-
Notifications
You must be signed in to change notification settings - Fork 1.8k
SCTP decoder and sticky buffers v5 #15497
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
9 commits
Select commit
Hold shift + click to select a range
0b16a9e
decoder/sctp: extend decoder
glongo 7e8ee23
detect/sctp: add sctp.hdr sticky buffer
glongo 341a9a6
detect/sctp: add sctp.chunk_type keyword
glongo 56317b5
detect/sctp: add sctp.chunk_cnt keyword
glongo 7fbdfd7
detect/sctp: add sctp.vtag keyword
glongo 03e1dbb
output/json: add sctp metadata to alerts
glongo 5539a04
decode/sctp: set p->payload to data chunk
glongo 38b6634
detect/sctp: add sctp.chunk_data sticky buffer
glongo bd1f229
doc/sctp: add sctp keywords
glongo File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,144 @@ | ||
| .. role:: example-rule-emphasis | ||
|
|
||
| SCTP Keywords | ||
| ============= | ||
|
|
||
| Suricata supports sticky buffers and keywords for matching on SCTP | ||
| packet headers, chunks, and metadata. | ||
|
|
||
| Sticky buffers are expected to be followed by one or more | ||
| :doc:`payload-keywords`. | ||
|
|
||
| sctp.hdr | ||
| -------- | ||
|
|
||
| Sticky buffer to match on the raw SCTP header and all chunks. | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP header match"; :example-rule-emphasis:`sctp.hdr; content:"|01|"; offset:8; depth:1;` sid:1; rev:1;) | ||
|
|
||
| ``sctp.hdr`` is a 'sticky buffer'. | ||
|
|
||
| ``sctp.hdr`` can be used as ``fast_pattern``. | ||
|
|
||
| sctp.chunk_data | ||
| --------------- | ||
|
|
||
| Sticky buffer to match on any SCTP DATA chunk user payload. | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP DATA payload match"; :example-rule-emphasis:`sctp.chunk_data; content:"test";` sid:2; rev:1;) | ||
|
|
||
| ``sctp.chunk_data`` is a 'sticky buffer'. | ||
|
|
||
| ``sctp.chunk_data`` can be used as ``fast_pattern``. | ||
|
|
||
| sctp.vtag | ||
| --------- | ||
|
|
||
| Match on the SCTP verification tag field in the common header. | ||
|
|
||
| sctp.vtag uses an :ref:`unsigned 32-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.vtag:[op]<number> | ||
|
|
||
| The verification tag can be matched exactly, or compared using the _op_ setting:: | ||
|
|
||
| sctp.vtag:12345 # exactly 12345 | ||
| sctp.vtag:>0 # greater than 0 | ||
| sctp.vtag:100-200 # range 100 to 200 | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP vtag match"; :example-rule-emphasis:`sctp.vtag:0;` sid:3; rev:1;) | ||
|
|
||
| sctp.chunk_type | ||
| --------------- | ||
|
|
||
| Match on the type of any SCTP chunk in the packet. | ||
|
|
||
| sctp.chunk_type uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.chunk_type:[!]<value> | ||
| sctp.chunk_type:[op]<number> | ||
|
|
||
| Values can be specified by name or by numeric value. The following | ||
| named chunk types are supported: | ||
|
|
||
| ================= ===== | ||
| Name Value | ||
| ================= ===== | ||
| data 0 | ||
| init 1 | ||
| init_ack 2 | ||
| sack 3 | ||
| heartbeat 4 | ||
| hb_ack 5 | ||
| abort 6 | ||
| shutdown 7 | ||
| shutdown_ack 8 | ||
| error 9 | ||
| cookie_echo 10 | ||
| cookie_ack 11 | ||
| ecne 12 | ||
| cwr 13 | ||
| shutdown_complete 14 | ||
| forward_tsn 192 | ||
| ================= ===== | ||
|
|
||
| Named values are case-insensitive and can be negated with ``!``:: | ||
|
|
||
| sctp.chunk_type:init # INIT chunk | ||
| sctp.chunk_type:init_ack # INIT ACK chunk | ||
| sctp.chunk_type:!data # any chunk that is not DATA | ||
|
|
||
| Numeric values support comparison operators and ranges:: | ||
|
|
||
| sctp.chunk_type:1 # INIT chunk (type 1) | ||
| sctp.chunk_type:0-4 # range 0 to 4 | ||
|
|
||
| Example rules: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:init;` sid:4; rev:1;) | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:1;` sid:5; rev:1;) | ||
|
|
||
| sctp.chunk_cnt | ||
| -------------- | ||
|
|
||
| Match on the number of SCTP chunks in the packet. | ||
|
|
||
| sctp.chunk_cnt uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.chunk_cnt:[op]<number> | ||
|
|
||
| The chunk count can be matched exactly, or compared using the _op_ setting:: | ||
|
|
||
| sctp.chunk_cnt:1 # exactly 1 chunk | ||
| sctp.chunk_cnt:>3 # more than 3 chunks | ||
| sctp.chunk_cnt:2-5 # range 2 to 5 | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP packet with multiple chunks"; :example-rule-emphasis:`sctp.chunk_cnt:>1;` sid:5; rev:1;) | ||
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| # SCTP decoder event rules. | ||
| # SID's fall in the 2239000-2239999 range. See http://doc.emergingthreats.net/bin/view/Main/SidAllocation | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP packet too small"; decode-event:sctp.pkt_too_small; classtype:protocol-command-decode; sid:2239001; rev:1;) | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP chunk too small"; decode-event:sctp.chunk_too_small; classtype:protocol-command-decode; sid:2239002; rev:1;) | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP chunk length invalid"; decode-event:sctp.chunk_len_invalid; classtype:protocol-command-decode; sid:2239003; rev:1;) | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP INIT chunk not alone"; decode-event:sctp.init_chunk_not_alone; classtype:protocol-command-decode; sid:2239004; rev:1;) | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP INIT with non-zero vtag"; decode-event:sctp.init_with_non_zero_vtag; classtype:protocol-command-decode; sid:2239005; rev:1;) | ||
| alert sctp any any -> any any (msg:"SURICATA SCTP DATA with zero vtag"; decode-event:sctp.data_with_zero_vtag; classtype:protocol-command-decode; sid:2239006; rev:1;) | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: we recently updated these for other files