Project

General

Profile

Actions

Feature #8766

open
JL JL

detect: add "exact" keyword — match a content spanning the whole buffer

Feature #8766: detect: add "exact" keyword — match a content spanning the whole buffer

Added by Jeff Lucovsky 3 days ago. Updated about 10 hours ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

While implementing bsize-as-depth (#4226, PRs #15596 / #15674), @Philippe Antoine
suggested that an explicit keyword would be friendlier for rule
authors than reasoning about bsize / startswith / endswith to indicate "this
content is the entire buffer."

Proposal

Add an "exact" keyword: a no-argument content modifier that pins the buffer
length to the length of the preceding content. It is shorthand for
bsize:<content-length> -- the content spans the whole buffer.

Behavior

  • "exact" follows a content and takes no argument.
  • It is equivalent to bsize:<len> where len is the content length, so it
    reuses the existing bsize machinery: the length validation, the depth
    optimization, and -- for a lone content -- the startswith/endswith
    anchoring and MPM length prefilter. No new inspection path is added.
  • Because the length is derived, the rule stays correct if the content
    later changes; there is no literal length to keep in sync.
  • It is rejected when there is no preceding content, or when that content
    carries a relative modifier (distance/within), a negation, or a non-zero
    offset -- cases where "spans the whole buffer" no longer holds. Note that
    offset:0 is allowed.

Example:

alert dns any any -> any any (msg:"exact"; dns.query; \
content:"google.com"; exact; sid:1;)

matches only when dns.query is exactly "google.com" -- the same as
content:"google.com"; bsize:10;.

engine-analysis

The analyzer now suggests "exact" when a single content is pinned to the
whole buffer with startswith/endswith, replacing the earlier bsize:<len>
suggestion.

Relationship to #4226

#4226 already handles the inference side: an exact bsize equal to a lone
content's length is applied as startswith/endswith automatically.

Actions

Also available in: PDF Atom