Skip to main content

Description

Project description

Stix <-> TypeDB ORM

Explanation of Repo

This Repo is designed to make it easy to build, test and play with the Stix <-> TypeDB ORM. It is based around the OASIS Stix2 Python Library, and is an implementation of their datastore api (https://stix2.readthedocs.io/en/latest/api/stix2.datastore.html).

The implementation is minimal, it enables TypeDB to be setup as a Stix2 DataSink and DataSource, with implementation of both the DataSink init and add methods, and the DataSource init and get methods.

A number of features from the library are not developed yet, including combining the DataSource and DataSink into a DataStore, running filters on queries, loading from files and other methods.

Installation

Download and install using

pipenv install

then start the virtual environment with

pipenv shell    

Suggested Experiments

Examine and run the granular marking example with

python test.py

Notice how the granular marking input example, has different markings for each of the items in a list? Compare those indexes to the TypeQL statements and the final output. See how the indexes and the list are now reversed?

Examine how the ORM handles different shaped objects in the various directories. Check out:

  • examples directory: Granular markings versus Data Markings
  • standard directory: Email_mime, file_binary, file_ntfs_stream, network_ext_HTTP_request, X509_cert_v3_ext
  • threat_reports director: Check out the final report, and the size of the auto-generated relation

To do this, use

python check_dir.py

and scroll through the logging output. Change the directory name as needed to change the directory focus

Contents

There are 3 directories and some local files.

1. Stix Directory

The Stix directory contains the actual module needed to be integrated with the Stix2 python library.

The module sub-drectory has two files:

  1. Convert Stix to TypeQL Match, Insert: Lines 1-735
  2. Dispatch Dicts: Lines 735 - 1,980
  3. Retrieve Stage 2: Intermediate to Final Shape: Lines 1,980 to 2,580
  4. Retrieve Stage 1: TypeDB to Intermediate Shape: Lines 2,580 to 3,120

The schema sub directory has 3 files:

  • cti-schema-v2.tql - updated Tomas schema
  • cti-rules.tql - updated Tomas rules
  • initialise.py - updated initialise file

2. Data Directory

The data directory contains all of the test examples harvested from the web

3. Docs Directory

There are some markdown docs that contain incomplete documentation describing the transform between TypeDB and Stix names and structures,

4. Local Files

There are four local files:

  • test.py: Enables loading of individual data files, and retrieving of a single Stix_id. It is currently set to examine the Granular Markings and how polymorphic lists mean outputs lose their absolute order, but retain their relative order.
  • check_dir.py: Enables each data file in a a directory to be loaded into TypeDB, and then every object to be sequentially retrieved and printed. The process handles files with either bundles or lists of objects.
  • export_test.json: An export of the intermediate form of the last object to be retrieved from the datastore
  • export_final.json: An export of the final form of the last object to be retrieved from the datastore

5. Code information

TypeDB:

  • init() - create clean database with schema and marking objects loaded
  • add() - can add single objects, lists and bundles
  • get() - can get single object based on id
  • get_all_ids() - get all of the stix ids in the database as a list (except for marking objects)
  • delete () - delete a list of sitx ids, orders the records and checks for missing dependencies and circular references

Raw STIX method:

dep_match, dep_insert, indep_ql, core_ql, dep_obj = raw_stix2_to_typeql(local_obj, self.import_type)

Returned description:

  • dep_match: the matches needed for the new object that are dependent on other objects, already inserted
  • dep_insert: the inserts needed for the new objects that are dependent on matches with existing objects
  • indep-ql: the inserts for the new object that are indepdpent of other objects
  • core_ql: statements describing the main object and its stix id
  • dep_obj: The dependency object for this objects, used to order it in a list. Contains its own id, and a list of all of the ids it is dependent on (i.e. dependent objects must be added before, or deleted after, this object)

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stixorm-0.3.2.tar.gz (138.2 kB view details)

Uploaded Source

Built Distribution

stixorm-0.3.2-py3-none-any.whl (195.4 kB view details)

Uploaded Python 3

File details

Details for the file stixorm-0.3.2.tar.gz.

File metadata

  • Download URL: stixorm-0.3.2.tar.gz
  • Upload date:
  • Size: 138.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/4.0.2 CPython/3.11.6

File hashes

Hashes for stixorm-0.3.2.tar.gz
Algorithm Hash digest
SHA256 f511d69d679bbe944b9ad017a0dfff1bd6bd278bed063773bfcf5b7c8f2e283d
MD5 26810ccd6b0d0effb6c9540b173423fe
BLAKE2b-256 1925c79958380270ac23f5e0c3c5b3074bf8de3f63215d15f3afa58822e6e86a

See more details on using hashes here.

File details

Details for the file stixorm-0.3.2-py3-none-any.whl.

File metadata

  • Download URL: stixorm-0.3.2-py3-none-any.whl
  • Upload date:
  • Size: 195.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/4.0.2 CPython/3.11.6

File hashes

Hashes for stixorm-0.3.2-py3-none-any.whl
Algorithm Hash digest
SHA256 175becf34d718cbcbf28cd2002dc06dfc372d6b8561bc2e92b3c45a57ecbd6a4
MD5 72c0e176437f9a19a9f908a0390be266
BLAKE2b-256 7fef3a99fca258b0db9b79c94fecce7930ceddcf4c9195731799f539a1cb808d

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page