diff --git a/README.md b/README.md index 47a1dc4..2d42065 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # DetLab -DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, and distributing behavioral detections across multiple security backends. +DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, distributing, and verifying behavioral detections across multiple security backends. ## Platform Capabilities @@ -12,72 +12,69 @@ DetLab is an advanced detection engineering platform for validating, translating - HTML analytics dashboards - Detection pack management - Pack registry workflows +- Pack trust verification - Governance reporting - CI/CD integration -## Detection Pack Registry +## Detection Pack Trust Verification -DetLab now supports registry-oriented detection pack workflows. +DetLab now supports integrity-oriented pack verification workflows. -## Pack Lifecycle +## Verification Workflow ```text -Build -> Publish -> Install -> Validate -> Analyze +Build -> Publish -> Verify -> Install -> Analyze ``` -## Supported Workflows +## Supported Verification Workflows -### Build Detection Pack +### Verify Detection Pack ```bash -detlab pack build packs/windows-core +detlab pack verify registry/windows-core-1.0.0.tar.gz \ + --metadata registry/windows-core.json ``` -Creates: -- distributable archives -- checksum metadata -- semantic version metadata +Supports: +- SHA256 verification +- Registry metadata validation +- Pack integrity validation +- Trust-oriented governance workflows -### Publish Detection Pack +## Example Trust Metadata -```bash -detlab pack publish packs/windows-core +```json +{ + "name": "windows-core", + "version": "1.0.0", + "checksum": "sha256-value", + "trust": { + "verified": true, + "algorithm": "sha256" + } +} ``` -Creates: -- registry archives -- registry metadata manifests -- reusable distributable bundles +## Detection Pack Registry -### Install Detection Pack +DetLab supports registry-oriented detection pack workflows. + +### Build Detection Pack ```bash -detlab pack install windows-core +detlab pack build packs/windows-core ``` -Supports: -- local registry cache -- reusable deployments -- portable content workflows - -## Registry Metadata Example +### Publish Detection Pack -```json -{ - "name": "windows-core", - "version": "1.0.0", - "checksum": "sha256-value", - "archive": "windows-core-1.0.0.tar.gz" -} +```bash +detlab pack publish packs/windows-core ``` -## Detection Pack Structure +### Install Detection Pack -```text -packs/ - windows-core/ - pack.yml - detections/ +```bash +detlab pack install windows-core ``` ## Behavioral Detection Example @@ -113,16 +110,17 @@ sequence: - Pack-level reporting - Behavioral analytics - Executive dashboards +- Pack integrity verification ## Long-Term Vision DetLab is evolving toward: -- community detection ecosystems -- reusable behavioral detection libraries - enterprise detection governance -- portable detection engineering pipelines -- threat-informed analytics platforms +- secure detection distribution ecosystems +- reusable behavioral detection libraries +- trusted security content pipelines +- portable detection engineering platforms ## License diff --git a/detlab/trust.py b/detlab/trust.py new file mode 100644 index 0000000..f9b9153 --- /dev/null +++ b/detlab/trust.py @@ -0,0 +1,44 @@ +from pathlib import Path +import json + +from detlab.registry import calculate_checksum + + + +def load_metadata(metadata_path: Path) -> dict: + return json.loads(metadata_path.read_text(encoding="utf-8")) + + + +def verify_checksum(archive_path: Path, expected_checksum: str) -> bool: + calculated = calculate_checksum(archive_path) + return calculated == expected_checksum + + + +def verify_pack(archive_path: Path, metadata_path: Path) -> dict: + metadata = load_metadata(metadata_path) + + expected_checksum = metadata.get("checksum") + verified = verify_checksum(archive_path, expected_checksum) + + return { + "name": metadata.get("name"), + "version": metadata.get("version"), + "verified": verified, + "checksum": expected_checksum, + "archive": archive_path.name, + } + + + +def generate_trust_metadata(name: str, version: str, checksum: str) -> dict: + return { + "name": name, + "version": version, + "checksum": checksum, + "trust": { + "verified": True, + "algorithm": "sha256", + }, + } diff --git a/tests/test_trust.py b/tests/test_trust.py new file mode 100644 index 0000000..cdfcfc2 --- /dev/null +++ b/tests/test_trust.py @@ -0,0 +1,44 @@ +import json +from pathlib import Path + +from detlab.trust import generate_trust_metadata, verify_checksum, verify_pack +from detlab.registry import calculate_checksum + + +def test_verify_checksum(tmp_path: Path): + archive = tmp_path / "pack.tar.gz" + archive.write_text("detlab-pack", encoding="utf-8") + + checksum = calculate_checksum(archive) + + assert verify_checksum(archive, checksum) is True + + +def test_verify_pack(tmp_path: Path): + archive = tmp_path / "windows-core-1.0.0.tar.gz" + archive.write_text("detlab-pack", encoding="utf-8") + + checksum = calculate_checksum(archive) + + metadata = { + "name": "windows-core", + "version": "1.0.0", + "checksum": checksum, + "archive": archive.name, + } + + metadata_path = tmp_path / "windows-core.json" + metadata_path.write_text(json.dumps(metadata), encoding="utf-8") + + result = verify_pack(archive, metadata_path) + + assert result["verified"] is True + assert result["name"] == "windows-core" + + +def test_generate_trust_metadata(): + metadata = generate_trust_metadata("windows-core", "1.0.0", "abc123") + + assert metadata["name"] == "windows-core" + assert metadata["trust"]["algorithm"] == "sha256" + assert metadata["trust"]["verified"] is True