D3FEND 防御知识库
技术列表 · 只读官方知识数据
D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-NAMNetwork Access MediationNetwork access mediation is the control method for authorizing access to a system by a user (or a process acting on behalf of a user) communicating through a network, including a local area network, a wide area network, and the Internet.IsolateAccessMediation20D3-NINetwork IsolationNetwork Isolation techniques prevent network hosts from accessing non-essential system network resources.Isolate--60D3-NMNetwork MappingNetwork mapping encompasses the techniques to identify and model the physical layer, network layer, and data exchange layers of the organization's network and their physical location, and determine allowed pathways through that network.Model--40D3-NNINetwork Node InventoryNetwork node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.) in the organization's architecture.ModelAssetInventory017D3-NRAMNetwork Resource Access MediationControl of access to organizational systems and services by users or processes over a network.IsolateAccessMediation28D3-NTANetwork Traffic AnalysisAnalyzing intercepted or summarized computer network traffic to detect unauthorized activity.Detect--170D3-NTCDNetwork Traffic Community DeviationEstablishing baseline communities of network hosts and identifying statistically divergent inter-community communication.DetectNetworkTrafficAnalysis090D3-NTFNetwork Traffic FilteringRestricting network traffic originating from any location.IsolateNetworkIsolation2119D3-NTPMNetwork Traffic Policy MappingNetwork traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or application levels.ModelNetworkMapping09D3-NTSANetwork Traffic Signature AnalysisAnalyzing network traffic and compares it to known signaturesDetectNetworkTrafficAnalysis090D3-NVANetwork Vulnerability AssessmentNetwork vulnerability assessment relates all the vulnerabilities of a network's components in the context of their configuration and interdependencies and can also include assessing risk emerging from the network's design as a whole, not just the sum of individual network node or network segment vulnerabilities.ModelNetworkMapping00D3-NPCNull Pointer CheckingChecking if a pointer is NULL.HardenPointerValidation00D3-OVAROT Variable Access RestrictionAssign read/write access controls on designated registers or data tags to prevent unauthorized writes.IsolateAccessMediation010D3-OEObject EvictionTerminate or remove an object from a host machine. This is the broadest class for object eviction.Evict--50D3-OTPOne-time PasswordA one-time password is valid for only one user authentication.HardenPasswordRotation04D3-OMMOperating Mode MonitoringDetects operating modes such as Program, Run, Remote, or Stop.DetectPlatformMonitoring02D3-OPROperating Mode RestrictionRestricting unauthorized changes to the operating mode prevents devices from switching into inappropriate or vulnerable states during normal use.IsolateAccessMediation02D3-OSMOperating System MonitoringThe operating system software, for D3FEND's purposes, includes the kernel and its process management functions, hardware drivers, initialization or boot logic. It also includes and other key system daemons and their configuration. The monitoring or analysis of these components for unauthorized activity constitute **Operating System Monitoring**.DetectPlatformMonitoring80D3-OAMOperational Activity MappingOperational activity mapping identifies activities of the organization and the organization's suborganizations, groups, roles, and individuals that carry out the activities and then establishes the dependencies of the activities on the systems and people that perform those activities.Model--40D3-ODMOperational Dependency MappingOperational dependency mapping identifies and models the dependencies of the organization's activities on each other and on the organization's performers (people, systems, and services.) This may include modeling the higher- and lower-level activities of an organization forming a hierarchy, or layering, of the dependencies in an organization's activities.ModelOperationalActivityMapping00D3-OLVOperational Logic ValidationValidation of variable state in the context of the control logic of the operational application.HardenDomainLogicValidation00D3-OPMOperational Process MonitoringMonitoring physical parameters and operator actions related to an operational environment.DetectPlatformMonitoring016D3-ORAOperational Risk AssessmentOperational risk assessment identifies and models the vulnerabilities of, and risks to, an organization's activities individually and as a whole.ModelOperationalActivityMapping00D3-OMOrganization MappingOrganization mapping identifies and models the people, roles, and groups with an organization and the relations between them.ModelOperationalActivityMapping00D3-OTFOutbound Traffic FilteringRestricting network traffic originating from a private host or enclave destined towards untrusted networks.IsolateNetworkTrafficFiltering032ParticleRadiationHardeningParticle Radiation HardeningThe application of material, process, layout, or circuit-level design measures to electronic systems and components to reduce susceptibility to total ionizing dose degradation and single-event effects caused by ionizing particles such as protons, heavy ions, neutrons, or electrons.HardenRadiationHardening00D3-PCAPassive Certificate AnalysisCollecting host certificates from network traffic or other passive sources like a certificate transparency log and analyzing them for unauthorized activity.DetectCertificateAnalysis00D3-PLLMPassive Logical Link MappingPassive logical link mapping only listens to network traffic as a means to map the the whole data link layer, where the links represent logical data flows rather than physical connections.ModelLogicalLinkMapping00D3-PWAPassword AuthenticationPassword authentication is a security mechanism used to verify the identity of a user or entity attempting to access a system or resource by requiring the input of a secret string of characters, known as a password, that is associated with the user or entity.HardenAgentAuthentication04D3-PRPassword RotationPassword rotation is a security policy that mandates the periodic change of user account passwords to mitigate the risk of unauthorized access due to compromised credentials.HardenCredentialRotation14