Powered by CognoDB Cloud (openCypher / Bolt), FastAPI (Python), and React.
Modern software architectures rely on dozens of microservices, each pulling in direct third-party dependencies which in turn pull in deep transitive packages. When a critical zero-day vulnerability (such as Log4Shell, Spring4Shell, or the XZ Utils Backdoor) is disclosed, security and platform engineering teams face a critical challenge:
"Which of our customer-facing microservices and production environments are secretly exposed through a 3rd or 4th-degree transitive library dependency?"
ShieldGraph models microservices, package dependencies, environments, and CVEs as an interconnected property graph. It allows engineers to:
- Trace arbitrary-depth dependency chains (multi-hop traversal).
- Calculate the exact Blast Radius of any CVE across production infrastructure.
- Compute the shortest impact/remediation path.
- Simulate upstream patch upgrades to immediately quantify risk reduction.
Relational (SQL) databases organize data into rigid tabular rows and columns. In software supply chain security, the central questions are not about isolated rowsβthey are about dynamic, variable-length paths and topological connections.
| Capability | Graph Database (CognoDB / openCypher) | Relational Database (SQL) |
|---|---|---|
| Transitive Dependencies (Multi-Hop) | Index-Free Adjacency: Follows direct memory pointers in constant time per hop [:DEPENDS_ON*1..5]. |
Expensive Recursive CTEs: Requires WITH RECURSIVE with exponential join overhead and memory spikes. |
| Query Ergonomics | Concise, visual pattern matching (MATCH (s)-[:DEPENDS_ON*]->(p)-[:HAS_VULN]->(v)). |
4+ nested joins across Services, DirectDeps, TransitiveDeps, Packages, and CVEs. |
| Arbitrary Depth Traversal | Native variable-length syntax *1..N. Query engine handles cycles and depth naturally. |
Must pre-define fixed join levels or risk infinite loops without complex CTE cycle detection. |
| Shortest Path Analysis | Built-in shortestPath() graph algorithm executed directly in the database engine. |
Impossible in standard SQL without custom Dijkstra algorithms implemented in external application code. |
The graph data model consists of labeled nodes, typed directed relationships, and rich properties:
graph LR
subgraph Microservice Layer
S1[Service: CheckoutGateway]
S2[Service: AuthenticationService]
end
subgraph Package Dependency Layer
P1[Package: spring-boot-starter-web]
P2[Package: spring-core]
P3[Package: log4j-core]
P4[Package: express]
P5[Package: lodash]
end
subgraph Vulnerability Layer
V1["Vulnerability: CVE-2021-44228 (Log4Shell - CRITICAL)"]
V2["Vulnerability: CVE-2021-23337 (Lodash Injection - HIGH)"]
end
subgraph Infrastructure
E1[Environment: Production-US-East]
end
S1 -->|"DEPENDS_ON {isDirect: true}"| P1
P1 -->|"DEPENDS_ON {isTransitive: true}"| P2
P2 -->|"DEPENDS_ON {isTransitive: true}"| P3
P3 -->|HAS_VULNERABILITY| V1
S2 -->|"DEPENDS_ON {isDirect: true}"| P4
P4 -->|"DEPENDS_ON {isTransitive: true}"| P5
P5 -->|HAS_VULNERABILITY| V2
S1 -->|DEPLOYED_IN| E1
S2 -->|DEPLOYED_IN| E1
style S1 fill:#0284c7,stroke:#38bdf8,color:#fff
style S2 fill:#0284c7,stroke:#38bdf8,color:#fff
style P1 fill:#7c3aed,stroke:#c084fc,color:#fff
style P2 fill:#7c3aed,stroke:#c084fc,color:#fff
style P3 fill:#7c3aed,stroke:#c084fc,color:#fff
style P4 fill:#7c3aed,stroke:#c084fc,color:#fff
style P5 fill:#7c3aed,stroke:#c084fc,color:#fff
style V1 fill:#dc2626,stroke:#f87171,color:#fff
style V2 fill:#ea580c,stroke:#fb923c,color:#fff
style E1 fill:#059669,stroke:#34d399,color:#fff
(:Service):id,name,tier,team,env,status(:Package):id,name,version,ecosystem,license(:Vulnerability):id,cveId,title,severity,cvssScore,summary,fixVersion,remediation(:Environment):id,name,cloud,region
(:Service)-[:DEPENDS_ON {isDirect: true/false, scope: 'runtime'}]->(:Package)(:Package)-[:DEPENDS_ON {isTransitive: true}]->(:Package)(:Package)-[:HAS_VULNERABILITY]->(:Vulnerability)(:Service)-[:DEPLOYED_IN]->(:Environment)
All queries use the official Neo4j Python driver (neo4j) and use strict parameterization without string concatenation.
