|
1
|
|
|
import uuid |
|
2
|
|
|
|
|
3
|
|
|
ns = { |
|
4
|
|
|
'XMLSchema': 'http://oval.mitre.org/XMLSchema/oval-results-5', |
|
5
|
|
|
'xccdf': 'http://checklists.nist.gov/xccdf/1.2', |
|
6
|
|
|
'arf': 'http://scap.nist.gov/schema/asset-reporting-format/1.1', |
|
7
|
|
|
'oval-definitions': 'http://oval.mitre.org/XMLSchema/oval-definitions-5', |
|
8
|
|
|
'scap': 'http://scap.nist.gov/schema/scap/source/1.2', |
|
9
|
|
|
'oval-characteristics': 'http://oval.mitre.org/XMLSchema/oval-system-characteristics-5', |
|
10
|
|
|
} |
|
11
|
|
|
|
|
12
|
|
|
|
|
13
|
|
|
class _TestInfo: |
|
14
|
|
|
def __init__(self, report_data): |
|
15
|
|
|
self.report_data = report_data |
|
16
|
|
|
self.oval_definitions = self._get_oval_definitions() |
|
17
|
|
|
self.tests = self._get_tests() |
|
18
|
|
|
self.objects = self._get_objects() |
|
19
|
|
|
self.oval_system_characteristics = self._get_oval_system_characteristics() |
|
20
|
|
|
self.collected_objects = self._get_collected_objects() |
|
21
|
|
|
self.system_data = self._get_system_data() |
|
22
|
|
|
self.tests_info = self._get_tests_info() |
|
23
|
|
|
|
|
24
|
|
|
def _get_oval_system_characteristics(self): |
|
25
|
|
|
return self.report_data.find( |
|
26
|
|
|
('.//XMLSchema:oval_results/XMLSchema:results/XMLSchema:system' |
|
27
|
|
|
'/oval-characteristics:oval_system_characteristics'), ns) |
|
28
|
|
|
|
|
29
|
|
|
@staticmethod |
|
30
|
|
|
def _get_dict_of_data(data): |
|
31
|
|
|
return {item.attrib.get('id'): item for item in data} |
|
32
|
|
|
|
|
33
|
|
|
def _get_collected_objects(self): |
|
34
|
|
|
data = self.oval_system_characteristics.find( |
|
35
|
|
|
'.//oval-characteristics:collected_objects', ns) |
|
36
|
|
|
return self._get_dict_of_data(data) |
|
37
|
|
|
|
|
38
|
|
|
def _get_system_data(self): |
|
39
|
|
|
data = self.oval_system_characteristics.find( |
|
40
|
|
|
'.//oval-characteristics:system_data', ns) |
|
41
|
|
|
return self._get_dict_of_data(data) |
|
42
|
|
|
|
|
43
|
|
|
def _get_oval_definitions(self): |
|
44
|
|
|
data = self.report_data.find( |
|
45
|
|
|
('.//XMLSchema:oval_results/oval-definitions:oval_definitions'), ns) |
|
46
|
|
|
return data |
|
47
|
|
|
|
|
48
|
|
|
def _get_tests(self): |
|
49
|
|
|
return self.oval_definitions.find('.//oval-definitions:tests', ns) |
|
50
|
|
|
|
|
51
|
|
|
def _get_objects(self): |
|
52
|
|
|
data = self.oval_definitions.find( |
|
53
|
|
|
('.//oval-definitions:objects'), ns) |
|
54
|
|
|
return self._get_dict_of_data(data) |
|
55
|
|
|
|
|
56
|
|
|
@staticmethod |
|
57
|
|
|
def _get_key_for_element(element): |
|
58
|
|
|
return element.tag.split('}')[1] if '}' in element.tag else element.tag |
|
59
|
|
|
|
|
60
|
|
|
def _find_item_ref(self, object_): |
|
61
|
|
|
list_of_item_ref = [self._get_item_ref(item) for item in object_] |
|
62
|
|
|
return list(filter(None, list_of_item_ref)) |
|
63
|
|
|
|
|
64
|
|
|
@staticmethod |
|
65
|
|
|
def _get_item_ref(item): |
|
66
|
|
|
return item.get('item_ref') if item.get('item_ref') else None |
|
67
|
|
|
|
|
68
|
|
|
@staticmethod |
|
69
|
|
|
def _get_unique_key(key): |
|
70
|
|
|
return key + '@' + str(uuid.uuid4()) |
|
71
|
|
|
|
|
72
|
|
|
def _get_unique_id_in_dict(self, object_, dict_): |
|
73
|
|
|
if self._get_key_for_element(object_) in dict_: |
|
74
|
|
|
return self._get_unique_key(self._get_key_for_element(object_)) |
|
75
|
|
|
return self._get_key_for_element(object_) |
|
76
|
|
|
|
|
77
|
|
|
def _get_collected_objects_info(self, collected_object, object_): |
|
78
|
|
|
out = {} |
|
79
|
|
|
if len(collected_object) == 0: |
|
80
|
|
|
out[self._get_unique_id_in_dict(object_, out) |
|
81
|
|
|
] = self._get_object_items(object_, collected_object) |
|
82
|
|
|
else: |
|
83
|
|
|
item_refs = self._find_item_ref(collected_object) |
|
84
|
|
|
if item_refs: |
|
85
|
|
|
for item_id in item_refs: |
|
86
|
|
|
