Search in sources :

Example 6 with BlockImpl

use of verdict.vdm.vdm_model.BlockImpl in project VERDICT by ge-high-assurance.

the class VDM2Lustre method visit.

// B) Component Implementation Translated into Lustre Node
public void visit(ComponentImpl componentImpl, Node node) {
    NodeBody nodeBody = new NodeBody();
    // Option 1) Block Implementation
    // retrieve_block(componentImpl);
    BlockImpl blockImpl = componentImpl.getBlockImpl();
    // BlockImpl
    if (blockImpl != null) {
        ComponentType componentType = componentImpl.getType();
        for (ComponentInstance componentInstance : blockImpl.getSubcomponent()) {
            // replace to make naming compliant with lustre code
            String id = componentInstance.getId();
            id = id.replace(".", "_dot_");
            id = id.replace("::", "_double_colon_");
            componentInstance.setId(id);
            String name = componentInstance.getName();
            name = name.replace(".", "_dot_");
            name = name.replace("::", "_double_colon_");
            componentInstance.setName(name);
            componentType = componentInstance.getSpecification();
            ComponentImpl subcomponentImpl = componentInstance.getImplementation();
            if (componentType == null && subcomponentImpl == null) {
                System.out.println(componentInstance.getName() + " subcomponent is missing both a specification and an implemention.");
                System.out.println("Please provide some specification or an implementation to continue.");
                System.exit(-1);
            }
            // Option 1) Implementation
            if (subcomponentImpl != null) {
                componentType = subcomponentImpl.getType();
                if (!this.marked_types.contains(componentType)) {
                    visit(componentType, nodeBody, componentInstance.getId(), true);
                }
            } else // Option 2) Specification
            if (componentType != null) {
                if (!this.marked_types.contains(componentType)) {
                    visit(componentType, nodeBody, componentInstance.getId(), false);
                }
            }
        }
        for (Connection connection : blockImpl.getConnection()) {
            if (!ignoreConnection(connection)) {
                visit(connection, nodeBody);
            }
        }
    } else {
        // Option 2) DataFlow Implementation / NodeBody
        nodeBody = componentImpl.getDataflowImpl();
    // node.setBody(nodeBody);
    }
    node.setBody(nodeBody);
}
Also used : BlockImpl(verdict.vdm.vdm_model.BlockImpl) ComponentType(verdict.vdm.vdm_model.ComponentType) NodeBody(verdict.vdm.vdm_lustre.NodeBody) ComponentInstance(verdict.vdm.vdm_model.ComponentInstance) Connection(verdict.vdm.vdm_model.Connection) ComponentImpl(verdict.vdm.vdm_model.ComponentImpl)

Example 7 with BlockImpl

use of verdict.vdm.vdm_model.BlockImpl in project VERDICT by ge-high-assurance.

the class Instrumentor method softwareVirus.

