Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
cleanup and add common validations
  • Loading branch information
StephenOTT committed Oct 30, 2019
commit b2ae2f180448aab926f237fd4fc538ec2ce278b9
2 changes: 1 addition & 1 deletion src/main/kotlin/com/stephenott/stix/MainRunner.kt
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ object MainRunner {
@JvmStatic
fun main(args: Array<String>){

val ap1 = AttackPattern("124")
val ap1 = AttackPattern(name = "124", confidence = StixConfidence(33))
val ap2 = AttackPattern("1245")
val ip6 = IPv6Address("dog")

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
package com.stephenott.stix.common

import com.stephenott.stix.StixContent
import com.stephenott.stix.type.StixType

fun requireStixType(type: StixType, obj: StixContent){
require(obj.type == type,
lazyMessage = {"Object has incorrect type value. Value was: ${obj.type}, but expected type value was $type"})
}
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ import com.stephenott.stix.objects.core.sro.objects.SightingSro
import com.stephenott.stix.type.StixType
import kotlin.reflect.KClass

//@TODO move to a instance so it can be passed into content handlers (such as JSON content mapper)
object StixObjectRegistry {

var sdoRegistry: Map<StixType, KClass<out StixDomainObject>> = mutableMapOf(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,8 @@ interface ArtifactSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: ArtifactSco) {
requireStixType(this.stixType, obj)

if (obj.url != null) {
require(obj.payloadBin == null, lazyMessage = { "payload_bin must not be present if url is provided." })
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ interface AutonomousSystemSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: AutonomousSystemSco) {

requireStixType(this.stixType, obj)
}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,8 @@ interface DirectorySco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: DirectorySco) {
requireStixType(this.stixType, obj)

obj.containsRefs?.let {
require(it.all { id -> id.type == stixType || id.type == FileSco.stixType },
lazyMessage = { "contains_refs must only contain SCOs of type Directory and File." }
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ interface DomainNameSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: DomainNameSco) {
requireStixType(this.stixType, obj)

}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,8 @@ interface EmailAddressSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: EmailAddressSco) {
requireStixType(this.stixType, obj)

obj.belongsToRef?.let {
require(it.type == UserAccountSco.stixType,
lazyMessage = { "belongs_to_ref must reference a user-account SCO." }
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ interface EmailMessageSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: EmailMessageSco) {
requireStixType(this.stixType, obj)

obj.fromRef?.let {
require(it.type == EmailAddressSco.stixType,
lazyMessage = { "from_ref must be references to email-address SCO" })
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,8 @@ interface FileSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: FileSco) {
requireStixType(this.stixType, obj)

obj.size?.let {
require(it.value >= 0,
lazyMessage = { "size must not be a negative number." })
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ interface IPv4AddressSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: IPv4AddressSco) {
requireStixType(this.stixType, obj)

}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ interface IPv6AddressSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: IPv6AddressSco) {
requireStixType(this.stixType, obj)

}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,8 @@ interface MacAddressSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: MacAddressSco) {
requireStixType(this.stixType, obj)

//@TODO The MAC address value ​MUST​ be represented as a single colon-delimited, lowercase MAC-48 address, which ​MUST​ include leading zeros for each octet.
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,8 @@ interface MutexSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: MutexSco) {
requireStixType(this.stixType, obj)

}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,8 @@ interface NetworkTrafficSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: NetworkTrafficSco) {
requireStixType(this.stixType, obj)

obj.isActive?.let {
if (it.value) {
require(obj.end == null,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@ interface ProcessSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: ProcessSco) {
requireStixType(this.stixType, obj)

require(obj.openedConnectionRef?.type == NetworkTrafficSco.stixType,
lazyMessage = { "opened_connection_ref must only reference network-traffic SCO." })

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,7 @@ interface SoftwareSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: SoftwareSco) {
requireStixType(this.stixType, obj)

}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ interface UrlSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: UrlSco) {

requireStixType(this.stixType, obj)
}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ interface UserAccountSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: UserAccountSco) {

requireStixType(this.stixType, obj)
}

}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ interface WindowsRegistryKeySco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: WindowsRegistryKeySco) {
requireStixType(this.stixType, obj)
require(
listOf(obj.key, obj.values, obj.modifiedTimed, obj.creatorUserRef, obj.numberOfSubkeys)
.any { it != null },
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ interface X509CertificateSco : StixCyberObservableObject {
)

override fun objectValidationRules(obj: X509CertificateSco) {
requireStixType(this.stixType, obj)

require(listOf( //@TODO review against Stix 2 Issues against 182
obj.isSelfSigned,
obj.hashes,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -21,7 +22,7 @@ interface AttackPatternSdo : StixDomainObject {
override val stixType = StixType("attack-pattern")

override fun objectValidationRules(obj: AttackPatternSdo) {

requireStixType(this.stixType, obj)
}

override val allowedRelationships: List<AllowedRelationship> = listOf(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -21,6 +22,7 @@ interface CampaignSdo : StixDomainObject {
CompanionAllowedRelationships {

