Predicting attack paths using code analysis
Predicting attack paths using code analysis, including: detecting a vulnerability in code by performing a static code analysis of the code; identifying an attack surface for the vulnerability in a cloud deployment; and generating an alert for the vulnerability by assigning a priority to the alert based on the attack surface.
1 . A method of predicting attack paths using code analysis, the method comprising:
detecting a vulnerability in code by performing a static code analysis of the code;
identifying an attack surface for the vulnerability in a cloud deployment; and
generating an alert for the vulnerability by assigning a priority to the alert using one or more rules based on the attack surface, wherein the priority is assigned to the alert as part of generating the alert.
2 . The method of claim 1 , wherein the priority for the alert is assigned relative to a size of the attack surface.
3 . The method of claim 1 , wherein code comprises application code.
4 . The method of claim 1 , wherein code comprises infrastructure-as-code (IaC) code.
5 . The method of claim 1 , wherein the code comprises deployed code and wherein identifying the attack surface for the vulnerability comprises identifying any compute assets of the cloud deployment having the vulnerability.
6 . The method of claim 1 , wherein the code comprises undeployed code and wherein identifying the attack surface for the vulnerability comprises identifying any compute assets of the cloud deployment that would have the vulnerability were the code deployed.
7 . The method of claim 3 , wherein identifying the attack surface for the vulnerability comprises:
generating a fingerprint based on a repository for an application associated with the code; and identifying any compute assets in the cloud deployment matching the fingerprint.
8 . The method of claim 7 , wherein the fingerprint is based on a listing of packages included in the application.
9 . The method of claim 1 , wherein detecting the vulnerability in code by performing the static code analysis of the code comprises determining whether a vulnerable method in the code is statically reachable.
10 . The method of claim 9 , wherein identifying the attack surface for the vulnerability comprises identifying, based on the vulnerable method being statically reachable, any compute assets in the cloud deployment in which the vulnerability is exploitable.
11 . A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to:
detect a vulnerability in code by performing a static code analysis of the code;
identify an attack surface for the vulnerability in a cloud deployment; and
generate an alert for the vulnerability by assigning a priority to the alert using one or more rules based on the attack surface, wherein the priority is assigned to the alert as part of generating the alert.
12 . The non-transitory computer readable storage medium of claim 11 , wherein a higher priority is assigned to the alert compared to another alert for another vulnerability having a lesser attack surface than the attack surface of the vulnerability.
13 . The non-transitory computer readable storage medium of claim 11 , wherein code comprises application code.
14 . The non-transitory computer readable storage medium of claim 11 , wherein code comprises infrastructure-as-code (IaC) code.
15 . The non-transitory computer readable storage medium of claim 11 , wherein the code comprises deployed code and wherein identifying the attack surface for the vulnerability comprises identifying one or more compute assets of the cloud deployment having the vulnerability.
16 . The non-transitory computer readable storage medium of claim 11 , wherein the code comprises undeployed code and wherein identifying the attack surface for the vulnerability comprises identifying one or more compute assets of the cloud deployment that would have the vulnerability were the code deployed.
17 . The non-transitory computer readable storage medium of claim 13 , wherein identifying the attack surface for the vulnerability comprises:
generating a fingerprint based on a repository for an application associated with the code; and identifying one or more compute assets in the cloud deployment matching the fingerprint.
18 . The non-transitory computer readable storage medium of claim 17 , wherein the fingerprint is based on a listing of packages included in the application.
19 . The non-transitory computer readable storage medium of claim 11 , wherein detecting the vulnerability in code by performing the static code analysis of the code comprises determining whether a vulnerable method in the code is statically reachable.
20 . The non-transitory computer readable storage medium of claim 11 further storing instructions which, when executed, cause a processing device to generate a polygraph.