Skip to content

Commit 320e26d

Browse files
committed
fix: align SonicWall filter and rule contracts
1 parent 6c3af7e commit 320e26d

3 files changed

Lines changed: 164 additions & 0 deletions

File tree

‎filters/audits/sonicwall.md‎

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# SonicWall normalization and rule review
2+
3+
Validate standard IPs and translate numeric IP protocol identifiers.
4+
5+
This draft targets UTMStack `v11`. It contains 1 filter changes
6+
and 0 rule changes for this technology only. Review covered
7+
1 filter configurations and 7 matching shipped rule files.
8+
Unchanged rules are listed in the regression manifest; they are not duplicated in the diff.
9+
10+
## Contract and validation
11+
12+
- Compared exact standard names/types with go-sdk v1.1.31 and the supplied UTMStack dictionaries.
13+
- Checked documented pipeline ordering, rename/move behavior, open vendor log fields,
14+
event-side versus alert-side fields, and surviving fields used by affected rule predicates/history/grouping.
15+
- Strict SDK configuration decoding and actual CEL compilation pass for this scope.
16+
- 3 synthetic normalization cases pass, including SDK Event conversion and any
17+
trigger predicate assertions recorded in the manifest.
18+
- The scoped alerts module tests and `git diff --check` pass with the shared contract runner applied.
19+
20+
The shared alert-contract PR supplies the reusable Go runner for the manifest in
21+
`plugins/alerts/testdata/filter-contracts/sonicwall.json`. Apply that support before running `go test ./...` in `plugins/alerts`.
22+
23+
The model starts from synthetic extraction results. It does not run complex grok,
24+
JSON/KV/XML/CSV extraction, time conversion, dynamic plugins, historical OpenSearch
25+
queries, or the closed EventProcessor. Raw vendor logs and resulting alerts must
26+
still be checked in staging before rollout. No customer false-positive reduction
27+
has been measured and no production rollout is included.
28+
29+
30+
31+
## References
32+
33+
- [SDK schema](https://github.com/threatwinds/go-sdk/blob/v1.1.31/plugins/plugins.proto)
34+
- [Filter steps](https://github.com/threatwinds/go-sdk/wiki/Filter-Steps-Reference)
35+
- [Standard event schema](https://github.com/threatwinds/go-sdk/wiki/Standard-Event-Schema)
36+
- [Rule implementation](https://github.com/threatwinds/go-sdk/wiki/Implementing-Rules)
37+
38+
`afterEvents`, empty noncapturing grok names, supported numeric strings, and custom
39+
`log.*` fields are accepted. Existing textual protocol casing and vendor action names
40+
are preserved unless a concrete consumer mismatch requires correction.

‎filters/sonicwall/sonic_wall.yml‎

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -852,3 +852,68 @@ pipeline:
852852
- log.cefVersion
853853
- log.fwaction
854854
- log.grokTrash
855+
856+
# Keep addresses in IP fields and retain other source values under log.
857+
- rename:
858+
from:
859+
- origin.ip
860+
to: log.unparsedOriginIp
861+
where: exists("origin.ip") && (!(inCIDR("origin.ip","0.0.0.0/0") || inCIDR("origin.ip","::/0")) || oneOf("origin.ip",["0.0.0.0","::"]))
862+
- rename:
863+
from:
864+
- target.ip
865+
to: log.unparsedTargetIp
866+
where: exists("target.ip") && (!(inCIDR("target.ip","0.0.0.0/0") || inCIDR("target.ip","::/0")) || oneOf("target.ip",["0.0.0.0","::"]))
867+
- add:
868+
function: string
869+
params:
870+
key: protocol
871+
value: ICMP
872+
where: equals("protocol",1)
873+
- add:
874+
function: string
875+
params:
876+
key: protocol
877+
value: TCP
878+
where: equals("protocol",6)
879+
- add:
880+
function: string
881+
params:
882+
key: protocol
883+
value: UDP
884+
where: equals("protocol",17)
885+
- add:
886+
function: string
887+
params:
888+
key: protocol
889+
value: GRE
890+
where: equals("protocol",47)
891+
- add:
892+
function: string
893+
params:
894+
key: protocol
895+
value: ESP
896+
where: equals("protocol",50)
897+
- add:
898+
function: string
899+
params:
900+
key: protocol
901+
value: AH
902+
where: equals("protocol",51)
903+
- add:
904+
function: string
905+
params:
906+
key: protocol
907+
value: ICMPV6
908+
where: equals("protocol",58)
909+
- add:
910+
function: string
911+
params:
912+
key: protocol
913+
value: SCTP
914+
where: equals("protocol",132)
915+
- rename:
916+
from:
917+
- protocol
918+
to: log.ipProtocolNumber
919+
where: exists("protocol") && greaterOrEqual("protocol",0)
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
{
2+
"technology": "SonicWall",
3+
"filters": [
4+
"filters/sonicwall/sonic_wall.yml"
5+
],
6+
"rules": [
7+
"rules/sonicwall/sonicwall_firewall/anti_spyware_detection.yml",
8+
"rules/sonicwall/sonicwall_firewall/botnet_detection.yml",
9+
"rules/sonicwall/sonicwall_firewall/capture_atp_verdicts.yml",
10+
"rules/sonicwall/sonicwall_firewall/gateway_antivirus_detection.yml",
11+
"rules/sonicwall/sonicwall_firewall/intrusion_prevention_alert.yml",
12+
"rules/sonicwall/sonicwall_firewall/sonicwall_admin_auth_failures.yml",
13+
"rules/sonicwall/sonicwall_firewall/sonicwall_vpn_failures.yml"
14+
],
15+
"fixtures": [
16+
{
17+
"name": "sonicwall_valid_source_ip",
18+
"filter": "sonicwall/sonic_wall.yml",
19+
"input": {
20+
"origin": {
21+
"ip": "2001:db8::7"
22+
}
23+
},
24+
"expected": {
25+
"origin.ip": "2001:db8::7"
26+
},
27+
"absent": [],
28+
"rules": {}
29+
},
30+
{
31+
"name": "sonicwall_hostname_not_ip",
32+
"filter": "sonicwall/sonic_wall.yml",
33+
"input": {
34+
"origin": {
35+
"ip": "lab-host"
36+
}
37+
},
38+
"expected": {
39+
"log.unparsedOriginIp": "lab-host"
40+
},
41+
"absent": [
42+
"origin.ip"
43+
],
44+
"rules": {}
45+
},
46+
{
47+
"name": "sonicwall_numeric_protocol",
48+
"filter": "sonicwall/sonic_wall.yml",
49+
"input": {
50+
"protocol": 6
51+
},
52+
"expected": {
53+
"protocol": "TCP"
54+
},
55+
"absent": [],
56+
"rules": {}
57+
}
58+
]
59+
}

0 commit comments

Comments
 (0)