// SV:
// - Select components c in the model M such that:
// c.ComponentType = 'Software' v c.ComponentType = 'Hybrid' & c.Manufacturer =
// 'ThirdParty'
// & \exists ch\in M. p\in InputPort(c). ch = p.channel & ch.Connectin-Type =
// Remote
@Override
public void softwareVirus(HashSet<ComponentType> vdm_components) {
    try {
        HashSet<String> components = new HashSet<String>();
        HashSet<String> svComponentTypeSet = new HashSet<String>(Arrays.asList("software", "swhwhybrid", "swhumanhybrid", "hybrid"));
        BlockImpl blockImpl = null;
        for (ComponentImpl componentImpl : vdm_model.getComponentImpl()) {
            blockImpl = componentImpl.getBlockImpl();
            // BlockImpl
            if (blockImpl != null) {
                ComponentType componentType = componentImpl.getType();
                for (ComponentInstance componentInstance : blockImpl.getSubcomponent()) {
                    componentType = componentInstance.getSpecification();
                    ComponentImpl subcomponentImpl = componentInstance.getImplementation();
                    // Option 1) Specification
                    if (componentType != null) {
                    } else // Option 2) Implementation
                    if (subcomponentImpl != null) {
                        componentType = subcomponentImpl.getType();
                    }
                    List<GenericAttribute> attributeList = componentInstance.getAttribute();
                    GenericAttribute componentKindAttribute = getAttributeByName(attributeList, "ComponentType", componentInstance.getName());
                    GenericAttribute staticCodeAnalysisAttribute = getAttributeByName(attributeList, "StaticCodeAnalysis", componentInstance.getName());
                    GenericAttribute inputValidationAttribute = getAttributeByName(attributeList, "InputValidation", componentInstance.getName());
                    GenericAttribute memoryProtectionAttribute = getAttributeByName(attributeList, "MemoryProtection", componentInstance.getName());
                    GenericAttribute secureBootAttribute = getAttributeByName(attributeList, "SecureBoot", componentInstance.getName());
                    String componentKind = componentKindAttribute.getValue().toString().toLowerCase();
                    int staticCodeAnalysis = Integer.parseInt(staticCodeAnalysisAttribute.getValue().toString());
                    int inputValidation = Integer.parseInt(inputValidationAttribute.getValue().toString());
                    int memoryProtection = Integer.parseInt(memoryProtectionAttribute.getValue().toString());
                    int secureBoot = Integer.parseInt(secureBootAttribute.getValue().toString());
                    if (svComponentTypeSet.contains(componentKind.toLowerCase()) && (staticCodeAnalysis == 0 || inputValidation == 0 || memoryProtection == 0 || secureBoot == 0)) {
                        Boolean hasEligibleIncomingChannels = false;
                        for (Port port : componentType.getPort()) {
                            PortMode mode = port.getMode();
                            if (mode == PortMode.IN) {
                                for (Connection connection : blockImpl.getConnection()) {
                                    if (connection.getDestination().getSubcomponentPort() != null) {
                                        if (connection.getDestination().getSubcomponentPort().getPort() == port) {
                                            Boolean scInsideTrustedBoundary;
                                            String scComponentKind;
                                            String scPedigree;
                                            int scStrongCryptoAlgorithms;
                                            int scSupplyChainSecurity;
                                            int scTamperProtection;
                                            if (connection.getSource().getSubcomponentPort() != null) {
                                                ComponentInstance sourceComponent = connection.getSource().getSubcomponentPort().getSubcomponent();
                                                List<GenericAttribute> sourceComponentAttributeList = sourceComponent.getAttribute();
                                                GenericAttribute sourceComponentInsideTrustedBoundaryAttribute = getAttributeByName(sourceComponentAttributeList, "InsideTrustedBoundary", sourceComponent.getName());
                                                GenericAttribute sourceComponentComponentKindAttribute = getAttributeByName(sourceComponentAttributeList, "ComponentType", sourceComponent.getName());
                                                GenericAttribute sourceComponentPedigreeAttribute = getAttributeByName(sourceComponentAttributeList, "Pedigree", sourceComponent.getName());
                                                GenericAttribute sourceComponentStrongCryptoAlgorithmsAttribute = getAttributeByName(sourceComponentAttributeList, "StrongCryptoAlgorithms", sourceComponent.getName());
                                                GenericAttribute sourceComponentSupplyChainSecurityAttribute = getAttributeByName(sourceComponentAttributeList, "SupplyChainSecurity", sourceComponent.getName());
                                                GenericAttribute sourceComponentTamperProtectionAttribute = getAttributeByName(sourceComponentAttributeList, "TamperProtection", sourceComponent.getName());
                                                scInsideTrustedBoundary = Boolean.parseBoolean(sourceComponentInsideTrustedBoundaryAttribute.getValue().toString());
                                                scComponentKind = sourceComponentComponentKindAttribute.getValue().toString().toLowerCase();
                                                scPedigree = sourceComponentPedigreeAttribute.getValue().toString().toLowerCase();
                                                scStrongCryptoAlgorithms = Integer.parseInt(sourceComponentStrongCryptoAlgorithmsAttribute.getValue().toString());
                                                scSupplyChainSecurity = Integer.parseInt(sourceComponentSupplyChainSecurityAttribute.getValue().toString());
                                                scTamperProtection = Integer.parseInt(sourceComponentTamperProtectionAttribute.getValue().toString());
                                            } else {
                                                scInsideTrustedBoundary = true;
                                                scComponentKind = "";
                                                scPedigree = "";
                                                scStrongCryptoAlgorithms = -1;
                                                scSupplyChainSecurity = -1;
                                                scTamperProtection = -1;
                                            }
                                            List<GenericAttribute> connectionAttributeList = connection.getAttribute();
                                            GenericAttribute connectionTypeAttribute = getAttributeByName(connectionAttributeList, "ConnectionType", connection.getName());
                                            GenericAttribute deviceAuthenticationAttribute = getAttributeByName(connectionAttributeList, "DeviceAuthentication", connection.getName());
                                            GenericAttribute sessionAuthenticityAttribute = getAttributeByName(connectionAttributeList, "SessionAuthenticity", connection.getName());
                                            String connectionType = connectionTypeAttribute.getValue().toString().toLowerCase();
                                            int deviceAuthentication = Integer.parseInt(deviceAuthenticationAttribute.getValue().toString());
                                            int sessionAuthenticity = Integer.parseInt(sessionAuthenticityAttribute.getValue().toString());
                                            if ((!scInsideTrustedBoundary || connectionType.equalsIgnoreCase("untrusted")) && !scComponentKind.equalsIgnoreCase("hardware") && ((scPedigree.equalsIgnoreCase("cots") || (scPedigree.equalsIgnoreCase("sourced") && scSupplyChainSecurity == 0 && scTamperProtection == 0)) || ((deviceAuthentication == 0 && sessionAuthenticity == 0) || scStrongCryptoAlgorithms == 0))) {
                                                hasEligibleIncomingChannels = true;
                                            }
                                            break;
                                        }
                                    }
                                }
                            }
                            if (hasEligibleIncomingChannels) {
                                break;
                            }
                        }
                        if (hasEligibleIncomingChannels) {
                            vdm_components.add(componentType);
                            components.add(componentType.getId());
                        }
                    }
                }
            }
        }
        this.attack_cmp_link_map.put("SV", components);
    } catch (CRVException e) {
        System.out.println("\tCRV Error " + e.getCode() + " " + e.getMessage());
    }
}
Also used : BlockImpl(verdict.vdm.vdm_model.BlockImpl) ComponentType(verdict.vdm.vdm_model.ComponentType) PortMode(verdict.vdm.vdm_model.PortMode) CompInstancePort(verdict.vdm.vdm_model.CompInstancePort) Port(verdict.vdm.vdm_model.Port) GenericAttribute(verdict.vdm.vdm_data.GenericAttribute) Connection(verdict.vdm.vdm_model.Connection) ComponentImpl(verdict.vdm.vdm_model.ComponentImpl) ComponentInstance(verdict.vdm.vdm_model.ComponentInstance) HashSet(java.util.HashSet)

