Class CommandSecurityChecker
The checker reads one or more rule resources and evaluates an input command line against those rules. Each non-empty, non-comment line of a deny-list file must use one of the following formats:
REGEX:...– a Java regular expression; a match anywhere in the command is considered dangerousKEYWORD:...– a case-insensitive substring match
This class provides a best-effort heuristic check. It should be used in addition to an allow-list and other host security controls. Instances load their rules during construction and are intended to be reused for subsequent command checks.
- Author:
- Viktor Tovstyi
-
Field Summary
FieldsModifier and TypeFieldDescriptionCase-insensitive keyword rules that reject matching command fragments.private static final StringConfiguration property whose value replaces or extends the loaded deny-list.Compiled regular-expression rules that reject matching command fragments.private static final org.slf4j.LoggerLogger used to report deny-list loading diagnostics. -
Constructor Summary
ConstructorsConstructorDescriptionCommandSecurityChecker(Configurator configurator) Creates a new checker and loads deny-list rules from an operating-system specific classpath resource. -
Method Summary
-
Field Details
-
DENYLIST_PROP_NAME
Configuration property whose value replaces or extends the loaded deny-list.When its value includes
ActProcessor.SUPER_VALUE_PLACEHOLDER, that placeholder is replaced with the operating-system-specific default rules.- See Also:
-
logger
private static final org.slf4j.Logger loggerLogger used to report deny-list loading diagnostics. -
denyPatterns
Compiled regular-expression rules that reject matching command fragments. -
denyKeywords
Case-insensitive keyword rules that reject matching command fragments.
-
-
Constructor Details
-
CommandSecurityChecker
Creates a new checker and loads deny-list rules from an operating-system specific classpath resource.The following resources are expected to exist on the classpath:
denylist/windows.txtwhen running on Windowsdenylist/unix.txtwhen running on a Unix-like OS
In addition, the host may provide
DENYLIST_PROP_NAMEto extend or override the default deny-list.- Parameters:
configurator- configurator used to optionally extend the deny-list; must not benull- Throws:
IOException- if the selected resource cannot be found or readIllegalArgumentException- if no deny-list is defined for the current operating systemNullPointerException- ifconfiguratorisnull
-
-
Method Details
-
loadRules
Loads deny-list rules from the provided string.This method is intended for internal initialization. Each rule is trimmed before parsing; blank lines and lines beginning with
#are ignored. AREGEX:rule is compiled as a Java regular expression, while aKEYWORD:rule is retained for case-insensitive substring matching. Rules with any other prefix are ignored.Empty strings and
nullvalues produce no rules and are logged as a warning. Existing rules are retained when this method is called again.- Parameters:
rulesString- string containing rule definitions, separated by line breaks; may benull- Throws:
PatternSyntaxException- if aREGEX:rule is not a valid Java regular expression
-
denyCheck
Checks whether the supplied command matches any deny-list rule.Regular-expression rules are evaluated first and match anywhere in the command. If none matches, keyword rules are evaluated as case-insensitive substring searches. If the command matches a rule, a
DenyExceptionis thrown containing a message identifying the matched rule; otherwise this method returns normally.- Parameters:
command- shell command to check; must not benull- Throws:
DenyException- if the command matches a deny-list ruleNullPointerException- ifcommandisnull
-