mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 07:58:25 +08:00
fix(mxc): align OCSF audit example with driver config
- remove unsupported egress proxy settings - stop requiring the unavailable proxy audit event - update example documentation for supported event coverage Signed-off-by: Akber Raza <akberr@nvidia.com>
This commit is contained in:
@@ -16,7 +16,7 @@ WHAT THIS PROVES / PRODUCES
|
||||
|
||||
OCSF classes you will see:
|
||||
[6002] Application Lifecycle - sandbox created
|
||||
[5019] Device Config State Change - OS policy / hardening / proxy / console
|
||||
[5019] Device Config State Change - OS policy / hardening / console
|
||||
[1007] Process Activity - in-sandbox process launch (+ executable identity)
|
||||
[2004] Detection Finding - MXC setup activity errors (informational)
|
||||
|
||||
@@ -46,7 +46,7 @@ WHAT YOU GET BACK
|
||||
FILES IN THIS PACKAGE
|
||||
openshell-gateway.exe the gateway (self-contained; needs only VC++ runtime)
|
||||
openshell.exe the CLI
|
||||
mxc-ocsf-audit.toml gateway/driver config (process_container, etw_audit=true, egress proxy)
|
||||
mxc-ocsf-audit.toml gateway/driver config (process_container, etw_audit=true)
|
||||
ocsf-audit.yaml sandbox policy (read-write grant to the share dir)
|
||||
run-ocsf-audit.ps1 the orchestrator you run
|
||||
README-ocsf-audit.txt this file
|
||||
@@ -54,9 +54,6 @@ FILES IN THIS PACKAGE
|
||||
|
||||
USEFUL OPTIONS
|
||||
-SandboxCount <n> Create n sandboxes (default 2). More sandboxes = more events.
|
||||
-NoProxy Skip the per-sandbox egress proxy. This omits ONLY the
|
||||
SandboxProxyConfigured config event; everything else is
|
||||
still produced. (Default is proxy ON for the full set.)
|
||||
-ShareDir <path> Host folder granted read-write to the workload. The script
|
||||
derives a disposable policy and per-sandbox config for it.
|
||||
-WxcExecPath <path> Path to wxc-exec.exe on this box.
|
||||
@@ -69,9 +66,6 @@ NOTES
|
||||
that is unrelated to the OCSF audit path this example exercises.
|
||||
- A "supervisor session not connected" / ssh 255 message during sandbox create
|
||||
is EXPECTED on MXC and harmless - the agent already ran in-driver.
|
||||
- The proxy path requires the host-side CONNECT proxy and an absolute agent
|
||||
binary (the packaged config uses C:\Windows\System32\cmd.exe); the run script
|
||||
handles this for you.
|
||||
- The Sandboxing provider reports the sandbox entry-point process, not the full
|
||||
in-sandbox process tree. Deep process-tree auditing would need a second ETW
|
||||
source (Microsoft-Windows-Kernel-Process) and is out of scope for this trail.
|
||||
|
||||
@@ -9,9 +9,9 @@
|
||||
# Detection Finding [2004] — written to a durable JSONL log, just like the Linux
|
||||
# OCSF pipeline.
|
||||
#
|
||||
# run-ocsf-audit.ps1 patches wxc_exec_path, backend, etw_audit and the
|
||||
# egress-proxy switch into a disposable copy of this file. Workload command and
|
||||
# cwd are sandbox-scoped and passed separately through --driver-config-json.
|
||||
# run-ocsf-audit.ps1 patches wxc_exec_path, backend, and etw_audit into a
|
||||
# disposable copy of this file. Workload command and cwd are sandbox-scoped and
|
||||
# passed separately through --driver-config-json.
|
||||
|
||||
[openshell.drivers.mxc]
|
||||
# Path to wxc-exec.exe on the box (patched by the run script; default is the
|
||||
@@ -28,13 +28,3 @@ debug = false
|
||||
|
||||
# Turn ON the Plane-A ETW -> OCSF audit consumer. This is the core of the example.
|
||||
etw_audit = true
|
||||
|
||||
# Per-sandbox governed egress. Enabling this makes the driver start a host CONNECT
|
||||
# proxy and hand MXC a `network.proxy` redirect, which is what makes MXC emit the
|
||||
# SandboxProxyConfigured event — the config event mapped to OCSF CONFIG [5019]
|
||||
# that completes full event coverage. Requires backend = process_container and a
|
||||
# loopback (127.0.0.1) seed address; the driver allocates a unique ephemeral port
|
||||
# per sandbox from this seed. Run-ocsf-audit.ps1 disables this when passed
|
||||
# -NoProxy.
|
||||
egress_proxy = true
|
||||
egress_proxy_addr = "127.0.0.1:18080"