out[self._get_unique_id_in_dict( |
|
87
|
|
|
object_, out)] = self._get_item(item_id) |
|
88
|
|
|
else: |
|
89
|
|
|
out[self._get_unique_id_in_dict( |
|
90
|
|
|
object_, out)] = self._get_object_items(object_, collected_object) |
|
91
|
|
|
return out |
|
92
|
|
|
|
|
93
|
|
|
def _xml_element_to_dict(self, object_, collected_object): |
|
94
|
|
|
result = {} |
|
95
|
|
|
if collected_object is not None: |
|
96
|
|
|
result[ |
|
97
|
|
|
collected_object.attrib.get('id') |
|
98
|
|
|
] = collected_object.attrib.get('flag') |
|
99
|
|
|
result.update( |
|
100
|
|
|
self._get_collected_objects_info(collected_object, object_)) |
|
101
|
|
|
else: |
|
102
|
|
|
result[object_.attrib.get('id')] = "does not exist" |
|
103
|
|
|
result[self._get_unique_id_in_dict( |
|
104
|
|
|
object_, result)] = self._get_object_items(object_, collected_object) |
|
105
|
|
|
return result |
|
106
|
|
|
|
|
107
|
|
|
def _get_object_items(self, object_, collected_object): |
|
108
|
|
|
out = {} |
|
109
|
|
|
for element in object_.iterchildren(): |
|
110
|
|
|
if element.text and element.text.strip(): |
|
111
|
|
|
out[self._get_unique_id_in_dict(element, out)] = element.text |
|
112
|
|
|
else: |
|
113
|
|
|
out[self._get_unique_id_in_dict(element, out)] = self._get_ref_var( |
|
114
|
|
|
element, collected_object) |
|
115
|
|
|
return out |
|
116
|
|
|
|
|
117
|
|
|
def _get_ref_var(self, element, collected_object): |
|
118
|
|
|
variable_value = '' |
|
119
|
|
|
if self._collected_object_is_not_none_and_contain_var_ref( |
|
120
|
|
|
element, collected_object): |
|
121
|
|
|
var_id = element.attrib.get('var_ref') |
|
122
|
|
|
for item in collected_object: |
|
123
|
|
|
if var_id == item.attrib.get('variable_id'): |
|
124
|
|
|
variable_value += item.text |
|
125
|
|
|
elif self._get_key_for_element(item) == 'message': |
|
126
|
|
|
variable_value += self._fix_message(item, var_id) + '<br>' |
|
127
|
|
|
else: |
|
128
|
|
|
variable_value = 'no value' |
|
129
|
|
|
return variable_value |
|
130
|
|
|
|
|
131
|
|
|
@staticmethod |
|
132
|
|
|
def _fix_message(item, var_id): |
|
133
|
|
|
if len(item.text) == 99 and var_id[:99 - item.text.find('(')] in var_id: |
|
134
|
|
|
return item.text[:item.text.find('(') + 1] + var_id + ')' |
|
135
|
|
|
return item.text |
|
136
|
|
|
|
|
137
|
|
|
@staticmethod |
|
138
|
|
|
def _collected_object_is_not_none_and_contain_var_ref(element, collected_object): |
|
139
|
|
|
return collected_object is not None and 'var_ref' in element.attrib |
|
140
|
|
|
|
|
141
|
|
|
def _get_item(self, item_ref): |
|
142
|
|
|
item = self.system_data.get(item_ref) |
|
143
|
|
|
out = {} |
|
144
|
|
|
for element in item.iterchildren(): |
|
145
|
|
|
if element.text and element.text.strip(): |
|
146
|
|
|
out[self._get_unique_id_in_dict(element, out)] = element.text |
|
147
|
|
|
return out |
|
148
|
|
|
|
|
149
|
|
|
def _get_object_info(self, id_object): |
|
150
|
|
|
object_ = self.objects.get(id_object) |
|
151
|
|
|
object_collected = self.collected_objects.get(id_object) |
|
152
|
|
|
return self._xml_element_to_dict(object_, object_collected) |
|
153
|
|
|
|
|
154
|
|
|
def _get_tests_info(self): |
|
155
|
|
|
out = [] |
|
156
|
|
|
for test in self.tests: |
|
157
|
|
|
objects = [] |
|
158
|
|
|
for item in test: |
|
159
|
|
|
object_id = item.attrib.get('object_ref') |
|
160
|
|
|
if object_id: |
|
161
|
|
|
objects.append(self._get_object_info(object_id)) |
|
162
|
|
|
out.append( |
|
163
|
|
|
dict( |
|
164
|
|
|
id=test.attrib.get('id'), |
|
165
|
|
|
comment=test.attrib.get('comment'), |
|
166
|
|
|
objects=objects, |
|
167
|
|
|
)) |
|
168
|
|
|
return out |
|
169
|
|
|
|
|
170
|
|
|
def get_info_about_test(self, id_of_test): |
|
171
|
|
|
for test in self.tests_info: |
|
172
|
|
|
if test['id'] == id_of_test: |
|
173
|
|
|
return test |
|
174
|
|
|
return None |
|
175
|
|
|
|