Loading...
Loading...
Compare original and translation side by side
| Category | Description | Security Property | Mitigation Focus |
|---|---|---|---|
| Spoofing | Impersonating users or systems | Authentication | MFA, certificates, strong auth |
| Tampering | Modifying data or code | Integrity | Signing, checksums, validation |
| Repudiation | Denying actions | Non-repudiation | Audit logs, digital signatures |
| Information Disclosure | Exposing data | Confidentiality | Encryption, access controls |
| Denial of Service | Disrupting availability | Availability | Rate limiting, redundancy |
| Elevation of Privilege | Gaining unauthorized access | Authorization | RBAC, least privilege |
| 类别 | 描述 | 安全属性 | 缓解重点 |
|---|---|---|---|
| 仿冒 | 冒充用户或系统 | 身份认证 | 多因素认证(MFA)、证书、强认证机制 |
| 篡改 | 修改数据或代码 | 完整性 | 签名、校验和、验证机制 |
| 抵赖 | 否认已执行的操作 | 不可抵赖性 | 审计日志、数字签名 |
| 信息泄露 | 泄露敏感数据 | 保密性 | 加密、访问控制 |
| 拒绝服务 | 破坏系统可用性 | 可用性 | 速率限制、冗余机制 |
| 权限提升 | 获取未授权访问权限 | 授权 | 基于角色的访问控制(RBAC)、最小权限原则 |
| DFD Element | S | T | R | I | D | E |
|---|---|---|---|---|---|---|
| External Entity | X | X | ||||
| Process | X | X | X | X | X | X |
| Data Store | X | X | X | X | ||
| Data Flow | X | X | X |
| DFD元素 | S | T | R | I | D | E |
|---|---|---|---|---|---|---|
| 外部实体 | X | X | ||||
| 流程 | X | X | X | X | X | X |
| 数据存储 | X | X | X | X | ||
| 数据流 | X | X | X |
Layer 1: PERIMETER
WAF, DDoS mitigation, DNS filtering, rate limiting
Layer 2: NETWORK
Segmentation, IDS/IPS, network monitoring, VPN, mTLS
Layer 3: HOST
Endpoint protection, OS hardening, patching, logging
Layer 4: APPLICATION
Input validation, authentication, secure coding, SAST
Layer 5: DATA
Encryption at rest/transit, access controls, DLP, backupLayer 1: PERIMETER
WAF, DDoS mitigation, DNS filtering, rate limiting
Layer 2: NETWORK
Segmentation, IDS/IPS, network monitoring, VPN, mTLS
Layer 3: HOST
Endpoint protection, OS hardening, patching, logging
Layer 4: APPLICATION
Input validation, authentication, secure coding, SAST
Layer 5: DATA
Encryption at rest/transit, access controls, DLP, backup| Use Case | Recommended Pattern |
|---|---|
| Web application | OAuth 2.0 + PKCE with OIDC |
| API authentication | JWT with short expiration + refresh tokens |
| Service-to-service | mTLS with certificate rotation |
| CLI/Automation | API keys with IP allowlisting |
| High security | FIDO2/WebAuthn hardware keys |
| 用例 | 推荐模式 |
|---|---|
| Web应用 | OAuth 2.0 + PKCE 搭配 OIDC |
| API身份认证 | 短过期时间JWT + 刷新令牌 |
| 服务间认证 | 带证书轮换的mTLS |
| CLI/自动化 | 带IP白名单的API密钥 |
| 高安全场景 | FIDO2/WebAuthn硬件密钥 |
| Rank | Vulnerability | Testing Approach |
|---|---|---|
| A01 | Broken Access Control | Manual IDOR testing, authorization checks |
| A02 | Cryptographic Failures | Algorithm review, key management audit |
| A03 | Injection | SAST + manual payload testing |
| A04 | Insecure Design | Threat modeling, architecture review |
| A05 | Security Misconfiguration | Configuration audit, CIS benchmarks |
| A06 | Vulnerable Components | Dependency scanning, CVE monitoring |
| A07 | Authentication Failures | Password policy, session management review |
| A08 | Software/Data Integrity | CI/CD security, code signing verification |
| A09 | Logging Failures | Log review, SIEM configuration check |
| A10 | SSRF | Manual URL manipulation testing |
| 排名 | 漏洞 | 测试方法 |
|---|---|---|
| A01 | 访问控制失效 | 手动IDOR测试、授权检查 |
| A02 | 加密失败 | 算法审查、密钥管理审计 |
| A03 | 注入 | SAST + 手动载荷测试 |
| A04 | 不安全设计 | 威胁建模、架构审查 |
| A05 | 安全配置错误 | 配置审计、CIS基准检查 |
| A06 | 易受攻击的组件 | 依赖扫描、CVE监控 |
| A07 | 身份认证失败 | 密码策略、会话管理审查 |
| A08 | 软件/数据完整性问题 | CI/CD安全、代码签名验证 |
| A09 | 日志记录失败 | 日志审查、SIEM配置检查 |
