Skip to content

The words, as we use them

Security vocabulary carries a lot of assumed meaning. These are the terms that matter most to how Gecko works, defined plainly, with the mechanism attached.

Terms

Terms we have a position on. Each definition leads with a direct answer, then explains what is actually happening underneath.

B

Business logic vulnerability
A flaw in what the application is allowed to do rather than in how it was written. Nothing is misconfigured and no unsafe function is called; the rules of the system simply permit a sequence they should not, such as applying a refund twice. These exist only in your specific application, which is why finding them requires understanding what the software is for.

C

Class of vulnerability
A class is the shape of a mistake rather than one instance of it. SQL injection is a class; the specific query in one service is an instance. Closing the instance closes a ticket. Closing the class removes the instances that share its root cause, including the ones nobody has found yet.
Coverage
How much of a system has genuinely been reasoned about, measured by reach rather than by how many scans ran. A scan that touches every repository and understands none of them reports high coverage and delivers little.

F

False positive
A finding that is not real. The expensive part is not the minute spent checking it, it is what a long list teaches a team over time: that findings can be skipped. A tool that is frequently wrong makes its accurate findings cheaper to ignore.

N

Name resolution
Working out what a name in the code actually refers to, the way a compiler does. The same identifier means different things in different scopes, so a tool that guesses reports bugs in code that does not exist and stays quiet about the code that does.

R

Reachability
Whether a vulnerable line can actually be driven by input. A dependency can carry a published vulnerability that no code path in your system ever calls. Reachability separates the findings someone can exploit from the ones that only look urgent in a list.
Recurrence
How often a vulnerability you already fixed comes back. New code brings new vulnerabilities, and it always will. Old ones returning is a different problem, and it is the one a programme can actually measure itself against. Recurrence is the number Gecko asks teams to watch, ahead of mean time to remediate.
Remediation
The change that removes a vulnerability, as distinct from the note that records it. A remediation is finished when the pattern stops being reachable, not when the ticket is closed.
Root cause
The decision that made a bug possible, rather than the line where it surfaced. A missing check in one shared helper can produce findings in twenty files. Twenty patches leave the helper exactly as it was.

S

Semantic graph
A model of what code means rather than what it says. It records which function a call actually reaches, which values can flow into it, and which boundaries that flow crosses. Text search finds a string. A semantic graph finds behaviour.

T

Taint tracking
Following untrusted input through a program to see where it ends up. The input is marked where it arrives, then tracked across assignments, calls and service boundaries until it either reaches something dangerous or is made safe.
Triage
Deciding which findings deserve attention. Triage is a response to volume, and most security tooling is built to help teams sort a long list faster. The other option is to produce fewer, better-founded findings so that sorting matters less.
Trust boundary
The line where data moves between something you control and something you do not. Request handlers, queue consumers and the joins between services are all trust boundaries. Assumptions that hold on one side of that line frequently stop holding on the other.
Trust gradient
The staged path from reviewing every suggested fix to letting them go straight to a developer. You would not give a new colleague production access on their first day. A trust gradient applies the same judgement to an automated one, widening access at the pace the evidence earns it.

V

Variant analysis
The search for every other place a known mistake already exists. Once one instance is understood, variant analysis asks what else has the same shape, across services and languages, including the copies that were pasted before anyone knew the original was wrong.

See what this looks like on your codebase