Skip to content

Commit fc3cb2f

Browse files
committed
Add all project files
1 parent 71cceaa commit fc3cb2f

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

52 files changed

+21661
-0
lines changed

app_node_proj/app_node_proj/__init__.py

Whitespace-only changes.
+136
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,136 @@
1+
"""
2+
Django settings for app_node_proj project.
3+
4+
Generated by 'django-admin startproject' using Django 2.0.6.
5+
6+
For more information on this file, see
7+
https://docs.djangoproject.com/en/2.0/topics/settings/
8+
9+
For the full list of settings and their values, see
10+
https://docs.djangoproject.com/en/2.0/ref/settings/
11+
"""
12+
13+
import os
14+
import mongoengine # Update
15+
16+
# Build paths inside the project like this: os.path.join(BASE_DIR, ...)
17+
BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
18+
19+
20+
# Quick-start development settings - unsuitable for production
21+
# See https://docs.djangoproject.com/en/2.0/howto/deployment/checklist/
22+
23+
# SECURITY WARNING: keep the secret key used in production secret!
24+
SECRET_KEY = '@@1aaaaaaa1aaaa@a@1aaaaaaa@@aaaaaa1a1@11@aa@aaa@aa@' # Update
25+
26+
# SECURITY WARNING: don't run with debug turned on in production!
27+
DEBUG = True
28+
29+
ALLOWED_HOSTS = []
30+
31+
32+
# Application definition
33+
34+
INSTALLED_APPS = [
35+
'django.contrib.admin',
36+
'django.contrib.auth',
37+
'django.contrib.contenttypes',
38+
'django.contrib.sessions',
39+
'django.contrib.messages',
40+
'django.contrib.staticfiles',
41+
'vm_app',
42+
'rest_framework',
43+
'rest_framework_mongoengine',
44+
]
45+
46+
MIDDLEWARE = [
47+
'django.middleware.security.SecurityMiddleware',
48+
'django.contrib.sessions.middleware.SessionMiddleware',
49+
'django.middleware.common.CommonMiddleware',
50+
'django.middleware.csrf.CsrfViewMiddleware',
51+
'django.contrib.auth.middleware.AuthenticationMiddleware',
52+
'django.contrib.messages.middleware.MessageMiddleware',
53+
'django.middleware.clickjacking.XFrameOptionsMiddleware',
54+
]
55+
56+
ROOT_URLCONF = 'app_node_proj.urls'
57+
58+
TEMPLATES = [
59+
{
60+
'BACKEND': 'django.template.backends.django.DjangoTemplates',
61+
'DIRS': [],
62+
'APP_DIRS': True,
63+
'OPTIONS': {
64+
'context_processors': [
65+
'django.template.context_processors.debug',
66+
'django.template.context_processors.request',
67+
'django.contrib.auth.context_processors.auth',
68+
'django.contrib.messages.context_processors.messages',
69+
],
70+
},
71+
},
72+
]
73+
74+
WSGI_APPLICATION = 'app_node_proj.wsgi.application'
75+
76+
77+
# Database
78+
# https://docs.djangoproject.com/en/2.0/ref/settings/#databases
79+
80+
DATABASES = {
81+
'default': {
82+
'ENGINE': '', # Update
83+
}
84+
}
85+
86+
SESSION_ENGINE = 'mongoengine.django.sessions' # Update
87+
_MONGO_USERNAME_ = ''
88+
_MONGO_PASSWORD_ = ''
89+
_MONGO_HOST_ = '127.0.0.1'
90+
_MONGO_PORT_ = '27017'
91+
_MONGO_DB_ = 'app_node_db'
92+
_MONGO_HOST_STRING_ = ''
93+
if _MONGO_USERNAME_:
94+
_MONGO_HOST_STRING_ = 'mongodb://%s:%s@%s:%s/%s' % (_MONGO_USERNAME_, _MONGO_PASSWORD_, _MONGO_HOST_, _MONGO_PORT_, _MONGO_DB_)
95+
else:
96+
_MONGO_HOST_STRING_ = 'mongodb://%s:%s/%s' % (_MONGO_HOST_, _MONGO_PORT_, _MONGO_DB_)
97+
98+
mongoengine.connect(host=_MONGO_HOST_STRING_)
99+
100+
# Password validation
101+
# https://docs.djangoproject.com/en/2.0/ref/settings/#auth-password-validators
102+
103+
AUTH_PASSWORD_VALIDATORS = [
104+
{
105+
'NAME': 'django.contrib.auth.password_validation.UserAttributeSimilarityValidator',
106+
},
107+
{
108+
'NAME': 'django.contrib.auth.password_validation.MinimumLengthValidator',
109+
},
110+
{
111+
'NAME': 'django.contrib.auth.password_validation.CommonPasswordValidator',
112+
},
113+
{
114+
'NAME': 'django.contrib.auth.password_validation.NumericPasswordValidator',
115+
},
116+
]
117+
118+
119+
# Internationalization
120+
# https://docs.djangoproject.com/en/2.0/topics/i18n/
121+
122+
LANGUAGE_CODE = 'en-us'
123+
124+
TIME_ZONE = 'UTC'
125+
126+
USE_I18N = True
127+
128+
USE_L10N = True
129+
130+
USE_TZ = True
131+
132+
133+
# Static files (CSS, JavaScript, Images)
134+
# https://docs.djangoproject.com/en/2.0/howto/static-files/
135+
136+
STATIC_URL = '/static/'

