44 lines
1.5 KiB
Go
44 lines
1.5 KiB
Go
// SPDX-License-Identifier: GPL-3.0-or-later
|
|
|
|
package correlation
|
|
|
|
import (
|
|
"reflect"
|
|
"testing"
|
|
)
|
|
|
|
func TestCorrelateMultiStageIntrusion(t *testing.T) {
|
|
records := Correlate(Incident{
|
|
FirstTimestamp: 1000, LastTimestamp: 1050,
|
|
Signatures: []string{"host_rule.suspicious-egress", "exec_rule.web-rce"},
|
|
}, nil)
|
|
if len(records) != 1 || records[0].SID != SIDMultiStageIntrusion ||
|
|
!reflect.DeepEqual(records[0].MatchedSignatures,
|
|
[]string{"exec_rule.web-rce", "host_rule.suspicious-egress"}) {
|
|
t.Fatalf("unexpected correlation: %#v", records)
|
|
}
|
|
if records := Correlate(Incident{
|
|
FirstTimestamp: 1000, LastTimestamp: 1601,
|
|
Signatures: []string{"exec_rule.web-rce", "host_rule.suspicious-listener"},
|
|
}, nil); len(records) != 0 {
|
|
t.Fatalf("expired incident correlated: %#v", records)
|
|
}
|
|
}
|
|
|
|
func TestLineageAssignAndSeverity(t *testing.T) {
|
|
parents := map[int]int{42: 20, 20: 10, 10: 1}
|
|
lineage := LineageOf([]int{42}, func(pid int) int { return parents[pid] }, 8)
|
|
if !lineage[42] || !lineage[20] || !lineage[10] || lineage[1] {
|
|
t.Fatalf("unexpected lineage: %#v", lineage)
|
|
}
|
|
index := []IndexIncident{
|
|
{ID: "old", Host: "h", LastTimestamp: 1010, Lineage: []int{20}},
|
|
{ID: "new", Host: "h", LastTimestamp: 1020, Lineage: []int{10}},
|
|
}
|
|
if got := Assign(index, lineage, 1030, "h", 60); got != "new" {
|
|
t.Fatalf("unexpected assignment: %s", got)
|
|
}
|
|
if MaxSeverity("HIGH", "CRITICAL") != "CRITICAL" || MaxSeverity("unknown", "MEDIUM") != "MEDIUM" {
|
|
t.Fatal("severity ordering drifted")
|
|
}
|
|
}
|