Skip to content

Conversation

@AWSHurneyt
Copy link
Owner

Description

[Describe what this change achieves]

Issues Resolved

[List any issues this PR will resolve]

Check List

  • New functionality includes testing.
    • All tests pass
  • New functionality has been documented.
    • New functionality has javadoc added
  • Commits are signed per the DCO using --signoff

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

jowg-amazon and others added 30 commits June 5, 2024 23:05
Signed-off-by: Surya Sashank Nistala <[email protected]>
* Rough draft of IOC data model.

Signed-off-by: AWSHurneyt <[email protected]>

* Changed IOC value from a list to a string.

Signed-off-by: AWSHurneyt <[email protected]>

* Added validation for IOC type, value, and feedId fields.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored IocType to for ipv4, and ipv6.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored IocType.

Signed-off-by: AWSHurneyt <[email protected]>

* Added unit tests.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
* create tif source config api implementation

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* tif/source

Signed-off-by: Joanne Wang <[email protected]>

* fix uri

Signed-off-by: Joanne Wang <[email protected]>

* comments

Signed-off-by: Joanne Wang <[email protected]>

* fix error message

Signed-off-by: Joanne Wang <[email protected]>

* moved createIndex invocation and other comments

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* create tif source config api implementation

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* getTIFSourceConfig API

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* more cleanup

Signed-off-by: Joanne Wang <[email protected]>

* remove runner

Signed-off-by: Joanne Wang <[email protected]>

* add unit serialization tests

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* index threat intel  monitor api

Signed-off-by: Surya Sashank Nistala <[email protected]>

* address review comments

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
* search threat intel monitor api

Signed-off-by: Surya Sashank Nistala <[email protected]>

* delete threat intel monitor api

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
* job scheduler

Signed-off-by: Joanne Wang <[email protected]>

* remove refresh policy from request

Signed-off-by: Joanne Wang <[email protected]>

* comments

Signed-off-by: Joanne Wang <[email protected]>

* added security analytics runner

Signed-off-by: Joanne Wang <[email protected]>

* changes to js test and lock

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* Removed unused imports. Removed redundant helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Added note about system index refactoring.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented draft of IocService.

Signed-off-by: AWSHurneyt <[email protected]>

* Made changes based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed test helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused imports.

Signed-off-by: AWSHurneyt <[email protected]>

* Adjusted mappings based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
…#1073)

* wip index monitor still fails

* fix remote monitor setup in security-analytics

Signed-off-by: Subhobrata Dey <[email protected]>

* wip threat intel trigger

* add remote monitor triggers

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Co-authored-by: Subhobrata Dey <[email protected]>
* source and store

Signed-off-by: Joanne Wang <[email protected]>

* search feeds api

Signed-off-by: Joanne Wang <[email protected]>

* cleanup

Signed-off-by: Joanne Wang <[email protected]>

* address comments

Signed-off-by: Joanne Wang <[email protected]>

* rest of comments

---------

Signed-off-by: Joanne Wang <[email protected]>
* delete api

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* delete api integ test

Signed-off-by: Joanne Wang <[email protected]>

* added validation logic

Signed-off-by: Joanne Wang <[email protected]>

* respond to comments

Signed-off-by: Joanne Wang <[email protected]>

* fix merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

* fix merge conflicts

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* Removed unused imports. Removed redundant helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Added note about system index refactoring.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented draft of IocService.

Signed-off-by: AWSHurneyt <[email protected]>

* Made changes based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed test helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused imports.

Signed-off-by: AWSHurneyt <[email protected]>

* Adjusted mappings based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Continuation of fetch IOC service implementation.

Signed-off-by: AWSHurneyt <[email protected]>

* Continuation of fetch IOC service implementation.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented ListtIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed "enabled" field from ListIOCs API as that will not be configured at the IOC level.

Signed-off-by: AWSHurneyt <[email protected]>

* Renamed response keys.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed "enabled" field mapping as that will not be configured at the IOC level.

Signed-off-by: AWSHurneyt <[email protected]>

* Updated fetch service.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed ListIOCs API assets. Those will be included in separate PR.

Signed-off-by: AWSHurneyt <[email protected]>

* Updated IOC mappings.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused import.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored NO_VERSION.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed dev logs.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed TODO.

Signed-off-by: AWSHurneyt <[email protected]>

* Added junit-jupiter dependency so EnabledIfSystemProperty annotation can be used to disable S3-related integ tests.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed dev code.

Signed-off-by: AWSHurneyt <[email protected]>

* Added bug fix TODO.