| A10 | 服务器端请求伪造(SSRF) | 手动URL操纵测试 |
| Impact / Exploitability | Easy | Moderate | Difficult |
|---|---|---|---|
| Critical | Critical | Critical | High |
| High | Critical | High | Medium |
| Medium | High | Medium | Low |
| Low | Medium | Low | Low |
| 影响 / 可利用性 | 易 | 中等 | 难 |
|---|---|---|---|
| 关键 | 关键 | 关键 | 高 |
| 高 | 关键 | 高 | 中 |
| 中 | 高 | 中 | 低 |
| 低 | 中 | 低 | 低 |
| Category | Check | Risk |
|---|---|---|
| Input Validation | All user input validated and sanitized | Injection |
| Output Encoding | Context-appropriate encoding applied | XSS |
| Authentication | Passwords hashed with Argon2/bcrypt | Credential theft |
| Session | Secure cookie flags set (HttpOnly, Secure, SameSite) | Session hijacking |
| Authorization | Server-side permission checks on all endpoints | Privilege escalation |
| SQL | Parameterized queries used exclusively | SQL injection |
| File Access | Path traversal sequences rejected | Path traversal |
| Secrets | No hardcoded credentials or keys | Information disclosure |
| Dependencies | Known vulnerable packages updated | Supply chain |
| Logging | Sensitive data not logged | Information disclosure |
| 类别 | 检查项 | 风险 |
|---|---|---|
| 输入验证 | 所有用户输入已验证与清理 | 注入攻击 |
| 输出编码 | 已应用上下文适配的编码 | XSS攻击 |
| 身份认证 | 密码使用Argon2/bcrypt哈希 | 凭证窃取 |
| 会话 | 已设置安全Cookie标记(HttpOnly、Secure、SameSite) | 会话劫持 |
| 授权 | 所有端点已执行服务器端权限检查 | 权限提升 |
| SQL | 仅使用参数化查询 | SQL注入 |
| 文件访问 | 已拒绝路径遍历序列 | 路径遍历攻击 |
| 密钥 | 无硬编码凭证或密钥 | 信息泄露 |
| 依赖 | 已知漏洞包已更新 | 供应链攻击 |
| 日志 | 未记录敏感数据 | 信息泄露 |
| Pattern | Issue | Secure Alternative |
|---|---|---|
| SQL string formatting | SQL injection | Use parameterized queries with placeholders |
| Shell command building | Command injection | Use subprocess with argument lists, no shell |
| Path concatenation | Path traversal | Validate and canonicalize paths |
| MD5/SHA1 for passwords | Weak hashing | Use Argon2id or bcrypt |
| Math.random for tokens | Predictable values | Use crypto.getRandomValues |
| 模式 | 问题 | 安全替代方案 |
|---|---|---|
| SQL字符串格式化 | SQL注入 | 使用带占位符的参数化查询 |
| Shell命令构建 | 命令注入 | 使用带参数列表的subprocess,不调用shell |
| 路径拼接 | 路径遍历 | 验证并规范化路径 |
| MD5/SHA1用于密码 | 弱哈希 | 使用Argon2id或bcrypt |
| Math.random生成令牌 | 值可预测 | 使用crypto.getRandomValues |
| Level | Description | Response Time | Escalation |
|---|---|---|---|
| P1 - Critical | Active breach, data exfiltration | Immediate | CISO, Legal, Executive |
| P2 - High | Confirmed compromise, contained | 1 hour | Security Lead, IT Director |
| P3 - Medium | Potential compromise, under investigation | 4 hours | Security Team |
| P4 - Low | Suspicious activity, low impact | 24 hours | On-call engineer |
| 等级 | 描述 | 响应时间 | 升级对象 |
|---|---|---|---|
| P1 - 关键 | 正在发生的数据泄露、数据外渗 | 立即响应 | CISO、法务、高管 |
| P2 - 高 | 已确认的入侵,已被遏制 | 1小时内 | 安全负责人、IT总监 |
| P3 - 中 | 潜在入侵,正在调查 | 4小时内 | 安全团队 |
| P4 - 低 | 可疑活动,影响轻微 | 24小时内 | 值班工程师 |
| Phase | Actions |
|---|---|
| Identification | Validate alert, assess scope, determine severity |
| Containment | Isolate systems, preserve evidence, block access |
| Eradication | Remove threat, patch vulnerabilities, reset credentials |
| Recovery | Restore services, verify integrity, increase monitoring |
| Lessons Learned | Document timeline, identify gaps, update procedures |
| 阶段 | 行动 |
|---|---|
| 识别 | 验证告警、评估范围、确定严重程度 |
| 遏制 | 隔离系统、保存证据、阻止访问 |
| 根除 | 移除威胁、修复漏洞、重置凭证 |
| 恢复 | 恢复服务、验证完整性、增强监控 |
| 经验总结 | 记录时间线、识别差距、更新流程 |
| Category | Tools |
|---|---|
| SAST | Semgrep, CodeQL, Bandit (Python), ESLint security plugins |
| DAST | OWASP ZAP, Burp Suite, Nikto |
| Dependency Scanning | Snyk, Dependabot, npm audit, pip-audit |
