一,hook点与数据流向
linux抽象出整体的hook架构,通过在以下几个数据流经点添加hook机制,为实现netfilter提供基础框架:
NF_IP_PRE_ROUTING、NF_IP_LOCAL_IN、NF_IP_FORWARD、NF_IP_LOCAL_OUT、NF_IP_POST_ROUTING。
这五个点在数据的流经方向如下图:
二、数据结构
1、nf_hook_ops
include/linux/netfilter.h
struct nf_hook_ops {
struct list_head list;
/* User fills in from here down. */
nf_hookfn *hook; // hook处理函数
struct net_device *dev; //模块所属
void *priv; //
u_int8_t pf; //协议号
unsigned int hooknum; // hook点
/* Hooks are ordered in ascending priority. */
int priority; //优先级
};
2、 nf_hookfn
include/linux/netfilter.h
typedef unsigned int nf_hookfn(void *priv,
struct sk_buff *skb,
const struct nf_hook_state *state);
struct nf_hook_state {
unsigned int hook;
int thresh;
u_int8_t pf;
struct net_device *in;
struct net_device *out;
struct sock *sk;
struct net *net;
struct list_head *hook_list;
int (okfn)(struct net , struct sock , struct sk_buff );
};
3、nf_hooks
nf_hooks是一个二维数组,该二维数组的每一个成员均是一个链表。每个链表都是由nf_hook_ops组成