
|
||||
#endif
|
||||
|
File diff suppressed because it is too large
Load Diff
@ -1,97 +0,0 @@
|
||||
/* Copyright (C) 2007-2010 Open Information Security Foundation
|
||||
*
|
||||
* You can copy, redistribute or modify this Program under the terms of
|
||||
* the GNU General Public License version 2 as published by the Free
|
||||
* Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful,
|
||||
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
* version 2 along with this program; if not, write to the Free Software
|
||||
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
||||
* 02110-1301, USA.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* \author Victor Julien <victor@inliniac.net>
|
||||
*/
|
||||
|
||||
#ifndef __UTIL_MPM_WUMANBER_H__
|
||||
#define __UTIL_MPM_WUMANBER_H__
|
||||
|
||||
#include "util-mpm.h"
|
||||
#include "util-bloomfilter.h"
|
||||
|
||||
//#define WUMANBER_COUNTERS
|
||||
|
||||
typedef struct WmPattern_ {
|
||||
uint8_t *cs; /* case sensitive */
|
||||
uint8_t *ci; /* case INsensitive */
|
||||
uint16_t len;
|
||||
struct WmPattern_ *next;
|
||||
uint16_t prefix_ci;
|
||||
uint16_t prefix_cs;
|
||||
uint8_t flags;
|
||||
uint32_t id; /* global pattern id */
|
||||
|
||||
/* sid(s) for this pattern */
|
||||
uint32_t sids_size;
|
||||
SigIntId *sids;
|
||||
|
||||
} WmPattern;
|
||||
|
||||
typedef struct WmHashItem_ {
|
||||
uint8_t flags;
|
||||
uint16_t idx;
|
||||
struct WmHashItem_ *nxt;
|
||||
} WmHashItem;
|
||||
|
||||
typedef struct WmCtx_ {
|
||||
/* hash used during ctx initialization */
|
||||
WmPattern **init_hash;
|
||||
|
||||
uint16_t shiftlen;
|
||||
|
||||
uint32_t hash_size;
|
||||
WmHashItem **hash;
|
||||
BloomFilter **bloom;
|
||||
uint8_t *pminlen; /* array containing the minimal length
|
||||
of the patters in a hash bucket. Used
|
||||
for the BloomFilter. */
|
||||
WmHashItem hash1[256];
|
||||
|
||||
/* we store our own search func ptr here for WmSearch1 */
|
||||
uint32_t (*Search)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
/* we store our own multi byte search func ptr here for WmSearch1 */
|
||||
uint32_t (*MBSearch)(struct MpmCtx_ *, struct MpmThreadCtx_ *, PatternMatcherQueue *, uint8_t *, uint16_t);
|
||||
|
||||
/* pattern arrays */
|
||||
WmPattern **parray;
|
||||
|
||||
/* only used for multibyte pattern search */
|
||||
uint16_t *shifttable;
|
||||
} WmCtx;
|
||||
|
||||
typedef struct WmThreadCtx_ {
|
||||
#ifdef WUMANBER_COUNTERS
|
||||
uint32_t stat_pminlen_calls;
|
||||
uint32_t stat_pminlen_total;
|
||||
uint32_t stat_bloom_calls;
|
||||
uint32_t stat_bloom_hits;
|
||||
uint32_t stat_shift_null;
|
||||
uint32_t stat_loop_match;
|
||||
uint32_t stat_loop_no_match;
|
||||
uint32_t stat_num_shift;
|
||||
uint32_t stat_total_shift;
|
||||
#endif /* WUMANBER_COUNTERS */
|
||||
} WmThreadCtx;
|
||||
|
||||
void MpmWuManberRegister(void);
|
||||
|
||||
#endif /* __UTIL_MPM_WUMANBER_H__ */
|
||||
|
Loading…
Reference in New Issue