app_node_proj/app_node_proj/urls.py

+23
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
"""app_node_proj URL Configuration
2+
3+
The `urlpatterns` list routes URLs to views. For more information please see:
4+
https://docs.djangoproject.com/en/2.0/topics/http/urls/
5+
Examples:
6+
Function views
7+
1. Add an import: from my_app import views
8+
2. Add a URL to urlpatterns: path('', views.home, name='home')
9+
Class-based views
10+
1. Add an import: from other_app.views import Home
11+
2. Add a URL to urlpatterns: path('', Home.as_view(), name='home')
12+
Including another URLconf
13+
1. Import the include() function: from django.urls import include, path
14+
2. Add a URL to urlpatterns: path('blog/', include('blog.urls'))
15+
"""
16+
from django.contrib import admin
17+
from django.urls import path
18+
from django.conf.urls import url, include
19+
20+
urlpatterns = [
21+
path('admin/', admin.site.urls),
22+
url(r'^', include('vm_app.urls')),
23+
]

app_node_proj/app_node_proj/wsgi.py

+16
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
"""
2+
WSGI config for app_node_proj project.
3+
4+
It exposes the WSGI callable as a module-level variable named ``application``.
5+
6+
For more information on this file, see
7+
https://docs.djangoproject.com/en/2.0/howto/deployment/wsgi/
8+
"""
9+
10+
import os
11+
12+
from django.core.wsgi import get_wsgi_application
13+
14+
os.environ.setdefault("DJANGO_SETTINGS_MODULE", "app_node_proj.settings")
15+
16+
application = get_wsgi_application()

app_node_proj/manage.py

+15
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
#!/usr/bin/env python
2+
import os
3+
import sys
4+
5+
if __name__ == "__main__":
6+
os.environ.setdefault("DJANGO_SETTINGS_MODULE", "app_node_proj.settings")
7+
try:
8+
from django.core.management import execute_from_command_line
9+
except ImportError as exc:
10+
raise ImportError(
11+
"Couldn't import Django. Are you sure it's installed and "
12+
"available on your PYTHONPATH environment variable? Did you "
13+
"forget to activate a virtual environment?"
14+
) from exc
15+
execute_from_command_line(sys.argv)

app_node_proj/vm_app/__init__.py

Whitespace-only changes.

app_node_proj/vm_app/admin.py

+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
from django.contrib import admin
2+
3+
# Register your models here.

app_node_proj/vm_app/apps.py

+5
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
from django.apps import AppConfig
2+
3+
4+
class VmAppConfig(AppConfig):
5+
name = 'vm_app'

app_node_proj/vm_app/choices.json

+9
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
{
2+
"node_type": ["webserver", "dbserver", "router", "firewall"],
3+
"node_name_type": ["ipaddress:port", "weburl"],
4+
"os": ["Win10", "WinXP", "MacOSX", "Linux", "iOS", "Android", "iOS-router"],
5+
"resource_type": ["webpage", "service", "os"],
6+
"finding_severity": ["Very High", "High", "Moderate", "Low", "Negligible"],
7+
"finding_code_type": ["c code", "py", "perl", "shellcode", "shell script"]
8+
}
9+

app_node_proj/vm_app/migrations/__init__.py

Whitespace-only changes.

