This document outlines the items of the OVAL System Characteristics XML schema that are independent of any specific family or platform. Each iten is an extention of a basic System Characteristics item defined in the core System Characteristics XML schema.
The OVAL Schema is maintained by The Mitre Corporation and developed by the public OVAL Community. For more information, including how to get involved in the project and how to submit change requests, please visit the OVAL website at http://oval.mitre.org.
Independent System Characteristics
5.4
4/1/2008 10:41:41 AM
Copyright (c) 2002-2008, The MITRE Corporation. All rights reserved. The contents of this file are subject to the terms of the OVAL License located at http://oval.mitre.org/oval/about/termsofuse.html. See the OVAL License for the specific language governing permissions and limitations for use of this schema. When distributing copies of the OVAL Schema, this license header must be included.
schematron validation of the Independent portion of an OVAL System Characteristics file
This element stores high level system OS type, otherwise known as the family.
This element describes the name of an environment variable.
item - datatype attribute for the family entity of a family_item should be 'string'
This element stores md5 hash associated with a specific file.
This item has been deprecated. You should use the filehash_item instead. This item will be dropped in the major release of OVAL.
Specifies the absolute path to a file on the machine.
item - datatype attribute for the path entity of a filemd5_item should be 'string'
The name of the file.
item - datatype attribute for the filename entity of a filemd5_item should be 'string'
The md5 hash of the file
item - datatype attribute for the md5 entity of a filemd5_item should be 'string'
This element stores the different hash values associated with a specific file.
Specifies the absolute path to a file on the machine.
item - datatype attribute for the path entity of a filehash_item should be 'string'
The name of the file.
item - datatype attribute for the filename entity of a filehash_item should be 'string'
The md5 hash of the file
item - datatype attribute for the md5 entity of a filehash_item should be 'string'
The sha1 hash of the file
item - datatype attribute for the sha1 entity of a filehash_item should be 'string'
This item stores information about environment variables and their values.
This element describes the name of an environment variable.
item - datatype attribute for the name entity of an environmentvariable_item should be 'string'
The actual value of the specified environment variable.
- The datatype has been set to 'int' but the value is not an integer.
The sql_item outlines information collected from a database via an SQL query.
The engine entity identifies the specific database engine used to connect to the database.
item - datatype attribute for the engine entity of an sql_item should be 'string'
The version entity identifies the version of the database engine used to connect to the database.
item - datatype attribute for the version entity of an sql_item should be 'string'
The connection_string entity defines connection parameters used to connect to the specific database.
item - datatype attribute for the connection_string entity of an sql_item should be 'string'
The sql entity holds the specific query used to identify the object(s) in the database.
item - datatype attribute for the sql entity of an sql_item should be 'string'
The result entity specifies the result(s) of the given SQL query against the database.
- The datatype has been set to 'int' but the value is not an integer.
The textfilecontent_item looks at the contents of a text file (aka a configuration file) by looking at individual lines.
The path entity specifies the absolute path (without the filename) to the file that is being represented. Note that the trailing slash should be included.
item - datatype attribute for the path entity of a textfilecontent_item should be 'string'
The filename entity specifies the name of the file (without the path) that is being represented.
item - datatype attribute for the filename entity of a textfilecontent_item should be 'string'
The pattern entity represents a regular expression that is used to define a block of text. Subexpression notation (parenthesis) is used to call out a value(s) to test against. For example, the pattern abc(.*)xyz would look for a block of text in the file that starts with abc and ends with xyz, with the subexpression being all the characters that exist inbetween. Note that if the pattern can match more than one block of text starting at the same point, then it matches the longest. Subexpressions also match the longest possible substrings, subject to the constraint that the whole match be as long as possible, with subexpressions starting earlier in the pattern taking priority over ones starting later.
item - datatype attribute for the pattern entity of a textfilecontent_item should be 'string'
The instance entity calls out which match of the pattern is being represented by this item. The main purpose of this entity is too provide uniqueness for different textfilecontent_items that results from multiple matches of a given pattern against the same file.
item - datatype attribute for the instance entity of a textfilecontent_item should be 'int'
The line entity has been deprecated and will be removed in version 6.0 of the language.
The line element represents a line in the file and is represented using a regular expression.
item - datatype attribute for the line entity of a textfilecontent_item should be 'string'
The text entity represents the block of text that matched the specified pattern.
item - datatype attribute for the text entity of a textfilecontent_item should be 'string'
The subexpression entity represents the value of a subexpression in the specified pattern. If multiple subexpressions are specified in the pattern, then multiple entities are presented. Note that the textfilecontent_state in the definition schema only allows a single subexpression entity. This means that the test will check that all (or at least one, none, etc.) the subexpressions pass the same check. This means that the order of multiple subexpression entities in the item does not matter.
- The datatype has been set to 'int' but the value is not an integer.
This item stores information about OVAL Variables and their values.
The id of the variable.
item - datatype attribute for the var_ref entity of a variable_item should be 'string'
The value of the variable. If a variable represents and array of values, then multiple value elements should exist.
- The datatype has been set to 'int' but the value is not an integer.
This item stores results from checking the contents of an xml file.
Specifies the absolute path to a file on the machine.
item - datatype attribute for the path entity of a xmlfilecontent_item should be 'string'
The filename element specifies the name of the file.
item - datatype attribute for the filename entity of a xmlfilecontent_item should be 'string'
Specifies an Xpath expression describing the nodes to look at.
item - datatype attribute for the xpath entity of a xmlfilecontent_item should be 'string'
The value element checks the value of the nodes found. How this is used is entirely controlled by operator attributes.
item - datatype attribute for the value_of entity of a xmlfilecontent_item should be 'string'
The EntityItemEngineType complex type defines a string entity value that is restricted to a set of enumerations. Each valid enumeration is a valid database engine.
The EntityItemFamilyType complex type defines a string entity value that is restricted to a set of enumerations. Each valid enumeration is a high-level family of system operating system.
The EntityItemVariableRefType complex type defines a string item entity that has a valid OVAL variable id as the value.