| Secret Detection | GitLeaks, TruffleHog, detect-secrets |
| Container Security | Trivy, Clair, Anchore |
| Infrastructure | Checkov, tfsec, ScoutSuite |
| Network | Wireshark, Nmap, Masscan |
| Penetration | Metasploit, sqlmap, Burp Suite Pro |
| 类别 | 工具 |
|---|---|
| SAST | Semgrep、CodeQL、Bandit(Python)、ESLint安全插件 |
| DAST | OWASP ZAP、Burp Suite、Nikto |
| 依赖扫描 | Snyk、Dependabot、npm audit、pip-audit |
| 密钥检测 | GitLeaks、TruffleHog、detect-secrets |
| 容器安全 | Trivy、Clair、Anchore |
| 基础设施 | Checkov、tfsec、ScoutSuite |
| 网络 | Wireshark、Nmap、Masscan |
| 渗透测试 | Metasploit、sqlmap、Burp Suite Pro |
| Use Case | Algorithm | Key Size |
|---|---|---|
| Symmetric encryption | AES-256-GCM | 256 bits |
| Password hashing | Argon2id | N/A (use defaults) |
| Message authentication | HMAC-SHA256 | 256 bits |
| Digital signatures | Ed25519 | 256 bits |
| Key exchange | X25519 | 256 bits |
| TLS | TLS 1.3 | N/A |
| 用例 | 算法 | 密钥长度 |
|---|---|---|
| 对称加密 | AES-256-GCM | 256位 |
| 密码哈希 | Argon2id | 无(使用默认配置) |
| 消息认证 | HMAC-SHA256 | 256位 |
| 数字签名 | Ed25519 | 256位 |
| 密钥交换 | X25519 | 256位 |
| TLS | TLS 1.3 | 无 |
| Script | Purpose | Usage |
|---|---|---|
| threat_modeler.py | STRIDE threat analysis with risk scoring | |
| secret_scanner.py | Detect hardcoded secrets and credentials | |
| 脚本 | 用途 | 使用方法 |
|---|---|---|
| threat_modeler.py | 带风险评分的STRIDE威胁分析 | |
| secret_scanner.py | 检测硬编码密钥与凭证 | |
| Document | Content |
|---|---|
| security-architecture-patterns.md | Zero Trust, defense-in-depth, authentication patterns, API security |
| threat-modeling-guide.md | STRIDE methodology, attack trees, DREAD scoring, DFD creation |
| cryptography-implementation.md | AES-GCM, RSA, Ed25519, password hashing, key management |
| 文档 | 内容 |
|---|---|
| security-architecture-patterns.md | 零信任、纵深防御、身份认证模式、API安全 |
| threat-modeling-guide.md | STRIDE方法论、攻击树、DREAD评分、DFD创建 |
| cryptography-implementation.md | AES-GCM、RSA、Ed25519、密码哈希、密钥管理 |
| Framework | Focus | Applicable To |
|---|---|---|
| OWASP ASVS | Application security | Web applications |
| CIS Benchmarks | System hardening | Servers, containers, cloud |
| NIST CSF | Risk management | Enterprise security programs |
| PCI-DSS | Payment card data | Payment processing |
| HIPAA | Healthcare data | Healthcare applications |
| SOC 2 | Service organization controls | SaaS providers |
| 框架 | 重点 | 适用对象 |
|---|---|---|
| OWASP ASVS | 应用安全 | Web应用 |
| CIS基准 | 系统加固 | 服务器、容器、云环境 |
| NIST CSF | 风险管理 | 企业安全项目 |
| PCI-DSS | 支付卡数据 | 支付处理系统 |
| HIPAA | 医疗数据 | 医疗应用 |
| SOC 2 | 服务组织控制 | SaaS提供商 |
| Header | Recommended Value |
|---|---|
| Content-Security-Policy | default-src self; script-src self |
| X-Frame-Options | DENY |
| X-Content-Type-Options | nosniff |
| Strict-Transport-Security | max-age=31536000; includeSubDomains |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | geolocation=(), microphone=(), camera=() |
| 头字段 | 推荐值 |
|---|---|
| Content-Security-Policy | default-src self; script-src self |
| X-Frame-Options | DENY |
| X-Content-Type-Options | nosniff |
| Strict-Transport-Security | max-age=31536000; includeSubDomains |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | geolocation=(), microphone=(), camera=() |
| Skill | Integration Point |
|---|---|
| senior-devops | CI/CD security, infrastructure hardening |
| senior-secops | Security monitoring, incident response |
| senior-backend | Secure API development |
| senior-architect | Security architecture decisions |
| 技能 | 集成点 |
|---|---|
| senior-devops | CI/CD安全、基础设施加固 |
| senior-secops | 安全监控、事件响应 |
| senior-backend | 安全API开发 |
| senior-architect | 安全架构决策 |