All tutorials

Malware & known vulnerabilities

Cordon 0.6.04 sections · 2 diagramsView this tutorial on GitHub

Two different questions, two different answers:

   "Is this package KNOWN-BAD?"          "Does this package behave badly?"   ────────────────────────────          ────────────────────────────────   advisory database (a list)            capability rules (behaviour)   MALWARE.DEPENDENCY.KNOWN              MALWARE.DROPPER / SUSPECT.EXFIL / ...   VULNERABLE.DEPENDENCY.KNOWN           (tutorial 02)

Both run offline against data shipped with the tool. See 06 to refresh it.

Malware & known vulnerabilities, figure 1
   lockfile ──┬──▶ name+version in the MALICIOUS list?  ──▶ MALWARE.DEPENDENCY.KNOWN.001
              │                                               (critical — do not install)
              └──▶ name+version in the VULNERABLE list?  ──▶ VULNERABLE.DEPENDENCY.KNOWN.001
                                                              (severity from the advisory)
Malware & known vulnerabilities, figure 2
   TYPOSQUAT                         DEPENDENCY CONFUSION
   ─────────                         ────────────────────
   you meant:   requests            your private pkg:   acme-internal   (internal registry)
   you got:     reqeusts            attacker publishes: acme-internal   (public registry,
   got:         python-requests3                        higher version) ──▶ pulled instead
        │                                    │
        ▼                                    ▼
   SUSPECT.TYPOSQUAT.*               SUSPECT.DEPENDENCYCONFUSION.*
   OFFLINE (default)                    ONLINE (--online)  — asks the registry   ─────────────────                    ──────────────────────────────────────   known-bad lists                      + was this version YANKED by its publisher?   name-shape heuristics                + is the pin far behind (downgrade attack)?   behaviour rules                      + does the lockfile hash match the registry?                                        + provenance / attestation  (tutorial 05)
   cordon-scanner scan .              # offline: safe, reproducible, air-gap-ready   cordon-scanner scan . --online     # + live registry questions (not reproducible)

A vulnerability three levels deep that your code never calls is not the same as one you invoke on every request. That is reachability, tutorial 04.

Next: 04 · Reachability.