Search in sources :

Example 1 with Intro

use of com.ge.research.osate.verdict.dsl.verdict.Intro in project VERDICT by ge-high-assurance.

the class VerdictJavaValidator method checkThreatModel.

/**
 * Check that IDS are unique and non-empty and that top-level intro is a system.
 * Check that assumptions are unique.
 *
 * @param threatModel
 */
@Check(CheckType.FAST)
public void checkThreatModel(ThreatModel threatModel) {
    if (threatModel.getIntro().getType() != null && !threatModel.getIntro().getType().equals("system") && !threatModel.getIntro().getType().equals("connection")) {
        error("Top-level quantified variable must be a system or connection", VerdictPackage.Literals.THREAT_MODEL__INTRO);
    }
    if (threatModel.getId().length() == 0) {
        error("Threat model must specify an ID", VerdictPackage.Literals.THREAT_MODEL__ID);
    } else {
        // Check IDs unique
        Set<String> otherIds = new HashSet<>();
        // Find AADL package
        EObject container = threatModel;
        while (container != null && !(container instanceof PublicPackageSection)) {
            container = container.eContainer();
        }
        if (container instanceof PublicPackageSection) {
            // Find all verdict annex libraries
            for (AnnexLibrary library : ((PublicPackageSection) container).getOwnedAnnexLibraries()) {
                if ("verdict".equals(library.getName())) {
                    // Find all other threat model declarations
                    for (ThreatStatement other : ThreatModelUtil.getVerdictThreatModels(library).getStatements()) {
                        if (other instanceof ThreatModel && !threatModel.equals(other)) {
                            otherIds.add(((ThreatModel) other).getId());
                        }
                    }
                }
            }
        }
        if (otherIds.contains(threatModel.getId())) {
            error("Duplicate ID " + threatModel.getId(), VerdictPackage.Literals.THREAT_MODEL__ID);
        }
    }
    // Check for duplicate assumptions
    Map<CRVAssumption, Integer> assumptionCounts = new HashMap<>();
    for (CRVAssumption assumption : threatModel.getAssumptions()) {
        if (assumptionCounts.containsKey(assumption)) {
            assumptionCounts.put(assumption, assumptionCounts.get(assumption) + 1);
        } else {
            assumptionCounts.put(assumption, 1);
        }
    }
    int pos = 0;
    for (CRVAssumption assumption : threatModel.getAssumptions()) {
        if (assumptionCounts.get(assumption) > 1) {
            warning("Duplicate assumption: " + assumption.getLiteral(), VerdictPackage.Literals.THREAT_MODEL__ASSUMPTIONS, pos);
        }
        pos++;
    }
    if (threatModel.getReference() != null) {
        // We say that a reference string is valid if there is a valid database ID
        // that is a prefix string of that reference string
        Set<String> definedDatabases = ThreatModelUtil.getDefinedThreatDatabases(threatModel);
        if (!definedDatabases.stream().anyMatch(database -> threatModel.getReference().startsWith(database))) {
            error("Undefined threat database: " + threatModel.getReference(), VerdictPackage.Literals.THREAT_MODEL__REFERENCE);
        }
    }
}
