Fixed fields are those protocol fields that are provided by the basic IP protocols ("IPv4"), TCP, UDP and ICMP. They are "fixed" by contrast with the calculated nature of many provided by other protocol specifications. Due to the fact that these fixed fields occur in most packets the Sensor inspects, it is impractical for performance reasons to inspect them in the same fashion as standard protocols. For the same reason, the number of fixed field comparisons is limited to 50.
Two types of tests for fixed fields are available. Both are numeric because the fixed fields are all numeric.
fields-eq — Fields-eq is a special test that is only available for fixed-field testing. It allows you to compare the values in two protocol fields. This is useful if, for example, you want to compare whether the source and destination IP addresses specified by packet headers are the same.
All of the numeric tests described for normal signature tests — This includes both signed and unsigned tests.
Note
The Single Fixed Field Match in the Custom Attack Editor also provides an "bitmask" function. This is not a normal "bitmask". Instead, starting from the offset you provide (in the selected fixed field), it selects the number of bits you specify, and then uses those bits to create an integer value that is compared against your provided comparison value.