2018-10-26 19:22:27 +03:00
|
|
|
import re
|
2019-05-30 23:53:17 +03:00
|
|
|
from ldap_access_log_humanizer.file_descriptor import FileDescriptor
|
|
|
|
from ldap_access_log_humanizer.operation import Operation
|
|
|
|
from ldap_access_log_humanizer.custom_logger import CustomLogger
|
2018-10-29 19:20:01 +03:00
|
|
|
|
2018-10-26 19:22:27 +03:00
|
|
|
|
|
|
|
class Connection:
|
2019-05-30 17:44:33 +03:00
|
|
|
def __init__(self, conn_id, args_dict):
|
2018-10-26 19:22:27 +03:00
|
|
|
self.conn_id = conn_id
|
|
|
|
self.time = ""
|
2018-11-01 07:34:21 +03:00
|
|
|
self.server = ""
|
|
|
|
self.process = ""
|
2018-10-31 18:26:40 +03:00
|
|
|
self.operations = {}
|
2019-06-05 17:10:23 +03:00
|
|
|
self.tls_status = False
|
2018-10-31 18:26:40 +03:00
|
|
|
self.file_descriptors = []
|
2019-05-30 17:44:33 +03:00
|
|
|
self.logger = CustomLogger(args_dict)
|
2019-09-24 22:06:40 +03:00
|
|
|
self.authenticated_status = False
|
2019-09-24 22:37:11 +03:00
|
|
|
self.user = ""
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-11-01 07:34:21 +03:00
|
|
|
def dict(self):
|
|
|
|
return {
|
|
|
|
"conn_id": self.conn_id,
|
|
|
|
"time": self.time,
|
|
|
|
"client": self.client(),
|
|
|
|
"server": self.server,
|
2019-09-24 22:06:40 +03:00
|
|
|
"tls": self.tls(),
|
2019-09-24 22:37:11 +03:00
|
|
|
"authenticated": self.authenticated(),
|
|
|
|
"user": self.user
|
2018-11-01 07:34:21 +03:00
|
|
|
}
|
|
|
|
|
2019-04-29 18:17:38 +03:00
|
|
|
def reconstitute(self, event_dict):
|
2018-11-01 07:34:21 +03:00
|
|
|
combined_dict = {}
|
|
|
|
combined_dict.update(self.dict())
|
|
|
|
combined_dict.update(event_dict)
|
|
|
|
return combined_dict
|
|
|
|
|
2019-09-24 22:06:40 +03:00
|
|
|
def authenticated(self):
|
2019-10-02 19:37:13 +03:00
|
|
|
mail_regex = r'.*mail=([a-zA-Z0-9._-]+@[a-zA-Z0-9._-]+\.[a-zA-Z0-9_-]+)'
|
|
|
|
uid_regex = r'.*uid=([a-zA-Z0-9._-]+)'
|
2019-09-24 22:37:11 +03:00
|
|
|
|
2019-09-24 22:06:40 +03:00
|
|
|
# requirements: single operation where we have a BIND verb followed by an LDAP_SUCCESS
|
2019-09-24 22:37:11 +03:00
|
|
|
for operation in self.operations.values():
|
2019-09-24 22:06:40 +03:00
|
|
|
for request in operation.requests:
|
2019-09-24 22:37:11 +03:00
|
|
|
if request.get("verb") == "BIND":
|
|
|
|
# Set user (even if they aren't authenticated, so we can track attempts)
|
|
|
|
for detail in request.get("details"):
|
2019-10-02 19:37:13 +03:00
|
|
|
mail_match_object = re.match(mail_regex, detail)
|
|
|
|
if mail_match_object:
|
|
|
|
self.user = mail_match_object.group(1)
|
|
|
|
|
|
|
|
uid_match_object = re.match(uid_regex, detail)
|
|
|
|
if uid_match_object:
|
|
|
|
self.user = uid_match_object.group(1)
|
2019-09-24 22:37:11 +03:00
|
|
|
|
|
|
|
# Set status if that user was successful
|
|
|
|
if operation.response_verb == "RESULT" and operation.error == "LDAP_SUCCESS":
|
|
|
|
self.authenticated_status = True
|
2019-09-24 22:06:40 +03:00
|
|
|
|
|
|
|
return self.authenticated_status
|
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def tls(self):
|
|
|
|
for file_descriptor in self.file_descriptors:
|
|
|
|
if file_descriptor.verb == "TLS" and file_descriptor.details.startswith("established"):
|
2019-06-05 17:10:23 +03:00
|
|
|
self.tls_status = True
|
2018-10-29 19:20:01 +03:00
|
|
|
|
2019-06-05 17:10:23 +03:00
|
|
|
return self.tls_status
|
2018-10-29 19:20:01 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def closed(self):
|
|
|
|