Also used : SubcomponentType(org.osate.aadl2.SubcomponentType) Inject(com.google.inject.Inject) Event(com.ge.research.osate.verdict.dsl.verdict.Event) ThreatEqualContains(com.ge.research.osate.verdict.dsl.verdict.ThreatEqualContains) ThreatStatement(com.ge.research.osate.verdict.dsl.verdict.ThreatStatement) SafetyRel(com.ge.research.osate.verdict.dsl.verdict.SafetyRel) CyberRel(com.ge.research.osate.verdict.dsl.verdict.CyberRel) FExpr(com.ge.research.osate.verdict.dsl.verdict.FExpr) Classifier(org.osate.aadl2.Classifier) TargetLikelihood(com.ge.research.osate.verdict.dsl.verdict.TargetLikelihood) CyberReq(com.ge.research.osate.verdict.dsl.verdict.CyberReq) Map(java.util.Map) ComponentType(org.osate.aadl2.ComponentType) Check(org.eclipse.xtext.validation.Check) Var(com.ge.research.osate.verdict.dsl.verdict.Var) ThreatDefense(com.ge.research.osate.verdict.dsl.verdict.ThreatDefense) Set(java.util.Set) EObject(org.eclipse.emf.ecore.EObject) AadlPackage(org.osate.aadl2.AadlPackage) EPackage(org.eclipse.emf.ecore.EPackage) List(java.util.List) ResourceDescriptionsProvider(org.eclipse.xtext.resource.impl.ResourceDescriptionsProvider) PublicPackageSection(org.osate.aadl2.PublicPackageSection) Optional(java.util.Optional) VerdictUtil(com.ge.research.osate.verdict.dsl.VerdictUtil) SLPort(com.ge.research.osate.verdict.dsl.verdict.SLPort) AnnexLibrary(org.osate.aadl2.AnnexLibrary) ThreatModel(com.ge.research.osate.verdict.dsl.verdict.ThreatModel) CRVAssumption(com.ge.research.osate.verdict.dsl.verdict.CRVAssumption) SystemType(org.osate.aadl2.SystemType) HashMap(java.util.HashMap) SystemImplementation(org.osate.aadl2.SystemImplementation) ArrayList(java.util.ArrayList) HashSet(java.util.HashSet) CheckType(org.eclipse.xtext.validation.CheckType) ThreatDatabase(com.ge.research.osate.verdict.dsl.verdict.ThreatDatabase) FieldTypeResult(com.ge.research.osate.verdict.dsl.ThreatModelUtil.FieldTypeResult) LPort(com.ge.research.osate.verdict.dsl.verdict.LPort) Subcomponent(org.osate.aadl2.Subcomponent) CyberMission(com.ge.research.osate.verdict.dsl.verdict.CyberMission) VerdictVariable(com.ge.research.osate.verdict.dsl.type.VerdictVariable) Intro(com.ge.research.osate.verdict.dsl.verdict.Intro) Verdict(com.ge.research.osate.verdict.dsl.verdict.Verdict) Statement(com.ge.research.osate.verdict.dsl.verdict.Statement) VerdictThreatModels(com.ge.research.osate.verdict.dsl.verdict.VerdictThreatModels) VerdictType(com.ge.research.osate.verdict.dsl.type.VerdictType) SafetyReq(com.ge.research.osate.verdict.dsl.verdict.SafetyReq) ThreatModelUtil(com.ge.research.osate.verdict.dsl.ThreatModelUtil) AnnexSubclause(org.osate.aadl2.AnnexSubclause) PropertiesJavaValidator(org.osate.xtext.aadl2.properties.validation.PropertiesJavaValidator) VerdictPackage(com.ge.research.osate.verdict.dsl.verdict.VerdictPackage) HashMap(java.util.HashMap) PublicPackageSection(org.osate.aadl2.PublicPackageSection) ThreatStatement(com.ge.research.osate.verdict.dsl.verdict.ThreatStatement) EObject(org.eclipse.emf.ecore.EObject) CRVAssumption(com.ge.research.osate.verdict.dsl.verdict.CRVAssumption) AnnexLibrary(org.osate.aadl2.AnnexLibrary) HashSet(java.util.HashSet) ThreatModel(com.ge.research.osate.verdict.dsl.verdict.ThreatModel) Check(org.eclipse.xtext.validation.Check)

