Repository navigation
Expand file tree
/
Copy pathimpact.py
More file actions
executable file
·153 lines (127 loc) · 4.45 KB
/
Copy pathimpact.py
File metadata and controls
executable file
·153 lines (127 loc) · 4.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
#!/usr/bin/env python3
# Standard library imports
import json
import argparse
import sys
import logging
from joblib import Parallel, delayed
# Impact handler functions imported from role_impact module
from role_impact import impact_availability, impact_confidentiality, impact_integrity
# Mapping of impact types to their corresponding handler functions
impact_handlers = {
"availability": impact_availability,
"confidentiality": impact_confidentiality,
"integrity": impact_integrity
}
#
# load_json_file - Load and parse a JSON file.
#
# parameters:
# name -- Path to the JSON file.
#
# returns: Parsed JSON data.
#
def load_json_file(name: str) -> dict:
with open(name) as f:
return json.load(f)
#
# find_node_details - Find and return node details by name.
#
# parameters:
# node_name -- The name of the node to find.
# enterprise -- The parsed deployment dictionary.
#
# returns: Node dictionary if found, else None.
#
def find_node_details(node_name: str, enterprise: dict) -> dict:
built = enterprise['enterprise_built']
for node in built['deployed']['nodes']:
if node.get('name') == node_name:
return node
return None
#
# print_result - Log the type of impact and target node.
#
# parameters:
# impact_type -- Type of the impact (e.g., availability).
# node_name -- Target node name.
#
# returns: None
#
def print_result(impact_type: str, node_name: str) -> None:
logging.info(f"Impact type: {impact_type}")
logging.info(f"Node name: {node_name}")
#
# run_impact - Execute the impact function for a specific node.
#
# parameters:
# impact_type -- Type of the impact.
# node_name -- Node to impact.
# deployed -- Deployment details from config.
#
# returns: None
#
def run_impact(impact_type: str, node_name: str, enterprise: dict) -> None:
if impact_type not in impact_handlers:
logging.error(f"Unknown impact type '{impact_type}'")
return
node = find_node_details(node_name, enterprise)
if not node:
logging.error(f"Node '{node_name}' not found in deployment.")
return
print_result(impact_type, node_name)
handler = impact_handlers[impact_type]
handler(node, enterprise)
#
# apply_impacts - Parse and dispatch impacts sequentially or in parallel.
#
# parameters:
# impact_entries -- List of impact specifications (e.g., "availability=node1").
# deployed -- Deployment configuration from the JSON file.
# parallel -- Whether to execute in parallel (default: False).
#
# returns: None
#
def apply_impacts(impact_entries: list[str], enterprise: dict, parallel: bool = False) -> None:
parsed_impacts = []
for impact_entry in impact_entries:
if '=' not in impact_entry:
logging.error("Each --impact must be in the format <type>=<node> where type={confidentialitiy, integrity, availability")
continue
impact_type, node_name = impact_entry.split('=', 1)
parsed_impacts.append((impact_type, node_name))
if parallel:
Parallel(n_jobs=-1, backend="threading")(delayed(run_impact)(itype, inode, enterprise) for itype, inode in parsed_impacts)
else:
for itype, inode in parsed_impacts:
run_impact(itype, inode, enterprise)
#
# main - Main entry point for argument parsing and orchestration.
#
# returns: Exit status code.
#
def main() -> int:
parser = argparse.ArgumentParser(
description="Simulate a cybersecurity impact on a node in post-deploy-output.json."
)
parser.add_argument(
"-i", "--impact",
action="append",
type=str,
help="Specify the impact in the form <type>=<node>, where type={confidentialitiy, integrity, availability}. Can be repeated.",
required=True
)
parser.add_argument("-c", "--config", type=str, help="Path to post-deploy-output.json", required=True)
parser.add_argument("--parallel", action="store_true", help="Run impacts in parallel")
parser.add_argument("--verbose", action="store_true", help="Enable verbose debug logging")
args = parser.parse_args()
logging_level = logging.DEBUG if args.verbose else logging.INFO
logging.basicConfig(level=logging_level, format='%(asctime)s %(levelname)s: %(message)s')
enterprise = load_json_file(args.config)
apply_impacts(args.impact, enterprise, parallel=args.parallel)
return 0
#
# Script execution entry point
#
if __name__ == '__main__':
sys.exit(main())