D3FEND 防御知识库
技术列表 · 只读官方知识数据
D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-PHDURAPer Host Download-Upload Ratio AnalysisDetecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host.DetectNetworkTrafficAnalysis090D3-PFVPeripheral Firmware VerificationCryptographically verifying peripheral firmware integrity.DetectFirmwareVerification00D3-PAMPhysical Access MediationPhysical access mediation is the process of granting or denying specific requests to enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances.)IsolateAccessMediation10D3-PHAMPhysical Access MonitoringMonitoring the physical access of a specified environment through detection, recording, reviewing, and logging of who/what enters and exists areas.Detect--40D3-PEHPhysical Enclosure HardeningPhysical changes to a computer enclosure which reduce the ability for agents or the environment to affect the contained computer system.HardenPlatformHardening00D3-PLMPhysical Link MappingPhysical link mapping identifies and models the link connectivity of the network devices within a physical network.ModelNetworkMapping222D3-EPLPhysical LockingEmploy a mechanical locking device for securing moveable portions of physical barriers (e.g., doors, gates, drawers) in a secured position.IsolatePhysicalAccessMediation00D3-PHPlatform HardeningHardening components of a Platform with the intention of making them more difficult to exploit.
Platforms includes components such as:
* BIOS UEFI Subsystems
* Hardware security devices such as Trusted Platform Modules
* Boot process logic or code
* Kernel software componentsHarden--100D3-PMPlatform MonitoringMonitoring platform components such as operating systems software, hardware devices, or firmware.Detect--90D3-PUMPlatform Uptime MonitoringMonitor the amount of time since the last power cycle or restart.DetectPlatformMonitoring00D3-PANPointer AuthenticationComparing the cryptographic hash or derivative of a pointer's value to an expected value.HardenApplicationHardening00D3-PVPointer ValidationEnsuring that a pointer variable has the required properties for use.HardenSourceCodeHardening20D3-PAProcess AnalysisProcess Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.Detect--90D3-PCSVProcess Code Segment VerificationComparing the "text" or "code" memory segments to a source of truth.DetectProcessAnalysis011D3-PEProcess EvictionProcess eviction techniques terminate or remove running process.Evict--40D3-PLAProcess Lineage AnalysisIdentification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.DetectProcessSpawnAnalysis021D3-PSEPProcess Segment Execution PreventionPreventing execution of any address in a memory region other than the code segment.HardenApplicationHardening017D3-PSMDProcess Self-Modification DetectionDetects processes that modify, change, or replace their own code at runtime.DetectProcessAnalysis021D3-PSAProcess Spawn AnalysisAnalyzing spawn arguments or attributes of a process to detect processes that are unauthorized.DetectProcessAnalysis148D3-PSProcess SuspensionSuspending a running process on a computer system.EvictProcessEviction021D3-PTProcess TerminationTerminating a running application process on a computer system.EvictProcessEviction021D3-PMADProtocol Metadata Anomaly DetectionCollecting network communication protocol metadata and identifying statistical outliers.DetectNetworkTrafficAnalysis090D3-PSMProximity Sensor MonitoringMonitoring events from proximity sensors that indicate a credential or tagged asset is within the sensor’s read range or a defined zone. Common enabling technologies include RFID, Bluetooth Low Energy (BLE), and Ultra-Wideband (UWB).DetectPhysicalAccessMonitoring00D3-PBWSAMProxy-based Web Server Access MediationProxy-based web server access mediation focuses on the regulation of web server access through intermediary proxy servers.IsolateWebSessionAccessMediation00D3-RFSRF ShieldingAdding physical barriers to a platform to prevent undesired radio interference.HardenElectromagneticRadiationHardening00D3-RTARPC Traffic AnalysisMonitoring the activity of remote procedure calls in communication traffic to establish standard protocol operations and potential attacker activities.DetectNetworkTrafficAnalysis01D3-RHRadiation HardeningRadiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation.HardenPlatformHardening221D3-RNReference NullificationInvalidating all pointers that reference a specific memory block, ensuring that the block cannot be accessed or modified after deallocation.HardenSourceCodeHardening00D3-RKDRegistry Key DeletionDelete a registry key.EvictObjectEviction01D3-RICReissue CredentialIssue a new credential to a user which supercedes their old credential.RestoreRestoreAccess025