Example 8 with BlockImpl

use of verdict.vdm.vdm_model.BlockImpl in project VERDICT by ge-high-assurance.

the class Instrumentor method networkInjection.

// NI:
// - Select all channels ch in the model M such that:
// ch.ConnectionType = Remote & ch.Connection-Encrypted = False &
// ch.Connection-Authentication = False
// 
// - Select all channels ch in CH such that:
// (ch.start.insideTrustedBoundary = false and ch.connectionType = Remote)
// and ((ch.deviceAuthentication = 0 and ch.sessionAuthenticity = 0) or
// ch.start.strongCryptoAlgorithms = 0)
@Override
public void networkInjection(HashSet<Connection> vdm_links) {
    try {
        HashSet<String> links = new HashSet<String>();
        BlockImpl blockImpl = null;
        for (ComponentImpl componentImpl : vdm_model.getComponentImpl()) {
            blockImpl = componentImpl.getBlockImpl();
            // BlockImpl
            if (blockImpl != null) {
                // Selection channels (Authentication = OFF & DataEncrypted = OFF)
                for (Connection connection : blockImpl.getConnection()) {
                    boolean insideTrustedBoundary;
                    int strongCryptoAlgorithms;
                    if (connection.getSource().getSubcomponentPort() != null) {
                        ComponentInstance sourceComponent = connection.getSource().getSubcomponentPort().getSubcomponent();
                        List<GenericAttribute> sourceComponentAttributeList = sourceComponent.getAttribute();
                        GenericAttribute insideTrustedBoundaryAttribute = getAttributeByName(sourceComponentAttributeList, "InsideTrustedBoundary", sourceComponent.getName());
                        GenericAttribute strongCryptoAlgorithmsAttribute = getAttributeByName(sourceComponentAttributeList, "StrongCryptoAlgorithms", sourceComponent.getName());
                        insideTrustedBoundary = Boolean.parseBoolean(insideTrustedBoundaryAttribute.getValue().toString());
                        strongCryptoAlgorithms = Integer.parseInt(strongCryptoAlgorithmsAttribute.getValue().toString());
                    } else {
                        insideTrustedBoundary = true;
                        strongCryptoAlgorithms = 1;
                    }
                    List<GenericAttribute> connectionAttributeList = connection.getAttribute();
                    GenericAttribute connectionTypeAttribute = getAttributeByName(connectionAttributeList, "ConnectionType", connection.getName());
                    GenericAttribute deviceAuthenticationAttribute = getAttributeByName(connectionAttributeList, "DeviceAuthentication", connection.getName());
                    GenericAttribute sessionAuthenticityAttribute = getAttributeByName(connectionAttributeList, "SessionAuthenticity", connection.getName());
                    String connectionType = connectionTypeAttribute.getValue().toString().toLowerCase();
                    int deviceAuthentication = Integer.parseInt(deviceAuthenticationAttribute.getValue().toString());
                    int sessionAuthenticity = Integer.parseInt(sessionAuthenticityAttribute.getValue().toString());
                    if ((!insideTrustedBoundary || connectionType.equalsIgnoreCase("untrusted")) && ((deviceAuthentication == 0 && sessionAuthenticity == 0) || strongCryptoAlgorithms == 0)) {
                        vdm_links.add(connection);
                        links.add(connection.getName());
                    }
                }
            }
        }
        for (Connection con : vdm_links) {
            if (!isProbePort(con)) {
                links.addAll(get_ports(con));
            }
        }
        this.attack_cmp_link_map.put("NI", links);
    } catch (CRVException e) {
        System.out.println("\tCRV Error " + e.getCode() + " " + e.getMessage());
    }
}
Also used : BlockImpl(verdict.vdm.vdm_model.BlockImpl) Connection(verdict.vdm.vdm_model.Connection) ComponentInstance(verdict.vdm.vdm_model.ComponentInstance) GenericAttribute(verdict.vdm.vdm_data.GenericAttribute) ComponentImpl(verdict.vdm.vdm_model.ComponentImpl) HashSet(java.util.HashSet)

