The words, as we use them
Security vocabulary carries a lot of assumed meaning. These are the terms that matter most to how Gecko works, defined plainly, with the mechanism attached.
Terms
Terms we have a position on. Each definition leads with a direct answer, then explains what is actually happening underneath.
B
- Business logic vulnerability
- A flaw in what the application is allowed to do rather than in how it was written. Nothing is misconfigured and no unsafe function is called; the rules of the system simply permit a sequence they should not, such as applying a refund twice. These exist only in your specific application, which is why finding them requires understanding what the software is for.
C
- Class of vulnerability
- A class is the shape of a mistake rather than one instance of it. SQL injection is a class; the specific query in one service is an instance. Closing the instance closes a ticket. Closing the class removes the instances that share its root cause, including the ones nobody has found yet.
- Coverage
- How much of a system has genuinely been reasoned about, measured by reach rather than by how many scans ran. A scan that touches every repository and understands none of them reports high coverage and delivers little.
F
- False positive
- A finding that is not real. The expensive part is not the minute spent checking it, it is what a long list teaches a team over time: that findings can be skipped. A tool that is frequently wrong makes its accurate findings cheaper to ignore.
N
- Name resolution
- Working out what a name in the code actually refers to, the way a compiler does. The same identifier means different things in different scopes, so a tool that guesses reports bugs in code that does not exist and stays quiet about the code that does.
R
- Reachability
- Whether a vulnerable line can actually be driven by input. A dependency can carry a published vulnerability that no code path in your system ever calls. Reachability separates the findings someone can exploit from the ones that only look urgent in a list.
- Recurrence
- How often a vulnerability you already fixed comes back. New code brings new vulnerabilities, and it always will. Old ones returning is a different problem, and it is the one a programme can actually measure itself against. Recurrence is the number Gecko asks teams to watch, ahead of mean time to remediate.
- Remediation
- The change that removes a vulnerability, as distinct from the note that records it. A remediation is finished when the pattern stops being reachable, not when the ticket is closed.
- Root cause
- The decision that made a bug possible, rather than the line where it surfaced. A missing check in one shared helper can produce findings in twenty files. Twenty patches leave the helper exactly as it was.
S
- Semantic graph
- A model of what code means rather than what it says. It records which function a call actually reaches, which values can flow into it, and which boundaries that flow crosses. Text search finds a string. A semantic graph finds behaviour.
T
- Taint tracking
- Following untrusted input through a program to see where it ends up. The input is marked where it arrives, then tracked across assignments, calls and service boundaries until it either reaches something dangerous or is made safe.
- Triage
- Deciding which findings deserve attention. Triage is a response to volume, and most security tooling is built to help teams sort a long list faster. The other option is to produce fewer, better-founded findings so that sorting matters less.
- Trust boundary
- The line where data moves between something you control and something you do not. Request handlers, queue consumers and the joins between services are all trust boundaries. Assumptions that hold on one side of that line frequently stop holding on the other.
- Trust gradient
- The staged path from reviewing every suggested fix to letting them go straight to a developer. You would not give a new colleague production access on their first day. A trust gradient applies the same judgement to an automated one, widening access at the pace the evidence earns it.
V
- Variant analysis
- The search for every other place a known mistake already exists. Once one instance is understood, variant analysis asks what else has the same shape, across services and languages, including the copies that were pasted before anyone knew the original was wrong.