Syscall Tracker System-Call Parameters Modification Extension
-------------------------------------------------------------

Purpose
-------

Sometimes, a user wishes that a rule's action will modify the parameters of
the system call, before invoking the real system call. This modification
would be transparent to the user-mode code (i.e. the process invoking the
system call will not notice the change).

Eamples of using such a feature:

1. You have a server process that accepts connections on some TCP or UDP port.
   This server binds to INADDR_ANY. However, you have set several virtual IP
   addresses on the machine, and wish that this server will bind only to one
   of these IPs, allowing a different server to bind to the the port with 
   a different IP address. You don't want (or can't) change the source of
   the server.

   solution: add a rule that identifies when a process with a given command
   name tries to bind to INADDR_ANY, with the given port number. The rule's
   action will modify the IP address part to the virtual IP address you
   wish, and continue with the normal system call invocation.

2. You have a server process that authenticates users with data from
   /etc/passwd. You want to force this process to use a different file instead,
   so it will authenticate users who don't have login access to your machine.

   solution: add a rule that identifies when a process with the given command
   name tries to open "/etc/passwd". The rule's action will modify the file
   name parameter to the alternate user's database file (e.g.
   "/etc/oddservice/passwd"), and continue with the normal system call
   invocation.


Proposed Syntax
---------------

The syntax that will be used to describe this action might look as follows:

    rewrite(<parameter>, <value>);

For example:

  rewrite(PARAMS[1], 200)
  rewrite(((struct_sockaddr_in)PARAMS[2]).sin_addr.s_addr, inet_ntoa(192.168.7.9))

  rewrite(PARAMS[1], "/etc/oddservice/passwd")

note the usage of 2 mechanisms that weren't defined so far:

1. Type cast - In order to handle polymorphic system call parameters (e.g.
   the 'my_addr' parameter passed to the bind system call), we need to allow
   the user to tell us what type they expect for the parameter, so we could
   enforce proper type checking for their contents.

2. Macros - 'inet_ntoa' is a macro that will be supported directly by
   sct_config, to allow the user to write the IP address in a human-readable
   format, rather then as an int value (as is stored inside the 's_addr'
   field of the 'sin_addr' field of a 'struct sockaddr_in'.


Context-Sensitive Rewrites
--------------------------

At a second stage, support for context-sensitive rewriting will be added.
This will allow (for example) rewriting only parts of string parameters,
or modifying the contents of an interger parameter based on its original
value . for example:

  rewrite(PARAMS[1], PARAMS[1]+1)

This can be done by simply translating the second parameter of the rewrite
directive to a filter node, storing that filter node in the action, and then
evaluating this filter node during runtime, when the action is invoked.
In order to support more complicated manipulations on strings, new string
functions will need to be supported, such as:

  str_prefix(<string>, <len>) - returns a string which contains the first 'len'
                                characters of the given string.
  str_suffix(<string>, <len>) - returns a string which contains the last 'len'
                                characters of the given string.
  str_infix(<string>, <len>, <pos>) - returns a string which contains the 'len'
                                      characters of the given string, starting
				      at the cahracter in location 'pos'.
  str_from(<string>, <string2>) - returns a string containing all characters of
                                  the given string, starting with the first
                                  character that exists also in 'string2'.
  str_to(<string>, <string2>) - returns a string containing all characters of
                                the given string, up to (not including) the
                                the first character that exists also in
                                'string2'.

other similar functions may be added as well. They _could_ be used also in
filter matching, thought they are relatively expensive and should be used with
care.