Example 9 with BlockImpl

use of verdict.vdm.vdm_model.BlockImpl in project VERDICT by ge-high-assurance.

the class Instrumentor method outsiderThreat.

// OT
// - Select all components c in C such that:
// c.componentType is in {Human, SwHumanHybrid, Hybrid, HwHumanHybrid}
// and c.insideTrustBoundary = false and c.physicalAccessControl = 0
// and (c.logging = 0 and (c.systemAccessControl = 0 and c.userAuthentication = 0))
@Override
public void outsiderThreat(HashSet<ComponentType> vdm_components) {
    try {
        HashSet<String> components = new HashSet<String>();
        HashSet<String> otComponentTypeSet = new HashSet<String>(Arrays.asList("human", "swhumanhybrid", "hwhumanhybrid", "hybrid"));
        BlockImpl blockImpl = null;
        for (ComponentImpl componentImpl : vdm_model.getComponentImpl()) {
            blockImpl = componentImpl.getBlockImpl();
            // BlockImpl
            if (blockImpl != null) {
                ComponentType componentType = componentImpl.getType();
                for (ComponentInstance componentInstance : blockImpl.getSubcomponent()) {
                    componentType = getType(componentInstance);
                    List<GenericAttribute> attributeList = componentInstance.getAttribute();
                    GenericAttribute componentKindAttribute = getAttributeByName(attributeList, "ComponentType", componentInstance.getName());
                    GenericAttribute insideTrustedBoundaryAttribute = getAttributeByName(attributeList, "InsideTrustedBoundary", componentInstance.getName());
                    GenericAttribute physicalAccessControlAttribute = getAttributeByName(attributeList, "PhysicalAccessControl", componentInstance.getName());
                    GenericAttribute loggingAttribute = getAttributeByName(attributeList, "Logging", componentInstance.getName());
                    GenericAttribute systemAccessControlAttribute = getAttributeByName(attributeList, "SystemAccessControl", componentInstance.getName());
                    GenericAttribute userAuthenticationAttribute = getAttributeByName(attributeList, "UserAuthentication", componentInstance.getName());
                    String componentKind = componentKindAttribute.getValue().toString().toLowerCase();
                    Boolean insideTrustedBoundary = Boolean.parseBoolean(insideTrustedBoundaryAttribute.getValue().toString());
                    int physicalAccessControl = Integer.parseInt(physicalAccessControlAttribute.getValue().toString());
                    int logging = Integer.parseInt(loggingAttribute.getValue().toString());
                    int systemAccessControl = Integer.parseInt(systemAccessControlAttribute.getValue().toString());
                    int userAuthentication = Integer.parseInt(userAuthenticationAttribute.getValue().toString());
                    if (otComponentTypeSet.contains(componentKind) && !insideTrustedBoundary && physicalAccessControl == 0 && (logging == 0 && (systemAccessControl == 0 || userAuthentication == 0))) {
                        // Store component
                        vdm_components.add(componentType);
                        components.add(componentType.getId());
                    // instrument_component(componentType, blockImpl);
                    }
                }
            }
        }
        this.attack_cmp_link_map.put("OT", components);
    } catch (CRVException e) {
        System.out.println("\tCRV Error " + e.getCode() + " " + e.getMessage());
    }
}
Also used : BlockImpl(verdict.vdm.vdm_model.BlockImpl) ComponentType(verdict.vdm.vdm_model.ComponentType) ComponentInstance(verdict.vdm.vdm_model.ComponentInstance) GenericAttribute(verdict.vdm.vdm_data.GenericAttribute) ComponentImpl(verdict.vdm.vdm_model.ComponentImpl) HashSet(java.util.HashSet)

