D3FEND 防御知识库

技术列表 · 只读官方知识数据

D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-HDHomoglyph DetectionComparing strings using a variety of techniques to determine if a deceptive or malicious string is being presented to a user.DetectIdentifierAnalysis09D3-HRHost RebootInitiating a host's reboot sequence to terminate all running processes.EvictHostShutdown021D3-HSHost ShutdownInitiating a host's shutdown sequence to terminate all running processes.EvictProcessEviction121D3-IOPRIO Port RestrictionLimiting access to computer input/output (IO) ports to restrict unauthorized devices.IsolateAccessMediation09D3-IPRAIP Reputation AnalysisAnalyzing the reputation of an IP address.DetectIdentifierReputationAnalysis00D3-IPCTAIPC Traffic AnalysisAnalyzing standard inter process communication (IPC) protocols to detect deviations from normal protocol activity.DetectNetworkTrafficAnalysis01D3-IAAIdentifier Activity AnalysisTaking known malicious identifiers and determining if they are present in a system.DetectIdentifierAnalysis05D3-IDIdentifier AnalysisAnalyzing identifier artifacts such as IP address, domain names, or URL(I)s.Detect--40D3-IRAIdentifier Reputation AnalysisAnalyzing the reputation of an identifier.DetectIdentifierAnalysis40D3-ISVAInbound Session Volume AnalysisAnalyzing inbound network session or connection attempt volume.DetectNetworkTrafficAnalysis09D3-ITFInbound Traffic FilteringRestricting network traffic originating from untrusted networks destined towards a private host or enclave.IsolateNetworkTrafficFiltering19D3-IBCAIndirect Branch Call AnalysisAnalyzing vendor specific branch call recording in order to detect ROP style attacks.DetectProcessAnalysis00D3-IDAInput Device AnalysisOperating system level mechanisms to prevent abusive input device exploitation.DetectOperatingSystemMonitoring03D3-IRVInteger Range ValidationEnsuring that an integer is within a valid range.HardenSourceCodeHardening00D3-IHNIntegrated HoneynetThe practice of setting decoys in a production environment to entice interaction from attackers.DeceiveDecoyEnvironment00D3-JFAPAJob Function Access Pattern AnalysisDetecting anomalies in user access patterns by comparing user access activity to behavioral profiles that categorize users by role such as job title, function, department.DetectUserBehaviorAnalysis00D3-KBPIKernel-based Process IsolationUsing kernel-level capabilities to isolate processes.IsolateExecutionIsolation021D3-LAMEDLAN Access MediationLAN access mediation encompasses the application of strict access control policies, systematic verification of devices, and authentication mechanisms to govern connectivity to a Local Area Network.IsolateNetworkAccessMediation00D3-LAMLocal Account MonitoringAnalyzing local user accounts to detect unauthorized activity.DetectUserBehaviorAnalysis03D3-LFAMLocal File Access MediationLocal file access mediation is the process of an operating system granting or denying a specific access request to a local file.IsolateSystemCallFiltering00D3-LFPLocal File PermissionsLocal file permissions is the systematic process of defining, implementing, and managing access control policies that dictate user permissions for accessing files on a local system through the configuration of operating system functionality.IsolateAccessPolicyAdministration0111D3-LLMLogical Link MappingLogical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata.ModelNetworkMapping217D3-MBSVMemory Block Start ValidationEnsuring that a pointer accurately references the beginning of a designated memory block.HardenPointerValidation00D3-MBTMemory Boundary TrackingAnalyzing a call stack for return addresses which point to unexpected memory locations.DetectOperatingSystemMonitoring011D3-MAMessage AnalysisAnalyzing email or instant message content to detect unauthorized activity.Detect--20D3-MANMessage AuthenticationAuthenticating the sender of a message and ensuring message integrity.HardenMessageHardening135D3-MENCRMessage EncryptionEncrypting a message body using a cryptographic key.HardenMessageHardening035D3-MHMessage HardeningThe application of security controls to user-to-user and system-to-system communications so messages remain confidential, unaltered, and verifiable while resisting injection, replay, and tampering.Harden--30D3-MSMMotion Sensor MonitoringMonitoring events from motion detectors (e.g., passive IR, microwave, dual-technology) to detect presence or movement within protected areas.DetectPhysicalAccessMonitoring00D3-MFAMulti-factor AuthenticationRequiring proof of two or more pieces of evidence in order to authenticate a user.HardenAgentAuthentication025
272 条 · 第 5/10