kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Vexed by VEX Tools: Consistency Evaluation of Container Vulnerability Scanners
KTH, School of Electrical Engineering and Computer Science (EECS), Network and Systems Engineering.ORCID iD: 0009-0004-0657-095X
KTH, School of Electrical Engineering and Computer Science (EECS), Network and Systems Engineering.ORCID iD: 0000-0003-3922-9606
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Theoretical Computer Science, TCS.ORCID iD: 0000-0002-3600-6899
2026 (English)In: Foundations and Practice of Security - 18th International Symposium, FPS 2025, Revised Selected Papers, Springer Nature , 2026, Vol. 16402 LNCS, p. 139-156Conference paper, Published paper (Refereed)
Abstract [en]

The Vulnerability Exploitability eXchange (VEX) format has been introduced to complement Software Bill of Materials (SBOM) with security advisories of known vulnerabilities. VEX gives an accurate understanding of vulnerabilities found in the dependencies of third-party software, which is critical for secure software development and risk analysis. In this paper, we present a study that analyzes state-of-the-art VEX-generation tools (Trivy, Grype, DepScan, Scout, Snyk, OSV, Vexy) applied to containers. Our study examines how consistently different VEX-generation tools perform. By evaluating their performance across multiple datasets, we aim to gain insight into the overall maturity of the VEX-generation tool ecosystem, beyond any single implementation. We use the Jaccard and Tversky indices to produce similarity scores of tool results for three different datasets created from container images. Overall, our results show a low level of consistency among the tools, thus indicating a low level of maturity in the VEX tool space. We perform a number of experiments to explore the impact of different factors on the consistency of the results, with the difference in vulnerability databases queried showing the largest impact.

Place, publisher, year, edition, pages
Springer Nature , 2026. Vol. 16402 LNCS, p. 139-156
Keywords [en]
Cybersecurity, Docker Containers, Software Bill of Materials, Software Supply Chain, Software Vulnerability Management, Vulnerability Exploitability eXchange
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:kth:diva-383423DOI: 10.1007/978-3-032-20018-1_8Scopus ID: 2-s2.0-105040619279OAI: oai:DiVA.org:kth-383423DiVA, id: diva2:2070813
Conference
18th International Symposium on Foundations and Practice of Security, FPS 2025, Brest, France, Nov 25 2025 - Nov 27 2025
Note

Part of ISBN 9783032200174

QC 20260612

Available from: 2026-06-12 Created: 2026-06-12 Last updated: 2026-06-12Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Churakova, YekatierinaEkstedt, MathiasSchmid, Larissa

Search in DiVA

By author/editor
Churakova, YekatierinaEkstedt, MathiasSchmid, Larissa
By organisation
Network and Systems EngineeringTheoretical Computer Science, TCS
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 10 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf