Habr•September 12, 2026•🇷🇺Translated from Russian

Fuzzy Logic in Cybersecurity: Reducing Vulnerability Queue by 7.5 Times with CVSS, EPSS and FSTEC Comparison

An experienced security analyst has built a fuzzy logic model that cuts the vulnerability remediation queue by a factor of 7.5 while providing more nuanced prioritization than CVSS, EPSS or the Russian FSTEC methodology.

From Ancient Paradoxes to Modern Vulnerability Scoring

The work begins with the classic Sorites paradox: removing one grain of sand from a heap does not stop it being a heap, yet continued removal eventually destroys the concept. This illustrates that many real-world categories have blurred boundaries. The same problem appears in vulnerability management when analysts apply hard thresholds such as “if CVSS ≥ 9.0 then critical.”

CVSS (Common Vulnerability Scoring System) version 3.1 produces a score from 0 to 10 together with an attack vector string. While useful, the metric answers only “how bad could exploitation be” and “how difficult is exploitation,” not “how likely is exploitation in the next 30 days.” EPSS (Exploit Prediction Scoring System) supplies the missing probability but still yields a single crisp number that analysts must threshold manually.

Fuzzy Sets and Membership Functions

Lotfi Zadeh introduced fuzzy sets in 1965, allowing an element to belong to a set to a degree between 0 and 1. Membership is not probability: a liquid with membership 0.91 in the set of drinkable fluids is almost certainly potable, whereas a probability of 0.91 only states that 91 out of 100 similar samples would be safe.

The analyst implemented four common membership function shapes: triangular, trapezoidal, Gaussian and sigmoidal. For EPSS values, which cluster heavily near zero, a logarithmic transformation combined with trapezoidal functions proved most practical. The linguistic variable for EPSS contains five terms: negligible, low, medium, high and critical.

Rule Base Construction and Mamdani Inference

A complete rule base must satisfy coverage and consistency. With three inputs each having three terms, 27 rules are required; five inputs would demand 3125 rules, so the author cascaded multiple smaller inference blocks. Each rule follows the form “IF EPSS is high AND impact is complete THEN urgency is immediate.”

The Mamdani algorithm performs four steps: fuzzification of crisp inputs, evaluation of rule firing strength using the minimum t-norm, aggregation of clipped output membership functions, and defuzzification by centroid calculation. In one test case (CVE-2025-49113 in Roundcube Webmail), an EPSS of 0.30, impact of 5.9 and age of 244 days produced an urgency score of 94.4, placing the issue in the “immediate, 24-hour window” category.

Practical Results and Comparison

Side-by-side evaluation against raw CVSS thresholds, EPSS probability cut-offs and the FSTEC risk matrix showed a 7.5-fold reduction in the number of vulnerabilities requiring urgent attention. The fuzzy model also avoided the “hole” problem where certain input combinations receive no rule coverage. The author notes that the Mamdani method is especially suitable when results must be explained to auditors, while a Sugeno-style approach would offer faster numerical tuning.

The complete implementation, written from scratch in approximately 200 lines of Python without external fuzzy libraries, is intended both as a working tool and as an educational artifact demonstrating every stage of fuzzy inference applied to real vulnerability data.

Related articles

Security NEXT•Vulnerabilities & Exploits

WatchGuard Fireware OS Affected by 15 Vulnerabilities Including Critical CVE-2026-86131

WatchGuard Technologies disclosed 15 vulnerabilities in Fireware OS, the operating system powering its UTM appliances. The advisories were published between September 29 and 30, 2026, covering issues that range from remote code execution and authorization bypass to file disclosure and denial of service. Impact varies by deployment, yet none of the flaws had been observed in active exploitation at disclosure time. The most severe finding, CVE-2026-86131 in BOVPN Over TLS, received a CVSS v4.0 base score of 9.2 and Critical rating. This code-injection flaw in client configuration handling allows an attacker who controls the VPN server to execute arbitrary commands with root privileges on the connecting Firebox device. The remaining vulnerabilities affect multiple components and are tracked under separate CVE identifiers listed in the official advisories.

Habr•Vulnerabilities & Exploits

Rust Researcher Builds AI Pipeline to Test 900 Vulnerability Hypotheses Across Crates and Linux Kernel

Sergey Gordeychik developed the rust-in-peace research harness that combines multiple LLM agents, traditional SAST tools, and dynamic verification to hunt for memory-safety, logic, and API misuse issues in Rust code. The system generates independent hypotheses, attempts to refute them with separate agents, then validates survivors through fuzzing, protocol tests, or container execution. Starting from the Damn Vulnerable Rust Application, the pipeline was expanded to popular crates including x509-parser, h2, and lopdf, ultimately producing a Linux kernel patch. Experiments showed that three parallel analysis passes yielded 20 confirmed findings after triage, with nine appearing in all passes. The work also highlighted how models can produce convincing but false positives when context such as dependency checks or call order is missing. Gordeychik presented the approach at ZeroNights under the title Rust in Peace: How to Raise Your Own Pet Mythos.

Security NEXT•Vulnerabilities & Exploits

Critical Zero-Day Vulnerability in FortiMail Allows Unauthenticated File Writes

Fortinet disclosed a critical zero-day vulnerability in its FortiMail email security product that is already being exploited in attacks. The flaw, tracked as CVE-2026-104286, affects the graphical user interface component and stems from improper sanitization of path traversal and NULL byte sequences. Attackers can craft malicious HTTP requests to write arbitrary files to the system without authentication. The vulnerability received a CVSS v3.1 base score of 9.8, classifying it as Critical. Fortinet discovered the issue internally but has also received reports of active exploitation. Planned patches include FortiMail 8.0.2, 7.6.7, and 7.4.9, while users on the 7.2 branch are advised to migrate to 7.4 or later.

Habr•Vulnerabilities & Exploits

Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It

A detailed investigation reveals that Android VPN clients suffer from two distinct server address leaks when split tunneling is enabled. The first leak, tied to an unprotected local SOCKS proxy on 127.0.0.1, was quickly mitigated by most Xray and sing-box based clients through random ports and passwords. The second, more persistent leak allows excluded applications to bind sockets directly to the tun0 interface and discover the VPN server IP without root or special permissions. Only TeapodStream and OlConnect implemented owner-UID checks using ConnectivityManager.getConnectionOwnerUid, yet both initially mishandled the INVALID_UID response returned for excluded apps. AmneziaVPN has unmerged pull requests that correctly reject unknown owners, while sing-box offers a manual package_name_regex rule. v2rayNG closed the report as not planned, and major clients including WireGuard for Android, Mullvad, Proton VPN and others have issued no statements.