Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(securitycenter): Add Resource SCC Management API Org ETD Custom Module code samples (Create, Delete, List, Get) #9743

Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
/*
* Copyright 2024 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package management.api;

// [START securitycenter_create_event_threat_detection_custom_module]
import com.google.cloud.securitycentermanagement.v1.CreateEventThreatDetectionCustomModuleRequest;
import com.google.cloud.securitycentermanagement.v1.EventThreatDetectionCustomModule;
import com.google.cloud.securitycentermanagement.v1.EventThreatDetectionCustomModule.EnablementState;
import com.google.cloud.securitycentermanagement.v1.SecurityCenterManagementClient;
import com.google.protobuf.ListValue;
import com.google.protobuf.Struct;
import com.google.protobuf.Value;
import java.io.IOException;
import java.util.HashMap;
import java.util.Map;

public class CreateEventThreatDetectionCustomModule {

public static void main(String[] args) throws IOException {
// https://cloud.google.com/security-command-center/docs/reference/security-center-management/rest/v1/organizations.locations.eventThreatDetectionCustomModules/create
// TODO: Developer should replace project_id with a real project ID before running this code
String projectId = "project_id";

String customModuleDisplayName = "custom_module_display_name";

createEventThreatDetectionCustomModule(projectId, customModuleDisplayName);
}

public static EventThreatDetectionCustomModule createEventThreatDetectionCustomModule(
minherz marked this conversation as resolved.
Show resolved Hide resolved
String projectId, String customModuleDisplayName) throws IOException {

// Initialize client that will be used to send requests. This client only needs
// to be created
// once, and can be reused for multiple requests.
try (SecurityCenterManagementClient client = SecurityCenterManagementClient.create()) {

// define the metadata and other config parameters severity, description,
// recommendation and ips below
Map<String, Value> metadata = new HashMap<>();
metadata.put("severity", Value.newBuilder().setStringValue("MEDIUM").build());
metadata.put(
"description", Value.newBuilder().setStringValue("add your description here").build());
metadata.put(
"recommendation",
Value.newBuilder().setStringValue("add your recommendation here").build());
Struct metadataStruct = Struct.newBuilder().putAllFields(metadata).build();

Struct configStruct =
Struct.newBuilder()
.putFields("metadata", Value.newBuilder().setStructValue(metadataStruct).build())
.putFields(
"ips",
Value.newBuilder()
.setListValue(
ListValue.newBuilder()
.addValues(Value.newBuilder().setStringValue("0.0.0.0").build())
.build())
.build())
.build();
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: I'd like to propose a refactoring that unifies the process of initiating the protobuf struct according to the typed format. On the side note I would suggest to open a bug here because using untyped protobuf is very strange.

Suggested change
Map<String, Value> metadata = new HashMap<>();
metadata.put("severity", Value.newBuilder().setStringValue("MEDIUM").build());
metadata.put(
"description", Value.newBuilder().setStringValue("add your description here").build());
metadata.put(
"recommendation",
Value.newBuilder().setStringValue("add your recommendation here").build());
Struct metadataStruct = Struct.newBuilder().putAllFields(metadata).build();
Struct configStruct =
Struct.newBuilder()
.putFields("metadata", Value.newBuilder().setStructValue(metadataStruct).build())
.putFields(
"ips",
Value.newBuilder()
.setListValue(
ListValue.newBuilder()
.addValues(Value.newBuilder().setStringValue("0.0.0.0").build())
.build())
.build())
.build();
Map<String, Value> metadata = Map.of(
"severity", Value.newBuilder().setStringValue("MEDIUM").build(),
"description",
Value.newBuilder().setStringValue("add your description here").build(),
"recommendation",
Value.newBuilder().setStringValue("add your recommendation here").build(),
);
List<Value> ips = List.of(Value.newBuilder().setStringValue("0.0.0.0").build());
Value metadataVal = Value.newBuilder()
.setStructValue(Struct.newBuilder().putAllFields(metadata).build()).build();
Value ipsValue = Value.newBuilder()
.setListValue(ListValue.newBuilder().addAllValues(ips).build());
Struct configStruct =
Struct.newBuilder()
.putFields("metadata", metadataVal)
.putFields("ips", ipsVal)
.build();

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed


// define the Event Threat Detection custom module configuration, update the EnablementState
// below
EventThreatDetectionCustomModule eventThreatDetectionCustomModule =
EventThreatDetectionCustomModule.newBuilder()
.setConfig(configStruct)
.setDisplayName(customModuleDisplayName)
.setEnablementState(EnablementState.ENABLED)
.setType("CONFIGURABLE_BAD_IP")
.build();

CreateEventThreatDetectionCustomModuleRequest request =
CreateEventThreatDetectionCustomModuleRequest.newBuilder()
.setParent(String.format("projects/%s/locations/global", projectId))
minherz marked this conversation as resolved.
Show resolved Hide resolved
.setEventThreatDetectionCustomModule(eventThreatDetectionCustomModule)
.build();

