1 /*******************************************************************************
2 * Copyright (c) 2017 Politecnico di Torino and others.
4 * All rights reserved. This program and the accompanying materials
5 * are made available under the terms of the Apache License, Version 2.0
6 * which accompanies this distribution, and is available at
7 * http://www.apache.org/licenses/LICENSE-2.0
8 *******************************************************************************/
10 package mcnet.netobjs;
12 import java.util.ArrayList;
13 import java.util.List;
15 import com.microsoft.z3.BoolExpr;
16 import com.microsoft.z3.Context;
17 import com.microsoft.z3.DatatypeExpr;
18 import com.microsoft.z3.Expr;
19 import com.microsoft.z3.FuncDecl;
20 import com.microsoft.z3.IntExpr;
21 import com.microsoft.z3.Solver;
23 import mcnet.components.NetContext;
24 import mcnet.components.Network;
25 import mcnet.components.NetworkObject;
27 public class PolitoVpnExit extends NetworkObject {
29 List<BoolExpr> constraints = new ArrayList<BoolExpr>();
30 DatatypeExpr politoVpnExit;
31 FuncDecl private_addr_func;
36 public PolitoVpnExit(Context ctx, Object[]... args) {
41 public DatatypeExpr getZ3Node() {
46 protected void init(Context ctx, Object[]... args) {
48 this.isEndHost = false;
49 this.politoVpnExit = this.z3Node = ((NetworkObject)args[0][0]).getZ3Node();
50 this.net = (Network)args[0][1];
51 this.nctx = (NetContext)args[0][2];
55 protected void addConstraints(Solver solver) {
56 BoolExpr[] constr = new BoolExpr[constraints.size()];
57 solver.add(constraints.toArray(constr));
60 public void vpnAccessModel(DatatypeExpr vpnAccessIp, DatatypeExpr vpnExitIp) {
61 Expr x = ctx.mkConst("vpn_x", nctx.node);
62 Expr y = ctx.mkConst("vpn_y", nctx.node);
64 Expr p_0 = ctx.mkConst("vpn_p_0", nctx.packet);
65 Expr p_1 = ctx.mkConst("vpn_p_1", nctx.packet);
67 IntExpr t_0 = ctx.mkIntConst("vpn_t_0");
68 IntExpr t_1 = ctx.mkIntConst("vpn_t_1");
70 private_addr_func = ctx.mkFuncDecl("vpn_private_addr_func", nctx.address, ctx.mkBoolSort());
72 BoolExpr constraint1 = ctx.mkForall(new Expr[]{t_0, p_0, x},
73 ctx.mkImplies(ctx.mkAnd(
74 (BoolExpr)nctx.send.apply(politoVpnExit, x, p_0, t_0),
75 ctx.mkEq(nctx.pf.get("inner_src").apply(p_0), nctx.am.get("null"))),
77 (BoolExpr)private_addr_func.apply(nctx.pf.get("src").apply(p_0)),
78 ctx.mkNot((BoolExpr)nctx.pf.get("encrypted").apply(p_0)),
79 ctx.mkExists(new Expr[]{y, p_1, t_1},
80 ctx.mkAnd((BoolExpr)nctx.recv.apply(y, politoVpnExit, p_1, t_1),
82 (BoolExpr)nctx.pf.get("encrypted").apply(p_1),
83 ctx.mkEq(nctx.pf.get("src").apply(p_1), vpnAccessIp),
84 ctx.mkEq(nctx.pf.get("dest").apply(p_1), vpnExitIp),
85 ctx.mkEq(nctx.pf.get("inner_src").apply(p_1), nctx.pf.get("src").apply(p_0)),
86 ctx.mkEq(nctx.pf.get("inner_dest").apply(p_1), nctx.pf.get("dest").apply(p_0)),
87 ctx.mkEq(nctx.pf.get("origin").apply(p_1), nctx.pf.get("origin").apply(p_0)),
88 ctx.mkEq(nctx.pf.get("orig_body").apply(p_1), nctx.pf.get("orig_body").apply(p_0)),
89 ctx.mkEq(nctx.pf.get("body").apply(p_1), nctx.pf.get("body").apply(p_0)),
90 ctx.mkEq(nctx.pf.get("seq").apply(p_1), nctx.pf.get("seq").apply(p_0)),
91 ctx.mkEq(nctx.pf.get("proto").apply(p_1), nctx.pf.get("proto").apply(p_0)),
92 ctx.mkEq(nctx.pf.get("emailFrom").apply(p_1), nctx.pf.get("emailFrom").apply(p_0)),
93 ctx.mkEq(nctx.pf.get("url").apply(p_1), nctx.pf.get("url").apply(p_0)),
94 ctx.mkEq(nctx.pf.get("options").apply(p_1), nctx.pf.get("options").apply(p_0))), 1, null, null, null, null))),
95 1,null,null,null,null);
97 constraints.add(constraint1);
99 BoolExpr constraint2 = ctx.mkForall(new Expr[]{t_0, p_0, x},
100 ctx.mkImplies(ctx.mkAnd(
101 (BoolExpr)nctx.send.apply(politoVpnExit, x, p_0, t_0),
102 ctx.mkNot(ctx.mkEq(nctx.pf.get("inner_src").apply(p_0), nctx.am.get("null")))),
104 ctx.mkEq(nctx.pf.get("src").apply(p_0), vpnExitIp),
105 ctx.mkEq(nctx.pf.get("dest").apply(p_0), vpnAccessIp),
106 (BoolExpr)private_addr_func.apply(nctx.pf.get("dest").apply(p_0)),
107 ctx.mkNot(ctx.mkEq(nctx.pf.get("inner_dest").apply(p_1), vpnExitIp)),
108 (BoolExpr)nctx.pf.get("encrypted").apply(p_0),
109 ctx.mkExists(new Expr[]{y, p_1, t_1},
110 ctx.mkAnd((BoolExpr)nctx.recv.apply(y, politoVpnExit, p_1, t_1),
112 ctx.mkNot((BoolExpr)nctx.pf.get("encrypted").apply(p_1)),
113 ctx.mkEq(nctx.pf.get("src").apply(p_1), nctx.pf.get("inner_src").apply(p_0)),
114 ctx.mkEq(nctx.pf.get("dest").apply(p_1), nctx.pf.get("inner_dest").apply(p_0)),
115 ctx.mkEq(nctx.pf.get("inner_src").apply(p_1), nctx.am.get("null")),
116 ctx.mkEq(nctx.pf.get("inner_dest").apply(p_1), nctx.am.get("null")),
117 ctx.mkEq(nctx.pf.get("origin").apply(p_1), nctx.pf.get("origin").apply(p_0)),
118 ctx.mkEq(nctx.pf.get("orig_body").apply(p_1), nctx.pf.get("orig_body").apply(p_0)),
119 ctx.mkEq(nctx.pf.get("body").apply(p_1), nctx.pf.get("body").apply(p_0)),
120 ctx.mkEq(nctx.pf.get("seq").apply(p_1), nctx.pf.get("seq").apply(p_0)),
121 ctx.mkEq(nctx.pf.get("proto").apply(p_1), nctx.pf.get("proto").apply(p_0)),
122 ctx.mkEq(nctx.pf.get("emailFrom").apply(p_1), nctx.pf.get("emailFrom").apply(p_0)),
123 ctx.mkEq(nctx.pf.get("url").apply(p_1), nctx.pf.get("url").apply(p_0)),
124 ctx.mkEq(nctx.pf.get("options").apply(p_1), nctx.pf.get("options").apply(p_0))), 1, null, null, null, null))),
125 1,null,null,null,null);
127 constraints.add(constraint2);
130 public void setInternalAddress(ArrayList<DatatypeExpr> internalAddress){
131 List<BoolExpr> constr = new ArrayList<BoolExpr>();
132 Expr n_0 = ctx.mkConst("vpn_node", nctx.address);
134 for(DatatypeExpr n : internalAddress){
135 constr.add(ctx.mkEq(n_0,n));
137 BoolExpr[] constrs = new BoolExpr[constr.size()];
138 //Constraint private_addr_func(n_0) == or(n_0==n foreach internal address)
139 constraints.add(ctx.mkForall(new Expr[]{n_0}, ctx.mkEq(private_addr_func.apply(n_0),ctx.mkOr(constr.toArray(constrs))),1,null,null,null,null));