From 467059cd261f0172683c49aa4304a4ec8f617638 Mon Sep 17 00:00:00 2001 From: Lior Alafi Date: Wed, 15 Dec 2021 18:13:58 +0200 Subject: [PATCH 1/2] adding score --- go.mod | 2 +- go.sum | 3 ++- opaprocessor/processorhandler.go | 5 ++++- opaprocessor/processorhandlerutils.go | 2 +- resultshandling/results.go | 6 +++++- 5 files changed, 13 insertions(+), 5 deletions(-) diff --git a/go.mod b/go.mod index c215fd76..35ab11c2 100644 --- a/go.mod +++ b/go.mod @@ -5,7 +5,7 @@ go 1.17 require ( github.com/armosec/armoapi-go v0.0.23 github.com/armosec/k8s-interface v0.0.37 - github.com/armosec/opa-utils v0.0.64 + github.com/armosec/opa-utils v0.0.65 github.com/armosec/rbac-utils v0.0.9 github.com/armosec/utils-go v0.0.3 github.com/briandowns/spinner v1.16.0 diff --git a/go.sum b/go.sum index aa051b4d..d58b9c2f 100644 --- a/go.sum +++ b/go.sum @@ -89,8 +89,9 @@ github.com/armosec/armoapi-go v0.0.23/go.mod h1:iaVVGyc23QGGzAdv4n+szGQg3Rbpixn9 github.com/armosec/k8s-interface v0.0.8/go.mod h1:xxS+V5QT3gVQTwZyAMMDrYLWGrfKOpiJ7Jfhfa0w9sM= github.com/armosec/k8s-interface v0.0.37 h1:EPjzozpkVw0SmizoALmVg6D8VZIX7gcgTg+WxA02jNc= github.com/armosec/k8s-interface v0.0.37/go.mod h1:vHxGWqD/uh6+GQb9Sqv7OGMs+Rvc2dsFVc0XtgRh1ZU= -github.com/armosec/opa-utils v0.0.64 h1:RdiFpy6QqoTD2e9k5eIwgDrTWctUL215QI3ust8tnD0= github.com/armosec/opa-utils v0.0.64/go.mod h1:6tQP8UDq2EvEfSqh8vrUdr/9QVSCG4sJfju1SXQOn4c= +github.com/armosec/opa-utils v0.0.65 h1:wz9ruf/EjIqoedFBC0lnByKwD9BTlda4l+ircjniwP8= +github.com/armosec/opa-utils v0.0.65/go.mod h1:6tQP8UDq2EvEfSqh8vrUdr/9QVSCG4sJfju1SXQOn4c= github.com/armosec/rbac-utils v0.0.1/go.mod h1:pQ8CBiij8kSKV7aeZm9FMvtZN28VgA7LZcYyTWimq40= github.com/armosec/rbac-utils v0.0.9 h1:rIOWp4K7BELUNX32ktSjVbb8d/0SpH7W76W6Tf+8rzw= github.com/armosec/rbac-utils v0.0.9/go.mod h1:Ex/IdGWhGv9HZq6Hs8N/ApzCKSIvpNe/ETqDfnuyah0= diff --git a/opaprocessor/processorhandler.go b/opaprocessor/processorhandler.go index e2ac76c7..b3743321 100644 --- a/opaprocessor/processorhandler.go +++ b/opaprocessor/processorhandler.go @@ -8,6 +8,8 @@ import ( "github.com/armosec/kubescape/cautils" "github.com/armosec/opa-utils/objectsenvelopes" "github.com/armosec/opa-utils/reporthandling" + "github.com/armosec/opa-utils/score" + "github.com/golang/glog" "github.com/armosec/k8s-interface/k8sinterface" @@ -66,7 +68,8 @@ func (opaHandler *OPAProcessorHandler) ProcessRulesListenner() { // update score // opap.updateScore() - + scoreutil := score.NewScore(opaSessionObj.AllResources) + scoreutil.Calculate(opaSessionObj.PostureReport.FrameworkReports) // report *opaHandler.reportResults <- opaSessionObj } diff --git a/opaprocessor/processorhandlerutils.go b/opaprocessor/processorhandlerutils.go index 0d2159f4..6ddff1e4 100644 --- a/opaprocessor/processorhandlerutils.go +++ b/opaprocessor/processorhandlerutils.go @@ -28,7 +28,7 @@ func (opap *OPAProcessor) updateResults() { reporthandling.SetUniqueResourcesCounter(&opap.PostureReport.FrameworkReports[f]) // set default score - reporthandling.SetDefaultScore(&opap.PostureReport.FrameworkReports[f]) + // reporthandling.SetDefaultScore(&opap.PostureReport.FrameworkReports[f]) } } diff --git a/resultshandling/results.go b/resultshandling/results.go index 72d281b2..5dea6e4f 100644 --- a/resultshandling/results.go +++ b/resultshandling/results.go @@ -34,7 +34,11 @@ func (resultsHandler *ResultsHandler) HandleResults(scanInfo *cautils.ScanInfo) } // TODO - get score from table - score := CalculatePostureScore(opaSessionObj.PostureReport) + var score float32 = 0 + for i := range opaSessionObj.PostureReport.FrameworkReports { + score += opaSessionObj.PostureReport.FrameworkReports[i].Score + } + score /= float32(len(opaSessionObj.PostureReport.FrameworkReports)) resultsHandler.printerObj.Score(score) return