1 /* Copyright (C) 2007-2010 Open Information Security Foundation 2 * 3 * You can copy, redistribute or modify this Program under the terms of 4 * the GNU General Public License version 2 as published by the Free 5 * Software Foundation. 6 * 7 * This program is distributed in the hope that it will be useful, 8 * but WITHOUT ANY WARRANTY; without even the implied warranty of 9 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 10 * GNU General Public License for more details. 11 * 12 * You should have received a copy of the GNU General Public License 13 * version 2 along with this program; if not, write to the Free Software 14 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 15 * 02110-1301, USA. 16 */ 17 18 /** 19 * \file 20 * 21 * \author Breno Silva <breno.silva@gmail.com> 22 */ 23 24 #ifndef __DETECT_FLAGS_H__ 25 #define __DETECT_FLAGS_H__ 26 27 #include "decode-events.h" 28 #include "decode-ipv4.h" 29 #include "decode-tcp.h" 30 31 /** 32 * \struct DetectFlagsData_ 33 * DetectFlagsData_ is used to store flags: input value 34 */ 35 36 /** 37 * \typedef DetectFlagsData 38 * A typedef for DetectFlagsData_ 39 */ 40 41 typedef struct DetectFlagsData_ { 42 uint8_t flags; /**< TCP flags */ 43 uint8_t modifier; /**< !(1) +(2) *(3) modifiers */ 44 uint8_t ignored_flags; /**< Ignored TCP flags defined by modifer , */ 45 } DetectFlagsData; 46 47 /** 48 * Registration function for flags: keyword 49 */ 50 51 void DetectFlagsRegister (void); 52 53 int DetectFlagsSignatureNeedsSynPackets(const Signature *s); 54 int DetectFlagsSignatureNeedsSynOnlyPackets(const Signature *s); 55 56 #endif /*__DETECT_FLAGS_H__ */ 57