-
Notifications
You must be signed in to change notification settings - Fork 1.8k
next/1382/20260610/v1 #15592
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
next/1382/20260610/v1 #15592
Changes from all commits
Commits
Show all changes
18 commits
Select commit
Hold shift + click to select a range
fdd9f8a
github-ci: consolidate new authors check into a single workflow
jasonish e5e5606
rust: format snmp files
catenacyber d3a8a06
rust: check llmnr format
catenacyber cad95a4
decoder/sctp: extend decoder
glongo c941b0c
detect/sctp: add sctp.hdr sticky buffer
glongo f73c26f
detect/sctp: add sctp.chunk_type keyword
glongo 25b8db3
detect/sctp: add sctp.chunk_cnt keyword
glongo cdb79dc
detect/sctp: add sctp.vtag keyword
glongo a856a08
output/json: add sctp metadata to alerts
glongo 8744750
decode/sctp: set p->payload to data chunk
glongo c7c8302
detect/sctp: add sctp.chunk_data sticky buffer
glongo 4b3d97c
doc/sctp: add sctp keywords
glongo 7f98297
github-actions: bump github/codeql-action from 4.36.1 to 4.36.2
dependabot[bot] c5c1ede
github-actions: bump codecov/codecov-action from 6.0.1 to 7.0.0
dependabot[bot] 0e3dd86
detect/parse: assert HashListTableLookup results in duplicate sig check
9cb7fb2
detect: guard rate filter callback registration, return bool on failure
cf10c01
examples: check rate filter callback registration result
0cd9cc6
rust: exclude DETECT_BYTEMATH_ENDIAN_DEFAULT from bindings
inashivb File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,150 @@ | ||
| .. role:: example-rule-emphasis | ||
|
|
||
| SCTP Keywords | ||
| ============= | ||
|
|
||
| Suricata supports sticky buffers and keywords for matching on SCTP | ||
| packet headers, chunks, and metadata. | ||
|
|
||
| Sticky buffers are expected to be followed by one or more | ||
| :doc:`payload-keywords`. | ||
|
|
||
| sctp.hdr | ||
| -------- | ||
|
|
||
| Sticky buffer to match on the raw SCTP header and all chunks. | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP header match"; :example-rule-emphasis:`sctp.hdr; content:"|01|"; offset:8; depth:1;` sid:1; rev:1;) | ||
|
|
||
| ``sctp.hdr`` is a 'sticky buffer'. | ||
|
|
||
| ``sctp.hdr`` can be used as ``fast_pattern``. | ||
|
|
||
| sctp.chunk_data | ||
| --------------- | ||
|
|
||
| Sticky buffer to match on any SCTP DATA chunk user payload. | ||
|
|
||
| When a packet contains DATA chunks, the packet payload (``p->payload``) | ||
| is set to the user data of the first DATA chunk. A bare ``content`` | ||
| match (without a sticky buffer) therefore inspects the first DATA | ||
| chunk's payload. Use ``sctp.chunk_data`` to inspect all DATA chunks | ||
| independently. | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP DATA payload match"; :example-rule-emphasis:`sctp.chunk_data; content:"test";` sid:2; rev:1;) | ||
|
|
||
| ``sctp.chunk_data`` is a 'sticky buffer'. | ||
|
|
||
| ``sctp.chunk_data`` can be used as ``fast_pattern``. | ||
|
|
||
| sctp.vtag | ||
| --------- | ||
|
|
||
| Match on the SCTP verification tag field in the common header. | ||
|
|
||
| sctp.vtag uses an :ref:`unsigned 32-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.vtag:[op]<number> | ||
|
|
||
| The verification tag can be matched exactly, or compared using the _op_ setting:: | ||
|
|
||
| sctp.vtag:12345 # exactly 12345 | ||
| sctp.vtag:>0 # greater than 0 | ||
| sctp.vtag:100-200 # range 100 to 200 | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP vtag match"; :example-rule-emphasis:`sctp.vtag:0;` sid:3; rev:1;) | ||
|
|
||
| sctp.chunk_type | ||
| --------------- | ||
|
|
||
| Match on the type of any SCTP chunk in the packet. | ||
|
|
||
| sctp.chunk_type uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.chunk_type:[!]<value> | ||
| sctp.chunk_type:[op]<number> | ||
|
|
||
| Values can be specified by name or by numeric value. The following | ||
| named chunk types are supported: | ||
|
|
||
| ================= ===== | ||
| Name Value | ||
| ================= ===== | ||
| data 0 | ||
| init 1 | ||
| init_ack 2 | ||
| sack 3 | ||
| heartbeat 4 | ||
| hb_ack 5 | ||
| abort 6 | ||
| shutdown 7 | ||
| shutdown_ack 8 | ||
| error 9 | ||
| cookie_echo 10 | ||
| cookie_ack 11 | ||
| ecne 12 | ||
| cwr 13 | ||
| shutdown_complete 14 | ||
| forward_tsn 192 | ||
| ================= ===== | ||
|
|
||
| Named values are case-insensitive and can be negated with ``!``:: | ||
|
|
||
| sctp.chunk_type:init # INIT chunk | ||
| sctp.chunk_type:init_ack # INIT ACK chunk | ||
| sctp.chunk_type:!data # any chunk that is not DATA | ||
|
|
||
| Numeric values support comparison operators and ranges:: | ||
|
|
||
| sctp.chunk_type:1 # INIT chunk (type 1) | ||
| sctp.chunk_type:0-4 # range 0 to 4 | ||
|
|
||
| Example rules: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:init;` sid:4; rev:1;) | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP INIT chunk detected"; :example-rule-emphasis:`sctp.chunk_type:1;` sid:5; rev:1;) | ||
|
|
||
| sctp.chunk_cnt | ||
| -------------- | ||
|
|
||
| Match on the number of SCTP chunks in the packet. | ||
|
|
||
| sctp.chunk_cnt uses an :ref:`unsigned 8-bit integer <rules-integer-keywords>`. | ||
|
|
||
| Syntax:: | ||
|
|
||
| sctp.chunk_cnt:[op]<number> | ||
|
|
||
| The chunk count can be matched exactly, or compared using the _op_ setting:: | ||
|
|
||
| sctp.chunk_cnt:1 # exactly 1 chunk | ||
| sctp.chunk_cnt:>3 # more than 3 chunks | ||
| sctp.chunk_cnt:2-5 # range 2 to 5 | ||
|
|
||
| Example rule: | ||
|
|
||
| .. container:: example-rule | ||
|
|
||
| alert sctp any any -> any any (msg:"SCTP packet with multiple chunks"; :example-rule-emphasis:`sctp.chunk_cnt:>1;` sid:5; rev:1;) | ||
|
|
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
AI just flagged this, and I didn't realize github.ref would change here. With
pull_request_target,github.refbecomes the pull request target, so in our case usuallymain. What this means is one person's pull request is going to cancel all the other pull requests jobs.There is a simple fix:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#15598