Vulnerability exceptions for monitoring a compute environment
An illustrative method for monitoring a cloud environment may include determining, based on a scan of a compute environment, a set of vulnerable software components in the compute environment, identifying a subset of the vulnerable software components that satisfy an active vulnerability exception, and performing, based on the set of the vulnerable software components, a remedial operation, wherein the subset of the vulnerable software components is deprioritized for the remedial operation based on the active vulnerability exception.
1 . A method comprising:
detecting, by a data platform, a request to implement a vulnerability exception, wherein the vulnerability exception specifies one or more conditions used to identify one or more vulnerable software components that satisfy the one or more conditions and a vulnerable software component comprises a software component having a flaw that exposes a software component;
implementing, by the data platform and based on the request, the vulnerability exception to an active state;
comparing, by the data platform, software components deployed in a compute environment to one or more identifiers representative of predetermined vulnerabilities to determine a set of vulnerable software components in the compute environment;
comparing, by the data platform, attributes of each vulnerable software component to the one or more conditions specified in the vulnerable exception to identify a subset of the vulnerable software components; and
performing, by the data platform and based on the set of the vulnerable software components, a remedial operation, wherein the subset of the vulnerable software components is deprioritized for the remedial operation based on the vulnerability exception being in the active state.
2 . The method of claim 1 , wherein the detecting the request includes detecting a user input designating the vulnerability exception.
3 . The method of claim 1 , wherein the request to implement the vulnerability exception is generated by the data platform.
4 . The method of claim 1 , wherein the request to implement the vulnerability exception is based on a graph comprising a plurality of nodes connected by a plurality of edges, wherein each node of the plurality of nodes represents a logical entity from the set of vulnerable software components and each edge of the plurality of edges represents a behavioral relationship between nodes connected by the edge.
5 . The method of claim 1 , wherein the request to implement the vulnerability exception is based on runtime data associated with the set of the vulnerable software components and collected by an agent deployed in the compute environment.
6 . The method of claim 1 , wherein the set of the vulnerable software components is associated with a first compute asset having a first security posture, wherein the request to implement the vulnerability exception is generated by the data platfom1 for the compute environment and is based on a second compute asset that is in a second compute environment having a second security posture similar to the first security posture.
7 . The method of claim 1 , wherein the vulnerability exception specifies a category of vulnerable software components such that identifying the subset of the vulnerable software components includes identifying one or more vulnerable software components from the set of the vulnerable software components associated with the category.
8 . The method of claim 1 , wherein the one or more identifiers are included in a configuration file category includes one or more of an operating system, a kernel status, a set of hosts, an operational status, an external network status, a false positive, an accepted risk, a compensating control, or a pending fix.
9 . The method of claim 7 , wherein the predetermined vulnerabilities comprise Common Vulnerabilities and Exposures (CVE) subset of the vulnerable software components is configured to be filtered based on the category.
10 . The method of claim 1 , wherein the performing the remedial operation includes providing, for display by a user interface, one or more notifications associated with the set of the vulnerable software components.
11 . The method of claim 10 , wherein the performing the remedial operation includes suppressing one or more notifications associated with the subset of the vulnerable software components from the one or more notifications associated with the set of the vulnerable software components.
12 . The method of claim 10 , wherein the performing the remedial operation includes deprioritizing one or more notifications associated with the subset of the vulnerable software components relative to the one or more notifications associated with the set of the vulnerable software components.
13 . The method of claim 10 , wherein the one or more notifications associated with the set of the vulnerable software components includes a vulnerability risk score representative of a level of vulnerability risk associated with the set of the vulnerable components, wherein the performing the remedial operation includes omitting the level of vulnerability risk associated with the subset of the vulnerable software components from the vulnerability risk score.
14 . The method of claim 1 , further comprising deactivating the vulnerability exception to an inactive state based on an expiration of the vulnerability exception.
15 . The method of claim 14 , wherein the expiration of the vulnerability exception is based on a user input designating the expiration of the vulnerability exception.
16 . The method of claim 14 , wherein the expiration of the vulnerability exception is determined by the data platform.
17 . The method of claim 14 , further comprising providing, for display by a user interface, one or more notifications associated with the expiration of the vulnerability exception.
18 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions capable of being executed to:
detect a request to implement a vulnerability exception, wherein the vulnerability exception specifies one or more conditions used to identify one or more vulnerable software components that satisfy the one or more conditions and a vulnerable software component comprises a software component having a flaw that exposes a software component;
implement based on the request, the vulnerability exception to an active state;
compare software components deployed in a compute environment to one or more identifiers representative of predetermined vulnerabilities to determine a set of vulnerable software components in the compute environment, wherein a vulnerable software component comprises a software component having a flaw that exposes a software component;
compare attributes of each vulnerable software component to one or more conditions specified in a vulnerability-exception to identify a subset of the vulnerable software components; and
perform, based on the set of the vulnerable software components, a remedial operation, wherein the subset of the vulnerable software components is deprioritized for the remedial operation based on the active vulnerability exception.
19 . The computer program product of claim 18 , wherein the computer instructions are further capable of being executed to: detect a request to implement a vulnerability exception; and implement, based on the request, the vulnerability exception as the active vulnerability exception.
20 . A system comprising:
a memory storing instructions; and
a processor communicatively coupled to the memory and configured to execute the instructions to:
detect a request to implement a vulnerability exception, wherein the vulnerability exception specifies one or more conditions used to identify one or more vulnerable software components that satisfy the one or more conditions and a vulnerable software component comprises a software component having a flaw that exposes a software component:
implement based on the request, the vulnerability exception to an active state:
compare software components deployed in a compute environment to one or more identifiers representative of predetermined vulnerabilities to determine a set of vulnerable software components in the compute environment, wherein a vulnerable software component comprises a software component having a flaw that exposes a software component;
compare attributes of each vulnerable software component to one or more conditions specified in a vulnerable exception to identify a subset of the vulnerable software components; and
perform, based on the set of the vulnerable software components, a remedial operation, wherein the subset of the vulnerable software components is deprioritized for the remedial operation based on the active vulnerability exception.