Example 10 with BlockImpl

use of verdict.vdm.vdm_model.BlockImpl in project VERDICT by ge-high-assurance.

the class Instrumentor method locationSpoofing.

// LS:
// - Select all components c in C such that:
// c.category = GPS or c.category = IMU or c.category = LIDAR or c.category = LOCATION_DEVICE
@Override
public void locationSpoofing(HashSet<ComponentType> vdm_components) {
    try {
        HashSet<String> components = new HashSet<String>();
        HashSet<String> locIdentificationDeviceSet = new HashSet<String>(Arrays.asList("gps", "dme_vor", "iru", "lidar", "imu"));
        BlockImpl blockImpl = null;
        for (ComponentImpl componentImpl : vdm_model.getComponentImpl()) {
            blockImpl = componentImpl.getBlockImpl();
            // BlockImpl
            if (blockImpl != null) {
                ComponentType componentType = componentImpl.getType();
                for (ComponentInstance componentInstance : blockImpl.getSubcomponent()) {
                    componentType = componentInstance.getSpecification();
                    ComponentImpl subcomponentImpl = componentInstance.getImplementation();
                    // Option 1) Specification
                    if (componentType != null) {
                    } else // Option 2) Implementation
                    if (subcomponentImpl != null) {
                        componentType = subcomponentImpl.getType();
                    }
                    List<GenericAttribute> attributeList = componentInstance.getAttribute();
                    GenericAttribute componentCategoryAttribute = getAttributeByName(attributeList, "Category", componentInstance.getName());
                    String componentCategory = componentCategoryAttribute.getValue().toString();
                    if (locIdentificationDeviceSet.contains(componentCategory.toLowerCase())) {
                        vdm_components.add(componentType);
                        components.add(componentType.getId());
                    }
                }
            }
        }
        this.attack_cmp_link_map.put("LS", components);
    } catch (CRVException e) {
        System.out.println("\tCRV Error " + e.getCode() + " " + e.getMessage());
    }
}
Also used : BlockImpl(verdict.vdm.vdm_model.BlockImpl) ComponentType(verdict.vdm.vdm_model.ComponentType) ComponentInstance(verdict.vdm.vdm_model.ComponentInstance) GenericAttribute(verdict.vdm.vdm_data.GenericAttribute) ComponentImpl(verdict.vdm.vdm_model.ComponentImpl) HashSet(java.util.HashSet)

Aggregations

BlockImpl (verdict.vdm.vdm_model.BlockImpl)17 ComponentImpl (verdict.vdm.vdm_model.ComponentImpl)17 ComponentInstance (verdict.vdm.vdm_model.ComponentInstance)17 ComponentType (verdict.vdm.vdm_model.ComponentType)16 HashSet (java.util.HashSet)9 GenericAttribute (verdict.vdm.vdm_data.GenericAttribute)8 Connection (verdict.vdm.vdm_model.Connection)5 CompInstancePort (verdict.vdm.vdm_model.CompInstancePort)3 Port (verdict.vdm.vdm_model.Port)3 PortMode (verdict.vdm.vdm_model.PortMode)2 ArrayList (java.util.ArrayList)1 HashMap (java.util.HashMap)1 List (java.util.List)1 DataType (verdict.vdm.vdm_data.DataType)1 ConstantDeclaration (verdict.vdm.vdm_lustre.ConstantDeclaration)1 ContractItem (verdict.vdm.vdm_lustre.ContractItem)1 ContractSpec (verdict.vdm.vdm_lustre.ContractSpec)1 Expression (verdict.vdm.vdm_lustre.Expression)1 LustreProgram (verdict.vdm.vdm_lustre.LustreProgram)1 NodeBody (verdict.vdm.vdm_lustre.NodeBody)1