You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add structured exposure and attacker position fields to risk calibration
Introduces structured metadata to document the resolved threat boundaries of calibrated findings:
- Updated SCHEMA.md to define `inferred_exposure` (resolved exposure tier) and `attacker_position` (attacker starting position, declared earlier in the pipeline for review).
- Added `sanity_triage_applied` to SCHEMA.md and mantis_calibrate/SKILL.md to record a semicolon-separated list of all sanity triage rules that fired.
- Expanded `attacker_position` enums to support advanced threat contexts: `HOST_SYSTEM` (Confidential Computing), `SUPPLY_CHAIN`, `PHYSICAL_TEMPORARY`, and `PHYSICAL_LONG_TERM` (fault injection).
- Updated mantis_calibrate/SKILL.md to read and validate `attacker_position` from input, applying fallback logic only if missing (restoring fallback check precedence).
- Implemented position normalization in Section 2: if `attacker_position` is a free-text string (e.g. legacy phrasing), it is normalized to the closest valid enum (e.g. cluster peer -> `"IN_CLUSTER"`, authenticated user -> `"EXTERNAL"`) before applying caps.
- Added specific risk caps in SKILL.md for new positions (Confidential Computing host caps at HIGH, standard host downgrades to LOW, long-term laboratory physical caps at LOW, temporary physical caps at MEDIUM).
- Integrated `HOST_SYSTEM` and physical positions into the fallback-inference list in Section 2 to support legacy/missing data.
- Refined the Standard Host-to-Guest Attacks rule to default to standard (non-CC) VM (LOW downgrade) unless CC/TEE/enclave are explicitly named.
- Introduced a cap to MEDIUM (5.9) for high-privilege external attacks (`EXTERNAL` + `PR=HIGH`), with container escape/cross-tenant exception.
- Added a container escape/cross-tenant exception to the Section 2 HIGH privilege impact cap to allow correct scoring of node escapes.
- Enforced a mandatory exposure alignment rule: `LOCAL` or `IN_CLUSTER` positions MUST resolve to `INTERNAL` exposure.
- Enforced an `EXTERNAL` position alignment: `EXTERNAL` attackers MUST resolve to `EXPOSED` (1.0 multiplier) even if the component is mapped to `INTERNAL` (reflecting data-flow exposure to untrusted external inputs).
- Explicitly documented in the `Internal / Nested Components` cap that this rule MUST NOT fire when the attacker position is `EXTERNAL` (ensuring alignment consistency).
- Implemented a custom Calibration Overrides mechanism parsing the Threat Model to lift specific caps per-project/component (e.g. allowing CRITICAL for HSM physical key compromise).
- Enforced absolute unprivileged constraint for CRITICAL priority, ensuring even exempted escapes cannot go above HIGH (7.9) if they require administrative privileges.
- Restored the sanity triage precedence clause in Section 3, explicitly ensuring caps override Section 2 upgrades (like Security Control Bypass).
- Enforced Section 3 precedence rules: if multiple caps apply, the most restrictive wins (Force-LOW > cap-MEDIUM > cap-HIGH), and all rules are written to `sanity_triage_applied` (most restrictive first).
- Enforced that caps only act as limiters and must not upgrade lower scores (e.g. score of 5.0 remains MEDIUM).
- Added an exception to the Static Confirmation cap: if the finding details quote a valid external stack trace, sanitizer trace (ASan/UBSan), or crash log, it is treated as reproduced (Likelihood 5) and the static cap is lifted.
- Implemented DoS CRITICAL eligibility constraints: availability-only (DoS) bugs cannot be rated CRITICAL unless the availability_tier is explicitly documented as CRITICAL in the Threat Model and no auto-recovery (LB/restart) mitigates the crash.
- Created and stored a permanent 30-case calibration test suite in `~/moss/mantis-test/` to verify all rules, caps, and overrides function deterministically.
TAG=agy
CONV=258932e0-42ce-426c-8f4c-508a3d272c26
Change-Id: I51bb0fb1f9503563a2596bedcdacec07c883c246
0 commit comments