Commit Graph

2580 Commits (55ed6c2a55d41155a56efda237b475ff6ed72d54)
 

Author SHA1 Message Date
Anoop Saldanha 55ed6c2a55 disable session reassembly for either/both the directions, only when we have established failed proto detection in both the directions 13 years ago
Anoop Saldanha 4650bf7170 minor code cleanup. remove commented out code 13 years ago
Anoop Saldanha de9ad02b59 Remove leftover imap and msn toclient alproto PM contents 13 years ago
Anoop Saldanha caf26c2618 More updates to FFR code. Handle cases where we actually need to force stream reassembly and just have smsgs to be processsed by detection engine separately 13 years ago
Anoop Saldanha bc216a3396 fix/updates to app layer proto detection 13 years ago
Anoop Saldanha 78e6a7f713 enable toclient alproto detection. Detection all current alproto toclient PMP patterns 13 years ago
Anoop Saldanha 9c8d404db1 FFR update-fix. Fix check where we decide whether we need to send pseudo pkt or not 13 years ago
Anoop Saldanha b08b390bcd fix for bug 375 - update radix test that wrongly uses memset and sizeof 13 years ago
Victor Julien 3d845b6c77 Consider Windows new line chars as well when parsing rule files. Bug #374. 13 years ago
Eileen Donlon a92d15ed37 Fixed duplicate signature check 13 years ago
Anoop Saldanha 99baf18c8d updates to ac-gfbs search. Remove unnecessary casting of pointers 13 years ago
Anoop Saldanha 11e7dda59a updates to ac-gfbs search. Introduce handling cases where state_count is < 32k 13 years ago
Anoop Saldanha 708c4ad055 updates to ac-gfbs search. Combine output presence with mod goto table 13 years ago
Anoop Saldanha a4ea7e6197 updates to ac-gfbs search. Combine failure table along with mod goto table for better cache perf 13 years ago
Anoop Saldanha b69ac9514f updates to ac-gfbs search. Disable handling < 65k states separately. Now any state count would be given same treatment 13 years ago
Anoop Saldanha efb4c27b1f updates to ac-gfbs search. Add new unittests + fix cases where we have 2 patterns that are same but one is CS and other CI + Use SCMemcmp for state < 65k instead of custom memcmp 13 years ago
Anoop Saldanha 0920296aaa updates to ac-gfbs search. Remove unnecessary casting of pointers 13 years ago
Anoop Saldanha d149a5e806 updates to ac-gfbs search. Use SCMemcmp instead of the custom pattern searching used 13 years ago
Anoop Saldanha 47f2d6e07b updates to ac-gfbs search. Optimize pointer de-referencing for pid_pat_list 13 years ago
Anoop Saldanha 991f6d2d83 updates to ac-gfbs search. Optimize pointer de-referencing for frequently used pointers 13 years ago
Anoop Saldanha ffb925e3b3 indentation fixes for ac-gfbs 13 years ago
Anoop Saldanha e9eb0e502c updates to ac-gfbs search. Handle cases where we have a single entry for a state goto transition, just like how we handle for no entry for a particular state 13 years ago
Eric Leblond 9b75de3339 pfring: fix compilation when pfring is desactivated. 13 years ago
Eric Leblond 43ffd779f8 autotools: add libpcap dependencyto pfring for checks.
PF_RING seems to depend on pcap if bfp filter is activated. For this
reason, not having the dependency during configure test causes a
failure in feature detection.
13 years ago
Eric Leblond 0ac1cabf2a autotools: fix problem of pfring configuration. 13 years ago
deltay d5e254d504 Add pfring bpf filter, require pfring >= 5.1 13 years ago
Eric Leblond 9f73503daa capability: rework capability assignement
THis patch rework the capability code to use a switch
instead of a if. It also "reduces" PF_RING and NFQ capabilities.
13 years ago
Anoop Saldanha d034b10180 remove debug prints added to ac code 13 years ago
Anoop Saldanha 781e7c776f fix indentation in ac code 13 years ago
Anoop Saldanha 5c56053a33 Reintroduced optimized support for < 32k states for ac 13 years ago
Victor Julien fb76561b09 Set version to 1.2dev to reflect we're in the 1.2 branch. 13 years ago
Victor Julien 8cc82c7241 Add -S commandline option that loads a rule file exclusively. Issue #338. 13 years ago
Victor Julien 6256d6b598 Add content to ChangeLog and add links to more up to date versions of various docs. 13 years ago
Victor Julien c484b7a59e Bump version to 1.1 (final) 13 years ago
Eric Leblond 62e63e3fe9 af-packet: fix reconnection on netdown error.
AFPRead can fail following a NETDOWN error. This patch treat errors
of AFPRead by forcing a reconnection (instead of exiting thread
with error).
13 years ago
Eric Leblond 361bf22121 af-packet: suppress annoying debug message.
This message was firing multiple per second when a monitored
interface disappear.
13 years ago
Victor Julien 0fadd93011 Fix an invalid free in bpf code. 13 years ago
Victor Julien ea53f72f7d Fix CUDA build. 13 years ago
Eric Leblond 9f7ee03deb log: read output filter from config file.
The output filter was not read from configuration file and thus
not used in this case.
13 years ago
Eric Leblond 866d681ff2 pfring: fix stupid enum usage.
pfring code is not using standard notation for the cluster_type enum
and this leads to a horrific code in pfring acquisition code.
13 years ago
Eric Leblond a6a0d4eae6 pfring: use deinit function.
This fixes #368.
13 years ago
Eric Leblond a54afe7052 Fix printing of sizeof. 13 years ago
Eric Leblond 238cad77e2 coccinelle: test for invalid size_t printing. 13 years ago
Victor Julien 2d16abcf8b Minor code cleanups fixing all GCC 4.6 compiler warnings for default, debug and unittests mode. 13 years ago
Eric Leblond 2387c6b0e8 pcap: Fix setting of buffer size from command line. 13 years ago
Victor Julien 1be65e7b68 Fixes for building in Cygwin. 13 years ago
Victor Julien 85033f5afe Fix windows adapter id being truncated for pcap mode. 13 years ago
Eric Leblond 2bc0be6e65 af-packet: fix compilation problem on windows. 13 years ago
Victor Julien 404868c28b Get rid of strcasestr call as win32 doesn't have it. 13 years ago
Victor Julien 561630d864 Fix SMTP unittest. 13 years ago