Signed-off-by: AWSHurneyt <[email protected]>

* Added support for generating test IOCs of a specific type.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored factory used for connecting to S3. Added duration to fetchIOC response.

Signed-off-by: AWSHurneyt <[email protected]>

* Added integ test for fetching from s3.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed indexExists check.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
* Removed unused imports. Removed redundant helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Added note about system index refactoring.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented draft of IocService.

Signed-off-by: AWSHurneyt <[email protected]>

* Made changes based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed test helper function.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused imports.

Signed-off-by: AWSHurneyt <[email protected]>

* Adjusted mappings based on PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Continuation of fetch IOC service implementation.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented ListtIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed "enabled" field from ListIOCs API as that will not be configured at the IOC level.

Signed-off-by: AWSHurneyt <[email protected]>

* Renamed response keys.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed "enabled" field mapping as that will not be configured at the IOC level.

Signed-off-by: AWSHurneyt <[email protected]>

* Added feedId as a filter for LiistIOCs API. Added handling for IndexNotFoundException when calling ListIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented ListtIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed "enabled" field from ListIOCs API as that will not be configured at the IOC level.

Signed-off-by: AWSHurneyt <[email protected]>

* Renamed response keys.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused test suite.

Signed-off-by: AWSHurneyt <[email protected]>

* Added feedId as a filter for LiistIOCs API. Added handling for IndexNotFoundException when calling ListIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Added feedId as a filter for ListIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed merge conflict.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused test suite.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed test case.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed test index mappings.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
…ct#1078)

* refresh and update

Signed-off-by: Joanne Wang <[email protected]>

* clean up

Signed-off-by: Joanne Wang <[email protected]>

* change ID generation

Signed-off-by: Joanne Wang <[email protected]>

* comments

Signed-off-by: Joanne Wang <[email protected]>

* index create state and other comments

Signed-off-by: Joanne Wang <[email protected]>

* set states outside func

Signed-off-by: Joanne Wang <[email protected]>

* renamed model fields

Signed-off-by: Joanne Wang <[email protected]>

* lowercase s

Signed-off-by: Joanne Wang <[email protected]>

* added TODOs

Signed-off-by: Joanne Wang <[email protected]>

* respond to TODOs

Signed-off-by: Joanne Wang <[email protected]>

* remove file

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
… names (opensearch-project#1080)

* Implemented logic to update the IocStoreConfig with the saTifSourceConfig ID and IOC index names.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unused test suite.

Signed-off-by: AWSHurneyt <[email protected]>

* Added configId to error logs.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
* fix mappings

Signed-off-by: Joanne Wang <[email protected]>

* comment

Signed-off-by: Joanne Wang <[email protected]>

* fix comment

Signed-off-by: Joanne Wang <[email protected]>

* added java doc and todo

Signed-off-by: Joanne Wang <[email protected]>

* remove duplicate index names from mapping

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* fix integ test

Signed-off-by: Joanne Wang <[email protected]>

* fix mapping

Signed-off-by: Joanne Wang <[email protected]>

* add todo

Signed-off-by: Joanne Wang <[email protected]>

* change user type

Signed-off-by: Joanne Wang <[email protected]>

* change state and type to keyword

Signed-off-by: Joanne Wang <[email protected]>

* minor refactoring

Signed-off-by: Joanne Wang <[email protected]>

* fix existing tests

Signed-off-by: Joanne Wang <[email protected]>

* add serialization tests for tifsource config object

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* Moved "feed" variables from generic STIX2 model in SA-commons to STIX2IOC model as those variables are specific to security analytics functionality. Added feedName variables to STIX2IOC.

Signed-off-by: AWSHurneyt <[email protected]>

* Moved "feedId" variables back to generic STIX2 model in SA-commons. Moved "feedName" variables to generic STIX2 model in SA-commons.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
…#1085)

* Addressing PR comments.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed IOC type from the search bar param since we will offer a filter for it.

Signed-off-by: AWSHurneyt <[email protected]>

* Made feedId, and type params of ListIOCsActionRequest support lists of strings.

Signed-off-by: AWSHurneyt <[email protected]>

* Addressed PR feedback.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented DetailedSTIX2IOCDto for ListIOCs API.

Signed-off-by: AWSHurneyt <[email protected]>

* DetailedSTIX2IOCDto no longer extends STIX2IOCDto.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented basic unit tests for DetailedSTIX2IOCDto data model.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
* Implemented API to test s3 connection.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed comment.

Signed-off-by: AWSHurneyt <[email protected]>

* Updated permissions for communication with S3.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored TestS3ConnectionRequest to parse from an S3Source. Improved error message handling for failed connection attempts. Implemented integ tests.

