-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathtest_gate_version_cap.py
More file actions
61 lines (48 loc) · 2.5 KB
/
Copy pathtest_gate_version_cap.py
File metadata and controls
61 lines (48 loc) · 2.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
"""Version/pattern-matched CVEs are never findings.
A banner→NVD (or version-only) match cannot establish patch level. Distros
backport fixes without bumping the version string. Those signals are discarded
as findings — they may seed active validation elsewhere, but must not surface
as confirmed/potential in the report. Probe-confirmed evidence still promotes.
"""
from src.fusion.adjudicator import AIVerdict, apply_ai_verdicts
from src.fusion.gate import Verdict, adjudicate
from src.fusion.signals import Signal
def _nvd_sig(**kw):
defaults = dict(
source="nvd", kind="vuln", claim="cve-2021-40438", host="h", port=80,
service="http", evidence="apache 2.4.7", cvss=9.8, version_matched=True,
)
defaults.update(kw)
return Signal(**defaults)
def test_version_only_is_discarded_at_gate():
[v] = adjudicate([_nvd_sig(kev=True, cvss=9.8)])
assert v.decision == "discarded"
assert "pattern" in v.rationale.lower() or "version" in v.rationale.lower()
def test_version_only_ai_real_is_discarded():
v = Verdict(host="h", port=80, claim="cve-2021-40438", decision="gray",
impact="critical", pinned=False, agreement=1,
signals=[_nvd_sig()])
apply_ai_verdicts([v], {0: AIVerdict(verdict="real", confidence=0.9)})
assert v.decision == "discarded"
assert v.ai_safety_override is True
def test_probe_confirmed_real_stays_confirmed():
v = Verdict(host="h", port=80, claim="cve-2021-40438", decision="gray",
impact="critical", pinned=False, agreement=1,
signals=[_nvd_sig(probe_confirmed=True)])
apply_ai_verdicts([v], {0: AIVerdict(verdict="real", confidence=0.9)})
assert v.decision == "confirmed"
def test_non_version_real_stays_confirmed():
v = Verdict(host="h", port=80, claim="exposed-admin", decision="gray",
impact="high", pinned=False, agreement=1,
signals=[Signal(source="probe", kind="misconfig", claim="exposed-admin",
host="h", port=80, reliability="medium",
version_matched=False, cvss=8.0)])
apply_ai_verdicts([v], {0: AIVerdict(verdict="real", confidence=0.9)})
assert v.decision == "confirmed"
def test_probe_signal_confirms_at_gate():
[v] = adjudicate([
Signal(source="probe", kind="vuln", claim="cve-2021-40438", host="h",
port=80, reliability="high", cvss=9.8, exploit_available=True,
version_matched=False),
])
assert v.decision == "confirmed"