for file_descriptor in self.file_descriptors:
|
|
|
|
if file_descriptor.verb == "closed":
|
|
|
|
return True
|
2018-10-29 19:20:01 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
return False
|
2018-10-29 17:23:33 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def client(self):
|
|
|
|
for file_descriptor in self.file_descriptors:
|
|
|
|
if file_descriptor.verb == "ACCEPT":
|
|
|
|
pattern = r'from IP=(\d+\.\d+\.\d+\.\d+):'
|
|
|
|
match = re.search(pattern, file_descriptor.details)
|
2018-11-01 07:34:21 +03:00
|
|
|
if match:
|
2018-11-13 18:31:38 +03:00
|
|
|
return match.group(1)
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
return ""
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def add_operation(self, rest):
|
|
|
|
# Expecting something like:
|
|
|
|
# op=1 BIND dn="uid=bind-generateusers,ou=logins,dc=example" mech=SIMPLE ssf=0
|
|
|
|
#
|
|
|
|
pattern = r'^op=(\d+) (.*)$'
|
|
|
|
match = re.search(pattern, rest)
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
if match:
|
2018-11-13 18:31:38 +03:00
|
|
|
op_id = match.group(1)
|
2018-10-31 18:26:40 +03:00
|
|
|
operation = self.operations.get(int(op_id))
|
2018-10-29 17:23:33 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
# if an existing operation, update it's context
|
|
|
|
if operation:
|
2018-11-13 18:31:38 +03:00
|
|
|
operation.add_event(match.group(2))
|
2018-10-31 18:26:40 +03:00
|
|
|
# if a new operation, add it to our operations list
|
|
|
|
else:
|
|
|
|
operation = Operation(int(op_id))
|
2018-11-13 18:31:38 +03:00
|
|
|
operation.add_event(match.group(2))
|
2018-10-31 18:26:40 +03:00
|
|
|
self.operations[int(op_id)] = operation
|
2018-11-01 07:34:21 +03:00
|
|
|
|
|
|
|
if operation.loggable():
|
2019-04-29 18:17:38 +03:00
|
|
|
self.logger.log(self.reconstitute(operation.dict()))
|
2018-10-31 18:26:40 +03:00
|
|
|
else:
|
|
|
|
raise Exception('Malformed operation: {}'.format(rest))
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def add_file_descriptor(self, rest):
|
|
|
|
# Expecting something like:
|
|
|
|
# fd=34 ACCEPT from IP=192.168.1.1:56822 (IP=0.0.0.0:389)
|
|
|
|
#
|
|
|
|
pattern = r'^fd=(\d+) (.*)$'
|
2018-10-26 19:22:27 +03:00
|
|
|
match = re.search(pattern, rest)
|
|
|
|
|
|
|
|
if match:
|
2018-11-13 18:31:38 +03:00
|
|
|
file_descriptor = FileDescriptor(int(match.group(1)))
|
|
|
|
file_descriptor.add_event(match.group(2))
|
2018-10-31 18:26:40 +03:00
|
|
|
self.file_descriptors.append(file_descriptor)
|
2018-11-01 07:34:21 +03:00
|
|
|
|
|
|
|
if file_descriptor.loggable():
|
2019-04-29 18:17:38 +03:00
|
|
|
self.logger.log(self.reconstitute(file_descriptor.dict()))
|
2018-10-31 18:26:40 +03:00
|
|
|
else:
|
|
|
|
raise Exception('Malformed file file_descriptor: {}'.format(rest))
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
# Something happened, this method's job is to update the context
|
|
|
|
def add_event(self, event):
|
|
|
|
self.time = event['time']
|
|
|
|
self.server = event['server']
|
|
|
|
self.process = event['process']
|
|
|
|
self.add_rest(event['rest'])
|
2018-10-26 19:22:27 +03:00
|
|
|
|
2018-10-31 18:26:40 +03:00
|
|
|
def add_rest(self, rest):
|
|
|
|
if rest.startswith('op'):
|
|
|
|
self.add_operation(rest)
|
|
|
|
elif rest.startswith('fd'):
|
|
|
|
self.add_file_descriptor(rest)
|
2018-10-26 19:22:27 +03:00
|
|
|
else:
|
2018-10-31 18:26:40 +03:00
|
|
|
raise Exception('Unsupported option: {}'.format(rest))
|