Example 2 with Intro

use of com.ge.research.osate.verdict.dsl.verdict.Intro in project VERDICT by ge-high-assurance.

the class VerdictJavaValidator method checkIntro.

/**
 * Check that the new ID doesn't shadow a previously-introduced variable
 * and that the type of the introduced variable is valid
 *
 * @param intro
 */
@Check(CheckType.FAST)
public void checkIntro(Intro intro) {
    EObject scopeParent = ThreatModelUtil.getContainerForClasses(intro, ThreatModelUtil.INTRO_SCOPE_PARENT_CLASSES);
    // Check that the new ID doesn't shadow a previously-introduced variable
    String id = intro.getId();
    // Find a variable in scope with the same ID
    Optional<VerdictVariable> shadowVar = ThreatModelUtil.getScope(scopeParent, indexProvider).stream().filter(v -> v.getId().equals(id)).findFirst();
    if (shadowVar.isPresent()) {
        warning("Shadowing var: " + id, VerdictPackage.Literals.INTRO__ID);
    }
    // Check that the type of the introduced variable is valid
    Optional<VerdictType> type = ThreatModelUtil.getIntroType(intro, indexProvider);
    if (!type.isPresent()) {
        error("Invalid type: " + intro.getType(), VerdictPackage.Literals.INTRO__TYPE);
    }
}
Also used : SubcomponentType(org.osate.aadl2.SubcomponentType) Inject(com.google.inject.Inject) Event(com.ge.research.osate.verdict.dsl.verdict.Event) ThreatEqualContains(com.ge.research.osate.verdict.dsl.verdict.ThreatEqualContains) ThreatStatement(com.ge.research.osate.verdict.dsl.verdict.ThreatStatement) SafetyRel(com.ge.research.osate.verdict.dsl.verdict.SafetyRel) CyberRel(com.ge.research.osate.verdict.dsl.verdict.CyberRel) FExpr(com.ge.research.osate.verdict.dsl.verdict.FExpr) Classifier(org.osate.aadl2.Classifier) TargetLikelihood(com.ge.research.osate.verdict.dsl.verdict.TargetLikelihood) CyberReq(com.ge.research.osate.verdict.dsl.verdict.CyberReq) Map(java.util.Map) ComponentType(org.osate.aadl2.ComponentType) Check(org.eclipse.xtext.validation.Check) Var(com.ge.research.osate.verdict.dsl.verdict.Var) ThreatDefense(com.ge.research.osate.verdict.dsl.verdict.ThreatDefense) Set(java.util.Set) EObject(org.eclipse.emf.ecore.EObject) AadlPackage(org.osate.aadl2.AadlPackage) EPackage(org.eclipse.emf.ecore.EPackage) List(java.util.List) ResourceDescriptionsProvider(org.eclipse.xtext.resource.impl.ResourceDescriptionsProvider) PublicPackageSection(org.osate.aadl2.PublicPackageSection) Optional(java.util.Optional) VerdictUtil(com.ge.research.osate.verdict.dsl.VerdictUtil) SLPort(com.ge.research.osate.verdict.dsl.verdict.SLPort) AnnexLibrary(org.osate.aadl2.AnnexLibrary) ThreatModel(com.ge.research.osate.verdict.dsl.verdict.ThreatModel) CRVAssumption(com.ge.research.osate.verdict.dsl.verdict.CRVAssumption) SystemType(org.osate.aadl2.SystemType) HashMap(java.util.HashMap) SystemImplementation(org.osate.aadl2.SystemImplementation) ArrayList(java.util.ArrayList) HashSet(java.util.HashSet) CheckType(org.eclipse.xtext.validation.CheckType) ThreatDatabase(com.ge.research.osate.verdict.dsl.verdict.ThreatDatabase) FieldTypeResult(com.ge.research.osate.verdict.dsl.ThreatModelUtil.FieldTypeResult) LPort(com.ge.research.osate.verdict.dsl.verdict.LPort) Subcomponent(org.osate.aadl2.Subcomponent) CyberMission(com.ge.research.osate.verdict.dsl.verdict.CyberMission) VerdictVariable(com.ge.research.osate.verdict.dsl.type.VerdictVariable) Intro(com.ge.research.osate.verdict.dsl.verdict.Intro) Verdict(com.ge.research.osate.verdict.dsl.verdict.Verdict) Statement(com.ge.research.osate.verdict.dsl.verdict.Statement) VerdictThreatModels(com.ge.research.osate.verdict.dsl.verdict.VerdictThreatModels) VerdictType(com.ge.research.osate.verdict.dsl.type.VerdictType) SafetyReq(com.ge.research.osate.verdict.dsl.verdict.SafetyReq) ThreatModelUtil(com.ge.research.osate.verdict.dsl.ThreatModelUtil) AnnexSubclause(org.osate.aadl2.AnnexSubclause) PropertiesJavaValidator(org.osate.xtext.aadl2.properties.validation.PropertiesJavaValidator) VerdictPackage(com.ge.research.osate.verdict.dsl.verdict.VerdictPackage) VerdictType(com.ge.research.osate.verdict.dsl.type.VerdictType) EObject(org.eclipse.emf.ecore.EObject) VerdictVariable(com.ge.research.osate.verdict.dsl.type.VerdictVariable) Check(org.eclipse.xtext.validation.Check)

Aggregations

ThreatModelUtil (com.ge.research.osate.verdict.dsl.ThreatModelUtil)2 FieldTypeResult (com.ge.research.osate.verdict.dsl.ThreatModelUtil.FieldTypeResult)2 VerdictUtil (com.ge.research.osate.verdict.dsl.VerdictUtil)2 VerdictType (com.ge.research.osate.verdict.dsl.type.VerdictType)2 VerdictVariable (com.ge.research.osate.verdict.dsl.type.VerdictVariable)2 CRVAssumption (com.ge.research.osate.verdict.dsl.verdict.CRVAssumption)2 CyberMission (com.ge.research.osate.verdict.dsl.verdict.CyberMission)2 CyberRel (com.ge.research.osate.verdict.dsl.verdict.CyberRel)2 CyberReq (com.ge.research.osate.verdict.dsl.verdict.CyberReq)2 Event (com.ge.research.osate.verdict.dsl.verdict.Event)2 FExpr (com.ge.research.osate.verdict.dsl.verdict.FExpr)2 Intro (com.ge.research.osate.verdict.dsl.verdict.Intro)2 LPort (com.ge.research.osate.verdict.dsl.verdict.LPort)2 SLPort (com.ge.research.osate.verdict.dsl.verdict.SLPort)2 SafetyRel (com.ge.research.osate.verdict.dsl.verdict.SafetyRel)2 SafetyReq (com.ge.research.osate.verdict.dsl.verdict.SafetyReq)2 Statement (com.ge.research.osate.verdict.dsl.verdict.Statement)2 TargetLikelihood (com.ge.research.osate.verdict.dsl.verdict.TargetLikelihood)2 ThreatDatabase (com.ge.research.osate.verdict.dsl.verdict.ThreatDatabase)2 ThreatDefense (com.ge.research.osate.verdict.dsl.verdict.ThreatDefense)2