Generate SWID and CoSWID tags
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 20/100
- issue の種類
- 機能追加
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- typescript
- 領域
- security
調査の方向性
まず、issue にリンクされている SWID および CoSWID 仕様を確認し、NIST CPE 辞書の更新に関する関連する Security Issue も確認してください。issue にはソースファイル、テスト、エントリーポイント、受け入れ基準が記載されていないため、コーディングの前に実装範囲と Definition of Done を確立する必要があります。
索引モデルが issue の本文から書いたものです。
説明
Overview of specifications
ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.
IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.
Use-cases for SWID and CoSWID Tags
SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.
In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.
Comparison to CPE
CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".
SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):
- Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
- Inability to identify software patches
Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.
Relevance to LoopBack project
The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: https://github.com/loopbackio/security/issues/3).
These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.
As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.
Further usage
SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.
Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.
Relevance to LoopBack users
LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers
Specifications which incorporate SWID and CoSWID
- NIST SCAP version 1.3 (SWID)
- NIST SCAP version 2.0 (Planned) (SWID)
- NIST NVD (Planned) (SWID)
- DMTF DP 1067 (Software ID Tag Profile)
Tools which leverage SWID and CoSWID Tags
This is a non-exhaustive list.
- OpenSCAP
- Jamf
- NIST SWID Tag Tools
- Microsoft Assessment and Planning (MAP) Toolkit
- Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence
Projects & software which produce SWID an CoSWID Tags
This is a non-exhaustive list.
- Red Hat Enterprise Linux 8
- Adobe Creative Cloud
- Microsoft Windows
- Microsoft Office
- IBM MQ
References
- ISO/IEC 19770-2:2015
Information technology — IT asset management — Part 2: Software identification tag https://www.iso.org/standard/65666.html - https://datatracker.ietf.org/doc/html/draft-ietf-sacm-coswid-22
- Resource-Oriented Lightweight Information Exchange (ROLIE) https://datatracker.ietf.org/doc/html/rfc8322/
- Definition of the ROLIE Software Descriptor Extension https://datatracker.ietf.org/doc/html/draft-ietf-sacm-rolie-softwaredescriptor-08
- Security Automation and Continuous Monitoring (SACM) Architecture https://www.ietf.org/archive/id/draft-ietf-sacm-arch-12.html
- Software Identification (SWID) Tagging | CSRC https://csrc.nist.gov/Projects/Software-Identification-SWID
- Software Identification (SWID) Tag Tools https://pages.nist.gov/swid-tools/
- Security Content Automation Protocol 2 (SCAP v2) FAQS | CSRC https://csrc.nist.gov/Projects/Security-Content-Automation-Protocol-v2/faqs
- Transitioning to the Security Content
Automation Protocol (SCAP) Version 2 - NIST Cybersecurity White Paper https://doi.org/10.6028/NIST.CSWP.09102018 - NISTIR 8060 Guidelines for the Creation of Interoperable Software Identification (SWID) Tags https://doi.org/10.6028/NIST.IR.8060
- Red Hat Summit - Top 10 Security Changes in Red Hat Enterprise Linux 8 https://www.redhat.com/files/summit/session-assets/2019/TB13AD.pdf
- Update NIST Dictionary https://github.com/loopbackio/security/issues/3
- 主要言語
- TypeScript
- スター
- 4
- フォーク
- 1
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
loopbackio/security のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
loopbackio/security#42 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#41 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#40 ·
-
openjsf
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#39 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
loopbackio/security#38 ·
loopbackio/security の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
Doist/todoist-cli#576 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
vercel-labs/skills#2370 ·
メンテナーはふだん 1 日以内に返信
-
🐛 Bug supabase/cli
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
CopilotKit/aimock#491 ·
メンテナーはふだん 1 日以内に返信