app_node_proj/vm_app/models.py

+49
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
from mongoengine import *
2+
from bson.objectid import ObjectId
3+
import json
4+
5+
CHOICES = None
6+
with open('vm_app/choices.json', 'r') as choices_file:
7+
CHOICES = json.load(choices_file)
8+
9+
class Finding(EmbeddedDocument):
10+
finding_id = ObjectIdField(required=True, default=ObjectId, unique=True, primary_key=True)
11+
finding_details = StringField()
12+
finding_type = StringField(max_length=200)
13+
finding_severity = StringField(max_length=200, choices=CHOICES["finding_severity"])
14+
finding_score = IntField(required=True)
15+
finding_code = StringField()
16+
finding_code_type = StringField(max_length=200, choices=CHOICES["finding_code_type"])
17+
18+
class Resource(EmbeddedDocument):
19+
resource_id = ObjectIdField(required=True, default=ObjectId, unique=True, primary_key=True)
20+
resource = StringField()
21+
resource_criticality = IntField()
22+
resource_type = StringField(max_length=200, choices=CHOICES["resource_type"])
23+
findings = EmbeddedDocumentListField(Finding)
24+
25+
def risk_score(self):
26+
score = 0
27+
for finding in self.findings:
28+
score += finding.finding_score
29+
return self.resource_criticality*score
30+
31+
class SystemDetails(EmbeddedDocument):
32+
os = StringField(max_length=200, choices=CHOICES["os"])
33+
34+
class Node(Document):
35+
node_name = StringField()
36+
node_type = StringField(max_length=200, choices=CHOICES["node_type"])
37+
node_name_type = StringField(max_length=200, choices=CHOICES["node_name_type"])
38+
node_system_details = EmbeddedDocumentField(SystemDetails)
39+
node_resources = EmbeddedDocumentListField(Resource)
40+
41+
def __str__(self):
42+
return self.nodename
43+
44+
def risk_score(self):
45+
score = 0
46+
for res in self.node_resources:
47+
score += res.risk_score()
48+
return score
49+

app_node_proj/vm_app/serializers.py

+26
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
from rest_framework_mongoengine import serializers
2+
from rest_framework import serializers as drf_serializers
3+
from vm_app.models import Node, Resource, Finding
4+
5+
class NodeSerializer(serializers.DocumentSerializer):
6+
class Meta:
7+
model = Node
8+
fields = ('id', 'node_name', 'node_type', 'node_name_type', 'node_system_details', 'node_resources')
9+
10+
class ResourceSerializer(serializers.EmbeddedDocumentSerializer):
11+
class Meta:
12+
model = Resource
13+
fields = ('resource_id', 'resource', 'resource_criticality', 'resource_type', 'findings')
14+
15+
class FindingSerializer(serializers.EmbeddedDocumentSerializer):
16+
class Meta:
17+
model = Finding
18+
fields = ('finding_id', 'finding_details', 'finding_type', 'finding_severity', 'finding_score', 'finding_code', 'finding_code_type')
19+
20+
class NewFindingRequestSerializer(drf_serializers.Serializer):
21+
resource = drf_serializers.CharField()
22+
finding_details = drf_serializers.CharField()
23+
finding_type = drf_serializers.CharField(max_length=200)
24+
finding_code = drf_serializers.CharField()
25+
finding_code_type = drf_serializers.CharField(max_length=200)
26+

app_node_proj/vm_app/tests.py

+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
from django.test import TestCase
2+
3+
# Create your tests here.

