Skip to content
Graph docs0.6

Security attack paths

Latest stable Based on Graph release 0.6.0

This example makes exploit, trust, privilege, and blocking transitions visible along an attack path. It uses TinkerGraph to isolate modeling from container and network variance. Read core model and TinkerPop first; use the selection guide before production.

  • Nodes: EntryAsset/Host/Principal/Credential/Vulnerability/Permission
  • Edges: CAN_REACH/EXPLOITS/COMPROMISES/RUNS_AS/HAS_CREDENTIAL/GRANTS_ACCESS/HAS_PERMISSION/CONTROLS_ASSET
  • Key properties: assetId, hostId, principalId, vulnerabilityId, severity, privilege, status

Use JDK 21, commit 72c0256e2e1cf61101d29852210e3c827ca93bc0, and the checked-in wrapper. Examples are not published; run this release fixture as a Gradle project from the release source checkout. In a consumer application, select only bluetape4k-dependencies:<ecosystem-version> and add the required graph module without an individual version.

Terminal window
./gradlew :security-attack-path-examples:test --tests "io.bluetape4k.graph.examples.securityattack.TinkerGraphSecurityAttackPathTest"

The test asserts that the escalation path includes web-service, ci-admin-token, and domain-admin, while customer-db remains blocked. A failure means an exploit or trust edge, privilege transition, or blocking rule changed.

  1. Schema
  2. Service
  3. Shared executable contract
  4. Concrete TinkerGraph test
  5. Build file

Continue from fraud-detection, then read network-topology. Also see paired APIs, testing, and operations.

Add one result-changing edge and assertion; repeat through the suspend API; then run a persistent-backend concrete test serially. Add disconnected and malformed inputs as diagnostics. This fixture does not prove throughput, clustering, authorization, tenant isolation, migration, backup, remote-driver timeout, or index quality.