D3FEND 防御知识库

技术列表 · 只读官方知识数据

D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-CSPPClient-server Payload ProfilingComparing client-server request and response payloads to a baseline profile to identify outliers.DetectNetworkTrafficAnalysis090D3-CIConfiguration InventoryConfiguration inventory identifies and records the configuration of software and hardware and their components throughout the organization.ModelAssetInventory062D3-CHNConnected HoneynetA decoy service, system, or environment, that is connected to the enterprise network, and simulates or emulates certain functionality to the network, without exposing full access to a production system.DeceiveDecoyEnvironment00D3-CAAConnection Attempt AnalysisAnalyzing failed connections in a network to detect unauthorized activity.DetectNetworkTrafficAnalysis018D3-CIAContainer Image AnalysisAnalyzing a Container Image with respect to a set of policies.ModelAssetVulnerabilityEnumeration01D3-CNEContent ExcisionRemoving specific, potentially malicious, parts of contentIsolateContentModification00D3-CFContent FilteringContent Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputing a sanitized version.Isolate--3110D3-CFCContent Format ConversionContent format conversion is mechanical transformation from one format to another which may be normalization or specifically flattening.IsolateContentModification00D3-CMContent ModificationModify content that does not comply with policy.IsolateContentFiltering4110D3-CQContent QuarantineTransfer content that does not comply with policy to a quarantine zone.IsolateContentFiltering0123D3-CNRContent RebuildRebuild the file according to the spec so any unreferenced components or objects are removed.IsolateContentModification00D3-CNSContent SubstitutionModifies specific digital content information by replacing it with something else.IsolateContentModification00D3-CVContent ValidationVerify and validate contents complies with policyIsolateContentFiltering10D3-CFIControl Flow IntegrityEnforcing legal control flow transfers during application process execution.HardenApplicationHardening00D3-CCSACredential Compromise Scope AnalysisDetermining which credentials may have been compromised by analyzing the user logon history of a particular system.DetectUserBehaviorAnalysis025D3-CECredential EvictionCredential Eviction techniques disable or remove compromised credentials from a computer network.Evict--30D3-CHCredential HardeningCredential Hardening techniques modify system or network properties in order to protect system or network/domain credentials.Harden--425D3-CRCredential RevocationDeleting a set of credentials permanently to prevent them from being used to authenticate.EvictCredentialEviction025D3-CROCredential RotationCredential rotation is a security procedure in which authentication credentials, such as passwords, API keys, or certificates, are regularly changed or replaced to minimize the risk of unauthorized access.HardenCredentialHardening225D3-CSCredential ScrubbingThe systematic removal of hard-coded credentials from source code to prevent accidental exposure and unauthorized access.HardenSourceCodeHardening02D3-CTSCredential Transmission ScopingLimiting the transmission of a credential to a scoped set of relying parties.IsolateAccessMediation025D3-DNSALDNS AllowlistingPermitting only approved domains and their subdomains to be resolved.IsolateNetworkIsolation02D3-DNSCEDNS Cache EvictionFlushing DNS to clear any IP addresses or other DNS records from the cache.EvictObjectEviction00D3-DNSDLDNS DenylistingBlocking DNS Network Traffic based on criteria such as IP address, domain name, or DNS query type.IsolateNetworkIsolation32D3-DNSTADNS Traffic AnalysisAnalysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host.DetectNetworkTrafficAnalysis04D3-DEMData Exchange MappingData exchange mapping identifies and models the organization's intended design for the flows of the data types, formats, and volumes between systems at the application layer.ModelSystemMapping00D3-DIData InventoryData inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.ModelAssetInventory031D3-DQSADatabase Query String AnalysisAnalyzing database queries to detect [SQL Injection](https://capec.mitre.org/data/definitions/66.html).DetectProcessAnalysis01D3-DCEDead Code EliminationRemoving unreachable or "dead code" from compiled source code.HardenApplicationHardening00D3-DEDecoy EnvironmentA Decoy Environment comprises hosts and networks for the purposes of deceiving an attacker.Deceive--31
272 条 · 第 2/10