app_node_proj/vm_app/urls.py

+15
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
from django.conf.urls import url
2+
from rest_framework.urlpatterns import format_suffix_patterns
3+
from vm_app import views
4+
5+
urlpatterns = [
6+
url(r'^node/$', views.NodeList.as_view()),
7+
url(r'^node/(?P<id>[a-fA-F0-9]+)/$', views.NodeDetails.as_view()),
8+
url(r'^node/add_finding/(?P<id>[a-fA-F0-9]+)/$', views.NodeAddFinding.as_view()),
9+
url(r'^node/risk_score/$', views.AllNodesRiskScore.as_view()),
10+
url(r'^node/risk_score/(?P<id>[a-fA-F0-9]+)/$', views.NodeRiskScore.as_view()),
11+
url(r'^node/risk_score/(?P<id>[a-fA-F0-9]+)/(?P<r_id>[a-fA-F0-9]+)/$', views.ResourceRiskScore.as_view()),
12+
]
13+
14+
urlpatterns = format_suffix_patterns(urlpatterns)
15+

app_node_proj/vm_app/views.py

+85
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,85 @@
1+
from vm_app.models import Node
2+
from vm_app.serializers import NodeSerializer, ResourceSerializer, FindingSerializer, NewFindingRequestSerializer
3+
from rest_framework_mongoengine import generics
4+
from rest_framework.response import Response
5+
from rest_framework.views import APIView
6+
from rest_framework import status
7+
8+
class NodeList(generics.ListCreateAPIView):
9+
queryset = Node.objects.all()
10+
serializer_class = NodeSerializer
11+
12+
class NodeDetails(generics.RetrieveUpdateDestroyAPIView):
13+
queryset = Node.objects.all()
14+
serializer_class = NodeSerializer
15+
16+
class NodeAddFinding(APIView):
17+
def get_object(self, id):
18+
return Node.objects.get(pk=id)
19+
20+
def patch(self, request, id, format=None):
21+
node = self.get_object(id)
22+
serializer = NewFindingRequestSerializer(data=request.data)
23+
if not serializer.is_valid():
24+
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
25+
req_resource = request.data['resource']
26+
finding_data = request.data.copy()
27+
del finding_data['resource']
28+
serializer = FindingSerializer(data=finding_data)
29+
if not serializer.is_valid():
30+
return Response(serializer.errors, status=status.HTTP_400_BAD_REQUEST)
31+
node.node_resources.get(resource=req_resource).findings.create(**finding_data) #ToDo: Use res_id (objectid) instead
32+
node.save()
33+
return Response(serializer.data, status=status.HTTP_201_CREATED)
34+
35+
class AllNodesRiskScore(APIView):
36+
def get_object(self):
37+
return Node.objects
38+
39+
def get(self, request, format=None):
40+
nodes = self.get_object()
41+
data = {"nodes": []}
42+
for node in nodes:
43+
node_data = {}
44+
node_data["id"] = str(node.id)
45+
node_data["node_name"] = node.node_name
46+
node_data["risk_score"] = node.risk_score()
47+
data["nodes"].append(node_data)
48+
return Response(data, status=status.HTTP_200_OK)
49+
50+
class NodeRiskScore(APIView):
51+
def get_object(self, id):
52+
return Node.objects.get(pk=id)
53+
54+
def get(self, request, id, format=None):
55+
node = self.get_object(id)
56+
data = {}
57+
data["id"] = str(node.id)
58+
data["node_name"] = node.node_name
59+
data["risk_score"] = node.risk_score()
60+
data["resources"] = []
61+
for resource in node.node_resources:
62+
serializer = ResourceSerializer(resource)
63+
resource_data = serializer.data
64+
del resource_data["findings"]
65+
resource_data["risk_score"] = resource.risk_score()
66+
data["resources"].append(resource_data)
67+
return Response(data, status=status.HTTP_200_OK)
68+
69+
class ResourceRiskScore(APIView):
70+
def get_object(self, id, r_id):
71+
return Node.objects.get(pk=id).node_resources.get(resource_id=r_id)
72+
73+
def get(self, request, id, r_id, format=None):
74+
res = self.get_object(id, r_id)
75+
data = {}
76+
data["id"] = id
77+
data["resource_id"] = str(res.resource_id)
78+
data["risk_score"] = res.risk_score()
79+
data["findings"] = []
80+
for finding in res.findings:
81+
serializer = FindingSerializer(finding)
82+
finding_data = serializer.data
83+
data["findings"].append(finding_data)
84+
return Response(data, status=status.HTTP_200_OK)
85+

0 commit comments

Comments
 (0)