override fun objectValidationRules(obj: CampaignSdo) {
requireStixType(this.stixType, obj)
if (obj.firstSeen != null){
require(obj.lastSeen?.instant!!.isAfter(obj.firstSeen!!.instant))
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -24,6 +25,8 @@ interface CourseOfActionSdo : StixDomainObject {
override val stixType = StixType("course-of-action")

override fun objectValidationRules(obj: CourseOfActionSdo) {
requireStixType(this.stixType, obj)

if (obj.actionReference != null){
require(obj.actionBin == null,
lazyMessage = {"action_bin must not be present if action_reference is provided."})
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -22,7 +23,7 @@ interface GroupingSdo : StixDomainObject {
override val stixType = StixType("grouping")

override fun objectValidationRules(obj: GroupingSdo) {

requireStixType(this.stixType, obj)
}

override val allowedRelationships: List<AllowedRelationship> = listOf()
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -26,7 +27,7 @@ interface IdentitySdo : StixDomainObject {
override val stixType = StixType("identity")

override fun objectValidationRules(obj: IdentitySdo) {

requireStixType(this.stixType, obj)
}

override val allowedRelationships: List<AllowedRelationship> = listOf(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -29,6 +30,8 @@ interface IndicatorSdo : StixDomainObject {
override val stixType = StixType("indicator")

override fun objectValidationRules(obj: IndicatorSdo) {
requireStixType(this.stixType, obj)

require(obj.validUntil?.instant!!.isAfter(obj.validFrom.instant),
lazyMessage = {"valid_until must come after valid_from."})
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sco.StixCyberObservableObject
import com.stephenott.stix.objects.core.sco.objects.DomainNameSco
import com.stephenott.stix.objects.core.sco.objects.IPv4AddressSco
Expand Down Expand Up @@ -31,6 +32,8 @@ interface InfrastructureSdo : StixDomainObject {
override val stixType = StixType("infrastructure")

override fun objectValidationRules(obj: InfrastructureSdo) {
requireStixType(this.stixType, obj)

if (obj.firstSeen != null && obj.lastSeen != null){
require(obj.lastSeen!!.instant >= obj.firstSeen!!.instant)
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -27,6 +28,8 @@ interface IntrusionSetSdo : StixDomainObject {
override val stixType = StixType("intrusion-set")

override fun objectValidationRules(obj: IntrusionSetSdo) {
requireStixType(this.stixType, obj)

if (obj.firstSeen != null && obj.lastSeen != null){
require(obj.lastSeen!!.instant >= obj.firstSeen!!.instant,
lazyMessage = {"last_seen must be equal or greater than first_seen."})
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand Down Expand Up @@ -30,6 +31,8 @@ interface LocationSdo : StixDomainObject {
override val stixType = StixType("location")

override fun objectValidationRules(obj: LocationSdo) {
requireStixType(this.stixType, obj)

if (obj.latitude != null) require(obj.longitude != null,
lazyMessage = { "longitude must be provided when latitude is used." })
if (obj.longitude != null) require(obj.latitude != null,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sco.objects.*
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
Expand Down Expand Up @@ -32,6 +33,8 @@ interface MalwareSdo : StixDomainObject {
override val stixType = StixType("malware")

override fun objectValidationRules(obj: MalwareSdo) {
requireStixType(this.stixType, obj)

if (obj.firstSeen != null && obj.lastSeen != null) {
require(obj.lastSeen!!.instant >= obj.firstSeen!!.instant,
lazyMessage = { "last_seen must greater than or equal to first_seen." })
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sco.objects.SoftwareSco
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
Expand Down Expand Up @@ -33,6 +34,8 @@ interface MalwareAnalysisSdo : StixDomainObject {
override val stixType = StixType("malware-analysis")

override fun objectValidationRules(obj: MalwareAnalysisSdo) {
requireStixType(this.stixType, obj)

//@TODO Product Name Validation enhancement: The name of the analysis engine or product that was used. Product names ​SHOULD​ be all lowercase with words separated by a dash "-". For cases where the name of a product cannot be specified, a value of "anonymized" MUST ​be used.

require(obj.hostVmRef?.type == SoftwareSco.stixType,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package com.stephenott.stix.objects.core.sdo.objects
import com.stephenott.stix.common.BusinessRulesValidator
import com.stephenott.stix.common.CompanionAllowedRelationships
import com.stephenott.stix.common.CompanionStixType
import com.stephenott.stix.common.requireStixType
import com.stephenott.stix.objects.core.sdo.StixDomainObject
import com.stephenott.stix.objects.core.sro.objects.AllowedRelationship
import com.stephenott.stix.objects.core.sro.objects.RelationshipSro
Expand All @@ -21,6 +22,7 @@ interface NoteSdo : StixDomainObject {
override val stixType = StixType("note")

override fun objectValidationRules(obj: NoteSdo) {
requireStixType(this.stixType, obj)

}

Expand Down
Loading