|
||||
|
||||
@@ -6,10 +6,6 @@
|
||||
# Minimal filesystem policy granting the workload folder read-write; everything
|
||||
# else is default-deny. run-ocsf-audit.ps1 copies this policy into the result
|
||||
# bundle and replaces the default grant with -ShareDir for that run.
|
||||
#
|
||||
# No network_policies block is needed here: the per-sandbox egress proxy is driven
|
||||
# by `egress_proxy = true` in mxc-ocsf-audit.toml (that is what makes MXC emit the
|
||||
# SandboxProxyConfigured event we map to OCSF), not by a policy rule.
|
||||
version: 1
|
||||
|
||||
filesystem_policy:
|
||||
|
||||
@@ -23,9 +23,6 @@
|
||||
# powershell -NoProfile -ExecutionPolicy Bypass -File .\run-ocsf-audit.ps1 `
|
||||
# -WxcExecPath C:\mxc-kit\bin\wxc-exec.exe
|
||||
#
|
||||
# By default the per-sandbox egress proxy is ON so the full event set (including
|
||||
# SandboxProxyConfigured) is produced. Pass -NoProxy to omit only that one event.
|
||||
#
|
||||
# The deliverable is the OCSF audit log (openshell-ocsf.<date>.log) inside the
|
||||
# results-*.zip the script produces. Pass -ShareOut '\\server\share' to also copy
|
||||
# the bundle to a shared location (off by default).
|
||||
@@ -38,8 +35,6 @@ param(
|
||||
[string] $ShareDir = "C:\work\openshell-mxc-demo",
|
||||
# How many sandboxes to create (each drives a full event burst).
|
||||
[int] $SandboxCount = 2,
|
||||
# Disable the per-sandbox egress proxy (omits the SandboxProxyConfigured event).
|
||||
[switch] $NoProxy,
|
||||
# Gateway bind port (matches the gateway default) + CLI registration name.
|
||||
[int] $Port = 17670,
|
||||
[string] $GatewayName = "openshell-mxc-ocsf",
|
||||
@@ -95,7 +90,6 @@ $helloPath = Join-Path $ShareDir "hello.txt"
|
||||
$gw = $null
|
||||
$gatewayEtwSessions = @()
|
||||
$passed = $true
|
||||
$proxyOn = -not $NoProxy
|
||||
|
||||
try {
|
||||
# 1. Validate artifacts + privilege.
|
||||
@@ -133,12 +127,6 @@ try {
|
||||
} else {
|
||||
$tomlText = [regex]::Replace($tomlText, '(?m)^\[openshell\.drivers\.mxc\]\s*$', "[openshell.drivers.mxc]`r`netw_audit = true")
|
||||
}
|
||||
$proxyVal = if ($proxyOn) { 'true' } else { 'false' }
|
||||
if ($tomlText -match '(?m)^\s*#?\s*egress_proxy\s*=') {
|
||||
$tomlText = [regex]::Replace($tomlText, '(?m)^\s*#?\s*egress_proxy\s*=.*$', "egress_proxy = $proxyVal")
|
||||
} else {
|
||||
$tomlText = [regex]::Replace($tomlText, '(?m)^\[openshell\.drivers\.mxc\]\s*$', "[openshell.drivers.mxc]`r`negress_proxy = $proxyVal")
|
||||
}
|
||||
Set-Content $toml -Value $tomlText -Encoding UTF8
|
||||
|
||||
$shareDirPolicy = $ShareDir.Replace('\', '/')
|
||||
@@ -168,7 +156,7 @@ try {
|
||||
$driverConfig
|
||||
}
|
||||
|
||||
Info "backend=process_container etw_audit=true egress_proxy=$proxyVal"
|
||||
Info "backend=process_container etw_audit=true"
|
||||
Info "workload cwd=$shareDirPolicy policy grant=$shareDirPolicy"
|
||||
|
||||
# 3. Port must be free. Auto-clear a stale OUR-gateway; refuse anything else.
|
||||
@@ -326,9 +314,7 @@ finally {
|
||||
# Event-type coverage (detected from the human-readable shorthand lines).
|
||||
function Seen([string]$pat) { [bool]($logText | Select-String -Pattern $pat -Quiet) }
|
||||
|
||||
# Expected happy-path ETW->OCSF event types for THIS run. The egress-proxy
|
||||
# event only fires when the proxy is enabled, so it only counts toward the
|
||||
# expected total when -NoProxy was NOT passed.
|
||||
# Expected happy-path ETW->OCSF event types for this run.
|
||||
$coreEvents = [ordered]@{
|
||||
"sandbox lifecycle (start)" = Seen "(?i)ocsf:.*LIFECYCLE:"
|
||||
"OS policy enforced" = Seen "(?i)ocsf:.*OS policy enforced"
|
||||
@@ -338,7 +324,6 @@ finally {
|
||||
"console reference plumbed" = Seen "(?i)ocsf:.*console reference plumbed"
|
||||
"process launch (executable identity)" = Seen "(?i)ocsf:.*PROC:LAUNCH"
|
||||
}
|
||||
if ($proxyOn) { $coreEvents["egress proxy configured"] = Seen "(?i)ocsf:.*proxy configured" }
|
||||
|
||||
# Findings are anomaly / fallback signals - reported separately, NOT part of
|
||||
# the expected-coverage denominator (a clean run may emit none).
|
||||
@@ -369,7 +354,6 @@ user : $env:USERNAME (admin=$admin perfLogUsers=$plu)
|
||||
verdict : $verdict
|
||||
event coverage : $coreObserved of $coreExpected expected event types fired (+ $findingsObserved anomaly finding(s))
|
||||
queue overload : $(if ($consumerOverloaded) { 'YES - ETW records dropped; audit coverage gap' } else { 'no dropped ETW records observed' })
|
||||
proxy : $(if ($proxyOn) { 'on (full event set)' } else { 'off (-NoProxy; omits egress proxy event)' })
|
||||
workload output : $(if ($workloadCompleted) { $helloPath } else { '(missing)' })
|
||||
wxc_exec : $WxcExecPath
|
||||
backend : process_container
|
||||
|
||||
Reference in New Issue
Block a user