EventThreatDetectionCustomModule response =
client.createEventThreatDetectionCustomModule(request);

return response;
}
}
}
// [END securitycenter_create_event_threat_detection_custom_module]
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
/*
* Copyright 2024 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package management.api;

// [START securitycenter_delete_event_threat_detection_custom_module]
import com.google.cloud.securitycentermanagement.v1.DeleteEventThreatDetectionCustomModuleRequest;
import com.google.cloud.securitycentermanagement.v1.SecurityCenterManagementClient;
import java.io.IOException;

public class DeleteEventThreatDetectionCustomModule {

public static void main(String[] args) throws IOException {
// https://cloud.google.com/security-command-center/docs/reference/security-center-management/rest/v1/organizations.locations.eventThreatDetectionCustomModules/delete
// TODO: Developer should replace project_id with a real project ID before running this code
String projectId = "project_id";

String customModuleId = "custom_module_id";

deleteEventThreatDetectionCustomModule(projectId, customModuleId);
}

public static boolean deleteEventThreatDetectionCustomModule(
String projectId, String customModuleId) throws IOException {

// Initialize client that will be used to send requests. This client only needs
// to be created
// once, and can be reused for multiple requests.
try (SecurityCenterManagementClient client = SecurityCenterManagementClient.create()) {

String name =
String.format(
"projects/%s/locations/global/eventThreatDetectionCustomModules/%s",
projectId, customModuleId);

DeleteEventThreatDetectionCustomModuleRequest request =
DeleteEventThreatDetectionCustomModuleRequest.newBuilder().setName(name).build();

client.deleteEventThreatDetectionCustomModule(request);

return true;
}
}
}
// [END securitycenter_delete_event_threat_detection_custom_module]
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
/*
* Copyright 2024 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package management.api;

// [START securitycenter_get_event_threat_detection_custom_module]
import com.google.cloud.securitycentermanagement.v1.EventThreatDetectionCustomModule;
import com.google.cloud.securitycentermanagement.v1.GetEventThreatDetectionCustomModuleRequest;
import com.google.cloud.securitycentermanagement.v1.SecurityCenterManagementClient;
import java.io.IOException;

public class GetEventThreatDetectionCustomModule {

public static void main(String[] args) throws IOException {
// https://cloud.google.com/security-command-center/docs/reference/security-center-management/rest/v1/organizations.locations.eventThreatDetectionCustomModules/get
// TODO: Developer should replace project_id with a real project ID before running this code
String projectId = "project_id";

String customModuleId = "custom_module_id";

getEventThreatDetectionCustomModule(projectId, customModuleId);
}

public static EventThreatDetectionCustomModule getEventThreatDetectionCustomModule(
String projectId, String customModuleId) throws IOException {

// Initialize client that will be used to send requests. This client only needs
// to be created
// once, and can be reused for multiple requests.
try (SecurityCenterManagementClient client = SecurityCenterManagementClient.create()) {

String name =
String.format(
"projects/%s/locations/global/eventThreatDetectionCustomModules/%s",
projectId, customModuleId);

GetEventThreatDetectionCustomModuleRequest request =
GetEventThreatDetectionCustomModuleRequest.newBuilder().setName(name).build();

EventThreatDetectionCustomModule response =
client.getEventThreatDetectionCustomModule(request);

return response;
}
}
}
// [END securitycenter_get_event_threat_detection_custom_module]
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
/*
* Copyright 2024 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package management.api;

// [START securitycenter_list_event_threat_detection_custom_module]
import com.google.cloud.securitycentermanagement.v1.ListEventThreatDetectionCustomModulesRequest;
import com.google.cloud.securitycentermanagement.v1.SecurityCenterManagementClient;
import com.google.cloud.securitycentermanagement.v1.SecurityCenterManagementClient.ListEventThreatDetectionCustomModulesPagedResponse;
import java.io.IOException;

public class ListEventThreatDetectionCustomModules {

public static void main(String[] args) throws IOException {
// https://cloud.google.com/security-command-center/docs/reference/security-center-management/rest/v1/organizations.locations.eventThreatDetectionCustomModules/list
// TODO: Developer should replace project_id with a real project ID before running this code
String projectId = "project_id";

listEventThreatDetectionCustomModules(projectId);
}

public static ListEventThreatDetectionCustomModulesPagedResponse
listEventThreatDetectionCustomModules(String projectId) throws IOException {

// Initialize client that will be used to send requests. This client only needs
// to be created
// once, and can be reused for multiple requests.
try (SecurityCenterManagementClient client = SecurityCenterManagementClient.create()) {

ListEventThreatDetectionCustomModulesRequest request =
ListEventThreatDetectionCustomModulesRequest.newBuilder()
.setParent(String.format("projects/%s/locations/global", projectId))
.build();

ListEventThreatDetectionCustomModulesPagedResponse response =
client.listEventThreatDetectionCustomModules(request);

return response;
}
}
}
// [END securitycenter_list_event_threat_detection_custom_module]
Loading