score From 0aea384f419f8d325d5439cacb68f4d7fb23435d Mon Sep 17 00:00:00 2001 From: Lior Alafi Date: Wed, 15 Dec 2021 19:04:40 +0200 Subject: [PATCH 2/2] changed prettyprint to work with risk-score --- resultshandling/printer/prettyprinter.go | 47 ++++++++++++++---------- resultshandling/printer/summary.go | 9 +++-- 2 files changed, 33 insertions(+), 23 deletions(-) diff --git a/resultshandling/printer/prettyprinter.go b/resultshandling/printer/prettyprinter.go index 42b8a770..02148df7 100644 --- a/resultshandling/printer/prettyprinter.go +++ b/resultshandling/printer/prettyprinter.go @@ -18,7 +18,7 @@ type PrettyPrinter struct { summary Summary verboseMode bool sortedControlNames []string - frameworkSummary ControlSummary + frameworkSummary ResultSummary } func NewPrettyPrinter(verboseMode bool) *PrettyPrinter { @@ -35,15 +35,20 @@ func (printer *PrettyPrinter) ActionPrint(opaSessionObj *cautils.OPASessionObj) allResources := []string{} frameworkNames := []string{} + var overallRiskScore float32 = 0 for _, frameworkReport := range opaSessionObj.PostureReport.FrameworkReports { frameworkNames = append(frameworkNames, frameworkReport.Name) failedResources = reporthandling.GetUniqueResourcesIDs(append(failedResources, frameworkReport.ListResourcesIDs().GetFailedResources()...)) warningResources = reporthandling.GetUniqueResourcesIDs(append(warningResources, frameworkReport.ListResourcesIDs().GetWarningResources()...)) allResources = reporthandling.GetUniqueResourcesIDs(append(allResources, frameworkReport.ListResourcesIDs().GetAllResources()...)) printer.summarySetup(frameworkReport, opaSessionObj.AllResources) + overallRiskScore += frameworkReport.Score } - printer.frameworkSummary = ControlSummary{ + overallRiskScore /= float32(len(opaSessionObj.PostureReport.FrameworkReports)) + + printer.frameworkSummary = ResultSummary{ + RiskScore: overallRiskScore, TotalResources: len(allResources), TotalFailed: len(failedResources), TotalWarning: len(warningResources), @@ -73,7 +78,10 @@ func (printer *PrettyPrinter) summarySetup(fr reporthandling.FrameworkReport, al if printer.verboseMode { passedWorkloads = groupByNamespaceOrKind(workloadsSummary, workloadSummaryPassed) } - printer.summary[cr.Name] = ControlSummary{ + + //controlSummary + printer.summary[cr.Name] = ResultSummary{ + RiskScore: cr.Score, TotalResources: cr.GetNumberOfResources(), TotalFailed: cr.GetNumberOfFailedResources(), TotalWarning: cr.GetNumberOfWarningResources(), @@ -100,7 +108,7 @@ func (printer *PrettyPrinter) printResults() { } } -func (printer *PrettyPrinter) printSummary(controlName string, controlSummary *ControlSummary) { +func (printer *PrettyPrinter) printSummary(controlName string, controlSummary *ResultSummary) { cautils.SimpleDisplay(printer.writer, "Summary - ") cautils.SuccessDisplay(printer.writer, "Passed:%v ", controlSummary.TotalResources-controlSummary.TotalFailed-controlSummary.TotalWarning) cautils.WarningDisplay(printer.writer, "Excluded:%v ", controlSummary.TotalWarning) @@ -113,7 +121,7 @@ func (printer *PrettyPrinter) printSummary(controlName string, controlSummary *C } -func (printer *PrettyPrinter) printTitle(controlName string, controlSummary *ControlSummary) { +func (printer *PrettyPrinter) printTitle(controlName string, controlSummary *ResultSummary) { cautils.InfoDisplay(printer.writer, "[control: %s] ", controlName) if controlSummary.TotalResources == 0 { cautils.InfoDisplay(printer.writer, "resources not found %v\n", emoji.ConfusedFace) @@ -128,7 +136,7 @@ func (printer *PrettyPrinter) printTitle(controlName string, controlSummary *Con cautils.DescriptionDisplay(printer.writer, "Description: %s\n", controlSummary.Description) } -func (printer *PrettyPrinter) printResources(controlSummary *ControlSummary) { +func (printer *PrettyPrinter) printResources(controlSummary *ResultSummary) { if len(controlSummary.FailedWorkloads) > 0 { cautils.FailureDisplay(printer.writer, "Failed:\n") @@ -194,11 +202,11 @@ func generateRelatedObjectsStr(workload WorkloadSummary) string { return relatedStr } -func generateRow(control string, cs ControlSummary) []string { +func generateRow(control string, cs ResultSummary) []string { row := []string{control} row = append(row, cs.ToSlice()...) if cs.TotalResources != 0 { - row = append(row, fmt.Sprintf("%d%s", percentage(cs.TotalResources, cs.TotalFailed), "%")) + row = append(row, fmt.Sprintf("%.2f%s", cs.RiskScore, "%")) } else { row = append(row, EmptyPercentage) } @@ -206,7 +214,7 @@ func generateRow(control string, cs ControlSummary) []string { } func generateHeader() []string { - return []string{"Control Name", "Failed Resources", "Excluded Resources", "All Resources", "% success"} + return []string{"Control Name", "Failed Resources", "Excluded Resources", "All Resources", "% risk-score"} } func percentage(big, small int) int { @@ -218,18 +226,16 @@ func percentage(big, small int) int { } return int(float64(float64(big-small)/float64(big)) * 100) } -func generateFooter(numControlers, sumFailed, sumWarning, sumTotal int) []string { + +func generateFooter(printer *PrettyPrinter) []string { // Control name | # failed resources | all resources | % success row := []string{} row = append(row, "Resource Summary") //fmt.Sprintf(""%d", numControlers")) - row = append(row, fmt.Sprintf("%d", sumFailed)) - row = append(row, fmt.Sprintf("%d", sumWarning)) - row = append(row, fmt.Sprintf("%d", sumTotal)) - if sumTotal != 0 { - row = append(row, fmt.Sprintf("%d%s", percentage(sumTotal, sumFailed), "%")) - } else { - row = append(row, EmptyPercentage) - } + row = append(row, fmt.Sprintf("%d", printer.frameworkSummary.TotalFailed)) + row = append(row, fmt.Sprintf("%d", printer.frameworkSummary.TotalWarning)) + row = append(row, fmt.Sprintf("%d", printer.frameworkSummary.TotalResources)) + row = append(row, fmt.Sprintf("%.2f%s", printer.frameworkSummary.RiskScore, "%")) + return row } func (printer *PrettyPrinter) printSummaryTable(frameworksNames []string) { @@ -247,7 +253,10 @@ func (printer *PrettyPrinter) printSummaryTable(frameworksNames []string) { controlSummary := printer.summary[printer.sortedControlNames[i]] summaryTable.Append(generateRow(printer.sortedControlNames[i], controlSummary)) } - summaryTable.SetFooter(generateFooter(len(printer.summary), printer.frameworkSummary.TotalFailed, printer.frameworkSummary.TotalWarning, printer.frameworkSummary.TotalResources)) + + summaryTable.SetFooter(generateFooter(printer)) + + // summaryTable.SetFooter(generateFooter()) summaryTable.Render() } diff --git a/resultshandling/printer/summary.go b/resultshandling/printer/summary.go index 9b13b0dd..696ad406 100644 --- a/resultshandling/printer/summary.go +++ b/resultshandling/printer/summary.go @@ -7,13 +7,14 @@ import ( "github.com/armosec/opa-utils/reporthandling" ) -type Summary map[string]ControlSummary +type Summary map[string]ResultSummary func NewSummary() Summary { - return make(map[string]ControlSummary) + return make(map[string]ResultSummary) } -type ControlSummary struct { +type ResultSummary struct { + RiskScore float32 TotalResources int TotalFailed int TotalWarning int @@ -31,7 +32,7 @@ type WorkloadSummary struct { status string } -func (controlSummary *ControlSummary) ToSlice() []string { +func (controlSummary *ResultSummary) ToSlice() []string { s := []string{} s = append(s, fmt.Sprintf("%d", controlSummary.TotalFailed)) s = append(s, fmt.Sprintf("%d", controlSummary.TotalWarning))