Repository navigation
cravex2-reachability: Evaluate and implement rule-based tools for triaging vulnerabilities #1961
Description
Activity
- added sub-issues
on Jul 23, 2025 Also this rules system could be evolved in the future for other purposes... for instance:
- integrate reachability of course
- deal with license policies in a more fine grained way
- deal with license compatibility
- deal with other interesting events such as end-of-life/maintenance/support
- deal with other criteria such as code quality, projects vitality, dependency tree, etc.
Every rule will be a kind of decision tree, every rule will have results like {action, timeline}
Points - A - package.risk>1, B - package.vulnerablitiy.cwe=123, C- package.vulnerablitiy.epss>2
Decisions- Dec1: Do system upgrade, 24 hours ; Dec2: Forensic analysis, 3 daysRulset A
A,B,C D
YYY Dec1
YYN Dec2
YNY Dec2
YNN Dec1
NYY Dec2
NYN Dec1
NNY Dec2
NNN Dec1Rulset B
A,B,C D
YYY Dec2
YYN Dec2
YNY Dec2
YNN Dec1
NYY Dec2
NYN Dec1
NNY Dec2
NNN Dec1We will have some set of pre-defined rules as rulesets, one or more rulesets can be applied to a product/package
Every ruleset will have "precedence", in case 2 rules clash we will pick with higher priorityactions can be-
- label: Do system upgrade, and timeline: 1 days
Values:
- Upgarde
- Downgrade
- Forensic Analysis
- Reahability Analysis
Sort by timelines
For reference, building on SSVC see this from CISA:
This provides a concrete process with sensible steps:
Forensic Triage Steps- Step 1: Scoping
- Step 2: Preserve and Collect Evidence
- Step 3: Critical Patching and Stabilization
- Step 4: Contain and Control
- Step 5: Triage Analysis
- Step 6: Escalation Decision
This is done now
Completion report can be found in respective sub-issues
- cravex2-reachability: Create a design/evaluation doc for rules engines and policy engines #1962
- cravex2-reachability: Create code for the base framework to create rules/policies dejacode#364
- cravex2-reachability: Update UI and API code for rules and policies dejacode#365
- cravex2-reachability: Collect available SSVC in VulnerableCode/cravex2-reachability #1963
- cravex2-reachability: Integrate the SSVC scoring for decision trees-driven automation dejacode#366
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
The goal is to create an integrated, rule-based system to filter or rerank automatically the vulnerabilities in the context of the managed application, system or device. This will integrate the emerging SSVC scoring for decision tree-driven automation.
Practically this could look like this:
The rules would be eventually be user-configurable, and organized in a groups or profile. For instance, a set of rules could be for CRA compliance (and could be delivered as base set of rules built-in), or you have a set of rules for Mobile apps and another for internal apps or another for Fedramp compliance
Some things to check: