scieee AI-readable full text Open interactive document viewer

D4.2: RESCALE Continuous Security Assurance Platform (first version)

Henriques, Diogo

Abstract

This document outlines the design and implementation of the Security Assurance component within the RESCALE framework, a comprehensive solution aimed at ensuring secure-by-design supply chains. The component integrates key moduless, including a Local National Vulnerability Database, an Update NVD mechanism, a Security Engine for vulnerability analysis, an Asset Management module for TBOM organization, and a Notifications module for real-time alerts and trust validation. By leveraging frequent updates from the NVD and dynamic security assessments, the platform identifies vulnerabilities across TBOMs. Through automated processes and robust communication mechanisms, the Security Assurance Component provides organizations with the tools to address emerging threats, ensuring resilience and trustworthiness in rapidly evolving cybersecurity landscapes.

Full text

D4.2: RESCALE Continuous Security Assurance Platform (first version) PROJECT Project Number 101120962 Project Acronym RESCALE Project Title Revolutionised Enhanced Supply Chain Automation with Limited Threats Exposure Start Date 01.10.2023 Programme HORIZON-CL3-2022-CS-01-02 DELIVERABLE Deliverable Type R - Document Report Workpackage WP4 Deliverable Lead STS Editors Diogo Henriques (STS) Contributors ISI, INT, EISI, CBRL, ICERT, S5 Dissemination Level Public Abstract This document outlines the design and implementation of the Security Assurance component within the RESCALE framework, a comprehensive solution aimed at ensuring secure-by-design supply chains. The component integrates key moduless, including a Local National Vulnerability Database, an Update NVD mechanism, a Security Engine for vulnerability analysis, an Asset Management module for TBOM organization, and a Notifications module for real-time alerts and trust validation. By leveraging frequent updates from the NVD and dynamic security assessments, the platform identifies vulnerabilities across TBOMs. Through automated processes and robust communication mechanisms, the Security Assurance Component provides organizations with the tools to address emerging threats, ensuring resilience and trustworthiness in rapidly evolving cybersecurity landscapes. Disclaimer The information in this document is provided “as is”, and no guarantee or warranty is given that the information is fit for any particular purpose. The content of this document reflects only the author’s view – the European Commission is not responsible for any use that may be made of the information it contains. The users use the information at their sole risk and liability. This project has received funding from the European Union’s Horizon Europe research and innovation programme under grant agreement No 101120962 D4.2: RESCALE Continuous Security Assurance Platform (first version) Document Revision & Quality Assurance Internal Reviewers 1. Alessandro Visintin - (ICERT) 2. Konstantinos Latanis - (S5) Revisions Version Date Partner Overview 0.1 16/10/2024 STS ToC 0.2 22/11/2024 STS, All Finished draft 0.3 22/11/2024 S5 Reviewer comments and text update 0.4 25/11/2024 STS Comments addressed 0.5 27/11/2024 ICERT Reviewer comments and text update 0.6 28/11/2024 STS Comments addressed 0.9 06/12/2024 ISI, AEGIS Final comments 1.0 13/12/2024 STS Final version RESCALE – Public – Page 2 / 21 Table of Contents 1 Introduction 6 1.1 Scope&Contribution............................... 6 1.2 Relation to Work Packages, Deliverables, and Activities . . . . . . . . . . . . . 6 1.3 Contribution to WP4 and Project Objectives . . . . . . . . . . . . . . . . . . . 6 1.4 Structure of the Document . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 2 Security Assurance architecture 8 3 National Vulnerability Database 9 3.1 NVD........................................ 9 3.2 Local vulnerabilities database . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 3.3 Local database update routine . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 4 Security engine 11 5 Sphynx Assets management 13 6 Continuous Monitoring 14 6.1 Import SBOM from Management Module . . . . . . . . . . . . . . . . . . . . 14 6.2 Installation of the event captor . . . . . . . . . . . . . . . . . . . . . . . . . . 14 7 Notifications 15 7.1 Security/User Notification and TrustOR . . . . . . . . . . . . . . . . . . . . . 15 7.2 System Notification and Communication Mechanisms . . . . . . . . . . . . . . 16 8 Security assurance architecture 17 8.1 Deployment.................................... 17 9 Continuous risk assessment for the RESCALE platform 18 9.1 Realtimemonitoring ............................... 18 9.2 EventCaptors................................... 19 10 Conclusions 20 3 List of Figures 1 Software architecture of security assurance component . . . . . . . . . . . . . . . 8 2 Sequence Diagram import SBOM . . . . . . . . . . . . . . . . . . . . . . . . . . 14 3 Trust establishment high level architecture . . . . . . . . . . . . . . . . . . . . . . 17 4 SPA suite reference architecture . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 4 D4.2: RESCALE Continuous Security Assurance Platform (first version) List of Abbreviations CDX CycloneDX. 13 CIA Confidentiality, Integrity, and Availability. 18 CISA Cybersecurity and Infrastructure Security Agency. 9 CPE Common Platform Enumeration. 9 CVE Common Vulnerabilities and Exposures. 9 CVSS Common Vulnerability Scoring System. 9 CWE Common Weakness Enumeration. 9 DHS Department of Homeland Security. 9 DSCG Dynamic Supply Chain component Guarantee. 14 ELK Elasticsearch, Logstash, and Kibana. 19 NIST National Institute of Standards and Technology. 9 NVD National Vulnerability Database. 8–10, 12 OSS Open Source Software. 10 SaaS Software as a Service. 17 SBOM Software Bill of Material. 13, 14 SCAP Security Content Automation Protocol. 9 SPA SPHYNX’s Security and Privacy Assurance. 17–19 SSCG Static Supply Chain component Guarantee. 14 TBOM Trust-Based Object Model. 8, 10–14, 20 UUID Universally Unique Identifier. 14 VEX Vulnerability Exploitability eXchange. 11 RESCALE – Public – Page 5 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 1 Introduction The RESCALE project aims to advance secure-by-design supply chains, focusing on automating the evaluation of software and hardware components to mitigate vulnerabilities. RESCALE strives towards creating robust cybersecurity audit processes and developing secure systems with reliable assurances. Through systematic analysis and improvement of each layer in computing systems, RESCALE introduces new tools and methodologies across the entire supply chain. This document outlines the project’s progress by detailing the structure of the continuous security assurance platform. 1.1 Scope & Contribution This document specifies the architecture and implementation details of the Security Assurance Platform, highlighting its key modules: Local NVD, Update NVD, Security Engine, Asset Management, and Notifications. It provides an in-depth overview of how these components interact to support continuous security assessment, ensuring the integrity of TBOMs within the RESCALE framework. Additionally, it includes descriptions of the dynamic processes involved in vulnerability identification, asset management, and real-time notification delivery, which are essential for maintaining a secure supply chain. This deliverable serves as a foundational resource for the RESCALE project, specifically supporting the efforts outlined in Work Package 4 (Task T4.2). It offers the necessary guidance for the development and deployment of the Security Assurance Platform, ensuring that it meets the project’s objectives of achieving secure-by-design supply chains. Although the platform’s architecture is well-defined and capable of supporting real-time vulnerability management, future adjustments may be required to address evolving cybersecurity challenges. Any refinements or enhancements to the platform will be documented in subsequent deliverables to ensure alignment with the latest developments and emerging needs. 1.2 Relation to Work Packages, Deliverables, and Activities Deliverable D4.2 is an output of T4.2, within WP4. It also has some relevance to Work Packages 3 (WP3) and 5 (WP5). This work is closely associated with the establishment of a secure supply chain and the assurance of continuous security. 1.3 Contribution to WP4 and Project Objectives Deliverable D4.2 is a crucial output of WP4 T4.2, which contributes to the Objective O4.1 of the project: Design and develop a complete toolbox to audit and increase supply chain security based on emerging technologies for hardware and software modules and WP4 O4.2: Design Continuous Assurance Mechanisms and Implement the Relevant Platform along with RESCALE’s Objective 3: Provide a Trusted BOM approach that will infuse trust in software RESCALE – Public – Page 6 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) and hardware supply chain and promote trusted updates. Security assurance platform will provide input to TrustOR and the RESCALE Communication Mechanism. 1.4 Structure of the Document The rest of the deliverable is structured as follows: • Section 2 National Vulnerability Database: This section provides an overview of the National Vulnerability Database and the mechanisms used to provide up-to-date NVD data locally for the continuous security assessment. • Section 3 Security Engine: This section provides details about the security engine and the correlation of NVDs with the TBOMs. • Section 4 Assets Management: The next section details the management of the assets retrieved by the TBOM for the continuous security assurance. • Section 5 Continuous Monitoring: This section describes the way a TBOM is passed to the security assessment platform for continuous monitoring. • Section 6 Notifications: Section 6 deals with user and system notifications (TrustOR) every time a new vulnerability is found. • Section 7 Security Assurance Architecture: This section provides an overview of the Security Assurance Architecture. • Section 8 Continuous risk assessment for th RESCALE platform: The section provides a detailed description of the continuous risk assessment for the RESCALE platform which will be handled by the SPA suite. • Section 9 Conclusions: The final section provides the conclusions of the deliverable D4.2. RESCALE – Public – Page 7 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 2 Security Assurance architecture In an era of increasingly sophisticated cyber threats, ensuring the integrity and security of software has become a critical priority. The RESCALE project aims to pioneer a secure-bydesign approach to software supply chain management, focusing on automating evaluation processes, eliminating vulnerabilities in third-party components, and enhancing cybersecurity audit procedures. By systematically analysing and refining both hardware and software layers of computing systems, RESCALE seeks to establish a robust framework for constructing secure systems with maximum guarantees. A central component of RESCALE’s innovation is the development of a Continuous Security Assurance Mechanism. This mechanism operates on a Security and Privacy Assurance Platform that dynamically evaluates the relevance and accuracy of Trust-Based Object Models (TBOMs) for hardware and software components in the face of emerging vulnerabilities and faults. Whenever new security issues arise that were not accounted for during the initial creation of a TBOM, the platform activates a targeted update process, ensuring that the supply chain remains secure and resilient over time. Figure 1 shows the software architecture of the security assurance component. Figure 1: Software architecture of security assurance component The component is built upon a modular architecture that integrates key modules to deliver continuous and robust security assessments. At its core is the Local NVD, a localized mirror of the National Vulnerability Database(NVD), providing fast and uninterrupted access to the latest vulnerability information. This is supported by the Update NVD module, which ensures the Local NVD remains current by synchronizing with the central NVD to incorporate newly discovered vulnerabilities. The Security Engine serves as the analytical hub, leveraging data from the Local NVD to assess TBOMs for potential vulnerabilities in real time. The Local Asset Management Module oversees the lifecycle of TBOMs, categorizing and maintaining assets while interfacing with the Security Engine to ensure that all components are systematically evaluated. Complementing these is the Notifications Module, which provides real-time alerts about vulnerabilities, asset status changes via the Notification and TrustOR system. This document outlines the implementation of the Continuous Security Assurance Mechanism, detailing how it integrates with the Security Assurance Platform to provide real-time assessments and updates. By leveraging this proactive approach, RESCALE contributes to a future of resilient and trustworthy supply chains that adapt to the rapidly evolving cybersecurity landscape. RESCALE – Public – Page 8 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 3 National Vulnerability Database The Continuous Security Assurance platform uses the NVD as its main reference for vulnerability detection. The NVD is the United States government’s repository of vulnerability data to enable the management of security and vulnerabilities in an automated fashion, as well as facilitating compliance. The NVD provides a set of references for security checklists including product names, software flaws, and impact metrics. The data in the NVD is presented in the Security Content Automation Protocol (SCAP). The NVD also provides machine-readable dataset descriptions. The National Institute of Standards and Technology (NIST) is the organization which maintains the NVD [7]. 3.1 NVD The reference data for security automation contained in the NVD provides a foundation for the automation of configuration of security and software, as well as vulnerability management, security measurements and compliance. The NVD’s program for formal validation performs tests of vendors’ products’ capabilities to leverage automation data for security by verifying the level to which a given product conforms to specific enterprise capabilities [8]. Citation of elements of the NVD is structured as follows: Jane Doe, John Doe (2022), National Vulnerability Database, National Institute of Standards and Technology, https://doi.org/0.0/M0. The Security Content Automation Protocol (SCAP) through which the NVD enables security automation is a conglomeration of community driven specifications. The community aspect of SCAP takes input from the security automation community, which delivers a wide variety of use-cases to be addressed in the functionality of SCAP [9]. NIST provides information on both existing [11] and emerging [10] SCAP specifications. Every vulnerability in the NVD is assigned a Common Vulnerabilities and Exposures CVE identifier [5] [6]. The CVE is a glossary containing identified vulnerabilities along with the affected code base. CVE is maintained by MITRE corporation, and is sponsored by the U.S. Department of Homeland Security (DHS) and Cybersecurity and Infrastructure Security Agency (CISA) [5] The purpose of the CVE program is to assign unique identifiers to vulnerabilities as well as associate these vulnerabilities with specific versions of code, software or libraries. The unique identifier creates clarity on which vulnerability is being referred to. MITRE, generally, assigns CVE identifiers to vulnerabilities, but several authorized organizations including researchers and vendors from the international community also assign these. Once a CVE is published the NIST NVD carries out the work of enrichment of the CVE. The NVD enrichment process entails collating information accompanying the original CVE with available reference materials in order to add Reference Tags, Common Weakness Enumeration (CWE), Common Platform Enumeration (CPE) and Common Vulnerability Scoring System (CVSS) which assigns a severity score in decimal format ranging from 0.0 (none) to 10.0 (critical). RESCALE – Public – Page 9 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 7.2 System Notification and Communication Mechanisms Every time a system event is considered suspicious a new message is sent to the communication mechanisms with the following fields: {"event_id": string, "predictions": [predictions] } Where the event id is going to be use to correlate events and the predictions will be a list containing the prediction results for the given samples. RESCALE – Public – Page 16 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 8 Security assurance architecture 8.1 Deployment Continuous security assurance is part of the Security and Privacy Assurance suite of Sphynx adopted and integrated for the scopes of RESCALE. The Security Assurance component will be deployed to the premises of STS and will be integrated with other RESCALE components as described in sections 5 and 6. The following figure shows the high-level architecture of RESCALE solution, with the Security Assurance component highlighted. Figure 3: Trust establishment high level architecture The Security Assurance component is part of the SPHYNX’s Security and Privacy Assurance (SPA) suite and will be deployed outside of the trust boundary of RESCALE, serving the RESCALE requests as a Software as a Service (SaaS). The security mechanisms for the communication will be based on KrakenD and Keycloak of SPA suite. RESCALE – Public – Page 17 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 9 Continuous risk assessment for the RESCALE platform The continuous risk assessment for the RESCALE platform will be handled by the SPA suite. SPA suite offers a comprehensive, end-to-end solution for risk assessment, encompassing every critical stage from asset and threat modelling to penetration testing, vulnerability assessment, and beyond. Designed to continuously monitor, test, and evaluate the security (and privacy, when applicable) posture of the protected organizations and their assets in real-time, the platform ensures robust defence mechanisms are always in place. By employing an evidence-based methodology and customizable metrics aligned with the Confidentiality, Integrity, and Availability (CIA) triad, SPA delivers rigorous security assessments with certifiable outcomes. To support this evidence collection, the platform will have interoperability with various components and programmatic connectivity to some of their core components through appropriate probes (e.g., event captors, test tools), enabling it to obtain the monitoring and/or test the evidence required for the assessments. Below is an overview of SPA’s internal architecture: Figure 4: SPA suite reference architecture 9.1 Real time monitoring The component responsible for monitoring the target organisation, for potential issues within its cyber system. In its monitoring capacity, EVEREST possesses a multifaceted approach. It surveys the cyber system across a spectrum of crucial aspects, such as network traffic, potential threats from both internal and external sources, misconfiguration, and not properly installed security controls. By continuously evaluating events against defined rules expressed in Event RESCALE – Public – Page 18 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) Calculus and Drools, EVEREST can detect anomalies, deviations, and potential risks within the system. EVEREST works with the Event Captors to fetch the raw events from the cyber system. 9.2 Event Captors An Event Captor is a tool that, based on a specification set by EVEREST, aggregates log and event information from the targeted infrastructure, and encapsulates it in a specific format that can be consumed by the EVEREST model. Logs and events can be collected in two modes. The former mode is based on the Elasticsearch, Logstash, and Kibana(ELK) solution. More specifically, Elasticsearch[3] and some lightweight shippers (namely Beat[2]) are utilised to forward and centralize log data. The latter makes use of SPHYNX’s Native Event Captors, i.e., captors that cannot utilise the logging capabilities of the ELK stack. The needed Event Captors are initiated through EVEREST. The SPA suite serves as a comprehensive security assurance platform, offering continuous monitoring for RESCALE platform assets. With its capabilities, SPA suite can accommodate various types of assessments and allows security experts to develop new and customized assessments dynamically. The management of the platform is overseen by STS. It is crucial to emphasize that SPA suite doesn’t function as an incident response tool for RESCALE, it serves primarily as a monitoring tool to ensure the smooth operation of the RESCALE platform. In the event of anomaly detection the system will provide a notification to the RESCALE platform for the technical partners to conduct further investigation into the incident. RESCALE – Public – Page 19 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) 10 Conclusions The Security Assurance component within the RESCALE framework represents a comprehensive and proactive approach to maintaining the security and integrity of supply chains. Its modular architecture, comprising the Local NVD, Update NVD, Security Engine, Local Asset Management, and Notifications modules, ensures seamless integration and continuous operation. By leveraging the Local NVD and its frequent updates, the platform provides near realtime access to the latest vulnerability information, enabling rapid response to emerging threats. The Security Engine acts as the analytical cornerstone, cross-referencing vulnerabilities with TBOMs to identify risks. Together, these components form a robust system that facilitates automated and dynamic security assessments, minimizing exposure windows and strengthening the overall cybersecurity posture. A key strength of the platform lies in its holistic asset management and effective communication mechanisms. The Local Asset Management module ensures that TBOMs are organized, updated, and readily available for evaluation, while the Notifications module enhances user awareness by delivering timely alerts and updates. This end-to-end approach to security assurance not only reinforces trust but also equips organizations with the tools to build secure, resilient, and adaptable systems, aligning with RESCALE’s vision of secure-by-design supply chains. RESCALE – Public – Page 20 / 21 D4.2: RESCALE Continuous Security Assurance Platform (first version) References [1] CycloneDX. Cyclonedx - vulnerability exploitability exchange (vex). https:// cyclonedx.org/capabilities/vex/, 2024. Accessed: 2024-11-04. [2] Elasticsearch. Beats: Data shippers for elasticsearch — elastic. https://www.elastic. co/beats, 2024. Accessed: 2024-11-04. [3] Elasticsearch. Elasticsearch: The official distributed search & analytics engine — elastic. https://www.elastic.co/elasticsearch, 2024. Accessed: 2024-11-04. [4] GitHub. Github advisory database · github. https://github.com/advisories, 2024. Accessed: 2024-11-04. [5] MITRE. Common vulnerabilities and exposures. https://cve.mitre.org/, 2024. Accessed: 2024-11-04. [6] NIST. Nist vulnerabilities. https://nvd.nist.gov/vuln, 2023. Accessed: 2024-1104. [7] NIST. National vulnerability database. https://nvd.nist.gov/, 2024. Accessed: 2024-11-04. [8] NIST. Nist public data repository. https://data.nist.gov/od/id/ 1E0F15DAAEFB84E4E0531A5706813DD8436, 2024. Accessed: 2024-11-04. [9] NIST. Nist security content automation protocol. https://csrc.nist.gov/projects/ security-content-automation-protocol/, 2024. Accessed: 2024-11-04. [10] NIST. Nist security content automation protocol scap emerging specifications. https://csrc.nist.gov/projects/security-content-automation-protocol/ emerging-specifications, 2024. Accessed: 2024-11-04. [11] NIST. Nist security content automation protocol scap releases. https://csrc.nist. gov/projects/security-content-automation-protocol/scap-releases, 2024. Accessed: 2024-11-04. [12] Sonatype. Sonatype oss index. https://ossindex.sonatype.org/, 2024. Accessed: 2024-11-04. RESCALE – Public – Page 21 / 21