Finds all upstream services compromised by a specific CVE across variable dependency depth.
MATCH path = (s:Service)-[:DEPENDS_ON*1..5]->(p:Package)-[:HAS_VULNERABILITY]->(v:Vulnerability {cveId: $cveId})
OPTIONAL MATCH (s)-[:DEPLOYED_IN]->(e:Environment)
RETURN
s.id AS serviceId,
s.name AS serviceName,
s.tier AS tier,
e.name AS environment,
p.name AS vulnerablePackage,
p.version AS packageVersion,
v.cveId AS cveId,
v.severity AS severity,
v.cvssScore AS cvssScore,
[node in nodes(path) | {id: coalesce(node.id, node.cveId), name: coalesce(node.name, node.cveId), label: labels(node)[0]}] AS pathNodes,
length(path) AS depthHops
ORDER BY depthHops ASC;Ranks all microservices by their total count of transitive critical and high vulnerabilities.
MATCH (s:Service)
OPTIONAL MATCH (s)-[:DEPENDS_ON*1..5]->(p:Package)-[:HAS_VULNERABILITY]->(v:Vulnerability)
RETURN
s.id AS serviceId,
s.name AS serviceName,
s.tier AS tier,
s.team AS team,
count(DISTINCT v) AS totalCVEs,
count(DISTINCT CASE WHEN v.severity = 'CRITICAL' THEN v END) AS criticalCVEs,
count(DISTINCT CASE WHEN v.severity = 'HIGH' THEN v END) AS highCVEs,
collect(DISTINCT v.cveId) AS cveList
ORDER BY criticalCVEs DESC, totalCVEs DESC;Calculates the exact shortest sequence of dependencies linking a service to a CVE.
MATCH (s:Service {name: $serviceName}), (v:Vulnerability {cveId: $cveId})
MATCH path = shortestPath((s)-[:DEPENDS_ON|HAS_VULNERABILITY*]->(v))
RETURN
[node in nodes(path) | coalesce(node.name, node.cveId)] AS pathNodes,
length(path) AS hopCount;- Python 3.9+
- Node.js 18+ & npm
- A free CognoDB Cloud instance (from https://console.cognodb.com)
git clone https://github.com/<your-username>/shield-graph.git
cd shield-graph
# Copy backend environment template
cp backend/.env.example backend/.envEdit backend/.env with your CognoDB instance credentials:
COGNODB_URI=bolt+s://<your-instance-id>.databases.cognodb.cloud
COGNODB_USER=cognodb
COGNODB_PASSWORD=<your-generated-password>Note on Graceful Fallback: If CognoDB credentials are not provided or the database is offline, ShieldGraph automatically activates its rich local standby dataset so you can explore the full UI without interruption.
Run the seed script to clear and populate CognoDB with realistic microservice supply chains:
cd backend
pip install -r requirements.txt
python seed.pycd backend
uvicorn main:app --reload --port 8000API docs available at: http://localhost:8000/docs
cd frontend
npm install
npm run devOpen your browser at http://localhost:5173.
- Live Hosted Application: https://shield-graph.vercel.app
- Screen Recording Walkthrough: Watch Demo on Loom
- GitHub Repository: https://github.com/srikrishna0603/shield-graph
shield-graph/
βββ backend/
β βββ main.py # FastAPI REST API
β βββ db.py # CognoDB Neo4j driver connection pool & health checks
β βββ queries.py # Parameterized openCypher queries
β βββ mock_data.py # Seed dataset & offline fallback data
β βββ seed.py # CLI database seeding script
β βββ requirements.txt # Python dependencies
β βββ .env.example # Environment variable template
βββ frontend/
β βββ src/
β β βββ components/
β β β βββ GraphCanvas.jsx # Interactive Force-Directed Canvas
β β β βββ StatsOverview.jsx # Top-level SOC metrics
β β β βββ BlastRadiusModal.jsx # Transitive ripple simulator
β β β βββ CveExplorer.jsx # Filterable CVE cards & patch simulator
β β β βββ ServiceList.jsx # Microservices risk exposure table
β β β βββ QueryExplainerModal.jsx # Live Cypher vs SQL comparison modal
β β βββ api.js # API client
β β βββ App.jsx # Dashboard layout
β β βββ index.css # Dark Cyber SOC design tokens
β βββ package.json
β βββ vite.config.js
βββ INTERVIEW_CHEATSHEET.md# Comprehensive interview guide & plain-English code explanations
βββ vercel.json # Vercel deployment configuration
βββ README.md