Signed-off-by: AWSHurneyt <[email protected]>

* Removed unnecessary permissions from policy file.

Signed-off-by: AWSHurneyt <[email protected]>

* Revised S3 connection URI, and ListIOC API URI.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
…ct#1094)

* wip

Signed-off-by: Joanne Wang <[email protected]>

* comments

Signed-off-by: Joanne Wang <[email protected]>

* working

Signed-off-by: Joanne Wang <[email protected]>

* delete ioc indices for delete api

Signed-off-by: Joanne Wang <[email protected]>

* working rn

Signed-off-by: Joanne Wang <[email protected]>

* cleanup

Signed-off-by: Joanne Wang <[email protected]>

* comments

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* add search ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

add search ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

add search ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

add search ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

* fix review comments for ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

---------

Signed-off-by: Subhobrata Dey <[email protected]>
* ioc scan business logic

* add search ioc findings api

Signed-off-by: Subhobrata Dey <[email protected]>

* refactor iocFinding model and service to pull out CRUD operations to generic entity to re-use for threat intel alert

Signed-off-by: Surya Sashank Nistala <[email protected]>

* threat intel alert model and crud operations

Signed-off-by: Surya Sashank Nistala <[email protected]>

* threat intel trigger execution logic

* wire in ioc findings

* get threat intel monitor alerts API

Signed-off-by: Surya Sashank Nistala <[email protected]>

* revert commented out code

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Chase Engelbrecht <[email protected]>
Signed-off-by: Riya <[email protected]>
Signed-off-by: Riya Saxena <[email protected]>
Signed-off-by: Subhobrata Dey <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
Co-authored-by: Chase <[email protected]>
Co-authored-by: Riya <[email protected]>
Co-authored-by: Subhobrata Dey <[email protected]>
eirsep and others added 15 commits June 26, 2024 23:30
* fix list iocs api

Signed-off-by: Surya Sashank Nistala <[email protected]>

* fix list iocs api

Signed-off-by: Surya Sashank Nistala <[email protected]>

---------

Signed-off-by: Surya Sashank Nistala <[email protected]>
* ioc_upload

Signed-off-by: Joanne Wang <[email protected]>

* todos

Signed-off-by: Joanne Wang <[email protected]>

* fix upload to save then delete

Signed-off-by: Joanne Wang <[email protected]>

* fix the rollover name

Signed-off-by: Joanne Wang <[email protected]>

* fix response

Signed-off-by: Joanne Wang <[email protected]>

* fix background delete

Signed-off-by: Joanne Wang <[email protected]>

* wip

Signed-off-by: Joanne Wang <[email protected]>

* move iocs inside source

Signed-off-by: Joanne Wang <[email protected]>

* wip

Signed-off-by: Joanne Wang <[email protected]>

* change IntervalSchedule to schedule

Signed-off-by: Joanne Wang <[email protected]>

* add last refreshed time

Signed-off-by: Joanne Wang <[email protected]>

* comments and add listener to delete

Signed-off-by: Joanne Wang <[email protected]>

* remove extra version field

Signed-off-by: Joanne Wang <[email protected]>

* fix build after merge

Signed-off-by: Joanne Wang <[email protected]>

* add integ test

Signed-off-by: Joanne Wang <[email protected]>

* fix ioc created and mdoified parsing

Signed-off-by: Joanne Wang <[email protected]>

* add file name to source

Signed-off-by: Joanne Wang <[email protected]>

* fix state on update

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
* fix action names

Signed-off-by: Joanne Wang <[email protected]>

* lowercase threatintel for consistency

Signed-off-by: Joanne Wang <[email protected]>

* revert old tifjob name

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Surya Sashank Nistala <[email protected]>
* fix validation

Signed-off-by: Joanne Wang <[email protected]>

* switch case

Signed-off-by: Joanne Wang <[email protected]>

---------

Signed-off-by: Joanne Wang <[email protected]>
Signed-off-by: Joanne Wang <[email protected]>
…s commons directly from project rootDir. (opensearch-project#1114)

* Fixed validation bug.

Signed-off-by: AWSHurneyt <[email protected]>

* Fixed comment.

Signed-off-by: AWSHurneyt <[email protected]>

* Implemented support for making calls to S3 using either S3Client, or AmazonS3. Dependency on S3Client will eventually be removed.

Signed-off-by: AWSHurneyt <[email protected]>

* Refactored build.gradle to consume SA commons from jar in root directory.

Signed-off-by: AWSHurneyt <[email protected]>

* Updated jar.

Signed-off-by: AWSHurneyt <[email protected]>

---------

Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Signed-off-by: AWSHurneyt <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants