将Kubernetes上下文应用于扫描以抑制漏洞
(此 logo 并非 AI 生成)
Vex8s 通过将容器漏洞与 Kubernetes 设置相关联,生成 VEX 文档,以确定哪些 CVE 在您的集群中实际可被利用。
请注意,这是一个实验性项目。情况可能会迅速变化。
该项目旨在通过结合漏洞分类和 securityContext 分析,评估 Kubernetes 工作负载中已知 CVE 的可利用性。

它基于以下概念:
如需更深入的阅读,您可以查阅这篇论文:Environment-Aware Vulnerability Suppression Using Kubernetes Security Contexts and VEX
您可以从 release 页面下载最新的二进制文件。
或者您可以手动构建:
make build
vex8s 目前支持 2 种生成 VEX 文档的方式:
passive-mode:传入由 trivy 或 grype 生成的漏洞报告。
active-mode:使用 trivy 或 grype 引擎主动扫描镜像,然后根据结果生成文档。
使用 trivy:
# generate vulnerability report.
trivy image --format json --output nginx.trivy.json nginx:1.21.0
# generate VEX document by processing vulnerability report.
vex8s generate --manifest examples/nginx.yaml --report nginx.trivy.json --output nginx.vex.json
# scan again with VEX document to suppress vulnerabilities.
trivy image --vex nginx.vex.json --show-suppressed nginx:1.21.0
使用 grype 也可以实现同样的效果:
# generate sbom report.
grype --output cyclonedx-json --file nginx.grype.json nginx:1.21.0
# generate vulnerability report.
grype sbom:./nginx.grype.json --output json --file nginx.grype-vr.json
# generate VEX document by processing vulnerability report.
vex8s generate --manifest examples/nginx.yaml --report nginx.grype-vr.json --output nginx.vex.json
# scan sbom with VEX document to suppress vulnerabilities.
grype sbom:./nginx.grype.json --output table --vex nginx.vex.json --show-suppressed
使用 trivy:
# scan the image and automatically generate VEX document.
vex8s generate --manifest examples/nginx.yaml --scan.engine trivy --output nginx.vex.json
# scan again with VEX document to suppress vulnerabilities.
trivy image --vex nginx.vex.json --show-suppressed nginx:1.21.0
使用 grype 也可以实现同样的效果:
# generate sbom report.
grype --output cyclonedx-json --file nginx.grype.json nginx:1.21.0
# scan the image and automatically generate VEX document.
vex8s generate --manifest examples/nginx.yaml --scan.engine grype --output nginx.vex.json
# scan sbom with VEX document to suppress vulnerabilities.
grype sbom:./nginx.grype.json --output table --vex nginx.vex.json --show-suppressed
每个 CVE 被归类为一个或多个利用类别,这些类别驱动缓解决策。vex8s 通过 --classifier 支持三种分类器引擎:
embedded(默认):一个离线 ONNX ML 模型,捆绑在二进制文件中。无需网络访问。gemini:使用 Google 的 Gemini LLM 对 CVE 描述进行分类。需要 GEMINI_API_KEY 环境变量(可选 GEMINI_MODEL)。ollama:使用本地运行的 Ollama 服务器对 CVE 描述进行分类。请先拉取一个模型,例如 qwen2.5:3b-instruct(可选设置 OLLAMA_HOST / OLLAMA_MODEL)。export GEMINI_API_KEY="your-api-key"
vex8s generate --manifest examples/nginx.yaml --report nginx.trivy.json \
--output nginx.vex.json --classifier ollama
请参阅文档,特别是用户指南,以获取完整演练、Gemini 和 Ollama 分类器设置以及完整的标志参考。
本项目受 Akihiro Suda 的项目 vexllm 启发。