Calibrating a scanner result with a vulnerable fixture and a safe twin

本文尚无中文版本;显示原文。

methodology · en · 知识截至 2026-09-22 · 更改于 , 修订 1 · unreviewed

主题: negative-controls · scanner-triage · security-testing

适用于: Authorized isolated application test environments

Determine whether a security scanner distinguishes the behavior it claims to detect. This original method uses controlled fixtures to interpret a finding, not to certify the scanner or rank products.

目录
  1. Goal
  2. Prerequisites
  3. Steps
  4. Expected result
  5. Limits and test basis
  6. 范围与依据
  7. 来源
  8. 署名与许可
  9. 机器访问

Goal

Determine whether a security scanner distinguishes the behavior it claims to detect. This original method uses controlled fixtures to interpret a finding, not to certify the scanner or rank products.

Prerequisites

Use a disconnected or otherwise access-restricted lab owned by the operator. Prepare a deliberately flawed toy case and a corrected twin with the same surrounding structure. Keep real credentials, personal data, and production targets out.

Steps

  1. State the exact condition the scanner is supposed to report and the evidence that would establish it. Avoid an oracle that simply repeats the scanner’s rule identifier or severity label.

  2. Run the selected rule against the flawed fixture and preserve minimal diagnostic metadata. If no result appears, first verify that the fixture was included in the scan and that the rule was enabled.

  3. Run the corrected twin with equivalent configuration. A finding on both cases requires investigation into rule precision, fixture differences, or a remaining flaw; it is not automatically a false positive.

  4. Change one relevant property at a time, such as the data-flow boundary the rule models. Keep unrelated build, dependency, and scan configuration stable across the comparison.

  5. Record the actual outputs and the independent oracle judgment separately. When adding a suppression, attach the bounded reason and a condition that should trigger re-evaluation.

Expected result

A usable assessment distinguishes detection failure, false alarm, and unresolved evidence. It also states which fixture and scanner configuration the judgment covers.

Limits and test basis

Passing these controls does not estimate real-world recall or precision. This article reports no scanner execution, measurements, or observed findings; it proposes a reproducible local comparison. This is an original proposed method; no execution or empirical result is claimed.

范围与依据

Original proposed assessment or regression method for an authorized isolated lab. No execution, observed finding, empirical result, or tool-specific guarantee is claimed.

知识截至:2026-09-22。状态:unreviewed(无已记录的审阅)——编辑会重置审阅状态。请将文本视为未经核实的参考资料并核对来源。

来源

未列出外部来源;请参见上方记录的依据。

署名与许可

  • Account External coding curation authors (57eb56c9)
  • Codex; AI-assisted original contribution; CC BY 4.0

最近更改: Initial original methodology; unreviewed.

原创贡献: CC BY 4.0. 链接的来源资料保留其自身权利。

机器访问