Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
*fs/
*.zip
.*
*.pdf
screenshots/
*.sh
6 changes: 5 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -89,4 +89,8 @@ ENV/
.ropeproject

# Pycharm project settings
.idea/
.idea/

#filesystem artifacts
data/
fs/
25 changes: 25 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
#FROM neo4j:3.0
FROM phusion/baseimage:0.11

#HTTP, HTTPS, Bolt
#EXPOSE 7474 7473 7687

RUN apt update \
&& apt upgrade -y \
&& apt install -y python-pip radare2

#WORKDIR /var/lib/neo4j
#ENV PATH /var/lib/neo4j/bin:$PATH
#RUN neo4j start \
# && sleep 5
#RUN curl -v -H "Content-Type: application/json" -X POST -d '{"password":"test"}' -u neo4j:neo4j http://localhost:7474/user/neo4j/password

WORKDIR /home/POLAR
COPY ["requirements.txt", "."]
RUN pip install -r requirements.txt

COPY [".", "."]
RUN python setup.py install
#RUN ["scan_data_dir.py"]

CMD ["/bin/bash"]
19 changes: 19 additions & 0 deletions EXAMPLE_Docker.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
* Example - Docker
** Structure
The docker scripts uses two containers: neo4j and polar. The neo4j docker holds the frontend GUI with a website at http://localhost:7474/
username: neo4j
password: test

once the neo4j container is running, the scripts updates its password to the non default "test" (don't use this for real!) and the launches the polar container.

the polar container is scanning all files copied to it from the data/ folder - and pushes metadata over bolt:// to the neo4j instance. as the analysis is complete - you can query the information in the frontend.

* Creating the filesystem
In order to run the Example in Docker you need to follow these steps (or use the scripts):

** "build.sh" script
The build script build the "polar" conatainer with all needed dependencies, and copies the filesystem from the data/ directory

** "run.sh" script
starts up the neo4j container, updating the default password.
the it runs the polar container, goes over each file, analyse it and send the information to neo4j. once the analysis is complete you can use the frontend to query the data
1 change: 1 addition & 0 deletions build.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
docker build -t polar_img:1 .
11 changes: 5 additions & 6 deletions polar/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,6 @@

# Define an Object that stores the Symbol Properties.
# A symbol can either be Used, Provided or Imported.

class Symbol(StructuredNode):
name = StringProperty(required=True)
user = RelationshipFrom('File', 'uses')
Expand Down Expand Up @@ -44,12 +43,12 @@ class Function(StructuredNode):

# First parameter is the filename (the string that is stored, second argument is the path)
# Were we will perform the activities

def get_import_export_radare(filename, path):
def get_import_export_radare(filepath):
_, filename = path.split(filepath)
# We define the node or get it if already exists, for further operations.
filenode = File.get_or_create({'name': filename})[0]
# By using r2, we open the file
r2 = r2pipe.open(path)
r2 = r2pipe.open(filepath)
# And *a*nalyze the *f*unctions
r2.cmd('af')
# and get *i*nformation, on the *i*mports in a *j*son format
Expand Down Expand Up @@ -117,7 +116,7 @@ def parse_main(args=None):
parser.add_argument("-db", "--neo4j-database",
help="neo4j database url",
dest="db_url",
default="bolt://neo4j:neo4j@localhost:7687")
default=config.DATABASE_URL)

parser.add_argument("-d", "--directories",
help="Directory to parse",
Expand Down Expand Up @@ -145,7 +144,7 @@ def disassemble_main(args=None):
parser.add_argument("-db", "--neo4j-database",
help="neo4j database url",
dest="db_url",
default="bolt://neo4j:neo4j@localhost:7687")
default=config.DATABASE_URL)

parser.add_argument("-f", "--function-tuples",
help="file:function tuples",
Expand Down
20 changes: 20 additions & 0 deletions run.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
#!/bin/bash
echo "Removing old containers"
docker stop neo4j polar 2>/dev/null
docker rm neo4j polar 2>/dev/null

echo "setup the neo4j instance"
docker run -d --rm --name neo4j --publish 7474:7474 --publish 7473:7473 --publish 7687:7687 neo4j:3.0
secs=$((5))
while [ $secs -gt 0 ]; do
echo -ne "."
sleep 1
: $((secs--))
done
curl -H "Content-Type: application/json" -d '{"password":"test"}' -u neo4j:neo4j http://localhost:7474/user/neo4j/password

echo "push data to the neo4j instance"
time docker run -it --name polar --link neo4j polar_img:1 python scan_data_dir.py
echo "complete"
echo
echo "Use neo4j:test to log into http://localhost:7474"
24 changes: 24 additions & 0 deletions scan_data_dir.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
from os import listdir, getcwd, path
from os.path import isfile, join, islink
from polar import get_import_export_radare, config
import multiprocessing as mp

cwd = getcwd()
config.DATABASE_URL = "bolt://neo4j:test@neo4j:7687"

directories = ['data/lib/',
'data/sbin/',
'data/usr/bin/',
'data/usr/lib/',
'data/usr/sbin/']

files = []
for directory in directories:
onlyfiles = [f for f in listdir(directory) if isfile(join(directory, f)) and not islink(join(directory, f))]
for file in onlyfiles:
files.append(path.join(cwd, directory, file))

cpus = mp.cpu_count()
print("Analysing %d files using %d CPUs" % (len(files), cpus))
pl = mp.Pool(processes=cpus)
results = pl.map(get_import_export_radare, files)
2 changes: 1 addition & 1 deletion setup.py
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@

with open(path.join(__folder__, 'README.md')) as ld_file:
long_description = ld_file.read()
ld_file.flush()
ld_file.close()

setup(
name='POLAR',
Expand Down