D3FEND 防御知识库
技术列表 · 只读官方知识数据
D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-SFCVStack Frame Canary ValidationComparing a value stored in a stack frame with a known good value in order to prevent or detect a memory segment overwrite.HardenApplicationHardening08D3-SHNStandalone HoneynetAn environment created for the purpose of attracting attackers and eliciting their behaviors that is not connected to any production enterprise systems.DeceiveDecoyEnvironment00D3-SPPStrong Password PolicyModifying system configuration to increase password strength.HardenCredentialHardening14D3-SCASystem Call AnalysisAnalyzing system calls to determine whether a process is exhibiting unauthorized behavior.DetectProcessAnalysis147D3-SCFSystem Call FilteringControlling access to local computer system resources with kernel-level capabilities.IsolateAccessMediation166D3-SCPSystem Configuration PermissionsRestricting system configuration modifications to a specific user or group of users.HardenPlatformHardening014D3-SDMSystem Daemon MonitoringTracking changes to the state or configuration of critical system level processes.DetectOperatingSystemMonitoring03D3-SYSDMSystem Dependency MappingSystem dependency mapping identifies and models the dependencies of system components on each other to carry out their function.ModelSystemMapping00D3-SFASystem File AnalysisMonitoring system files such as authentication databases, configuration files, system logs, and system executables for modification or tampering.DetectOperatingSystemMonitoring110D3-SFVSystem Firmware VerificationCryptographically verifying installed system firmware integrity.DetectFirmwareVerification04D3-SICASystem Init Config AnalysisAnalysis of any system process startup configuration.DetectOperatingSystemMonitoring05D3-SYSMSystem MappingSystem mapping encompasses the techniques to identify the organization's systems, how they are configured and decomposed into subsystems and components, how they are dependent on one another, and where they are physically located.Model--40D3-SYSVASystem Vulnerability AssessmentSystem vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and can also include assessing risk emerging from the system's design as a whole, not just the sum of individual component vulnerabilities.ModelSystemMapping01D3-TBITPM Boot IntegrityAssuring the integrity of a platform by demonstrating that the boot process starts from a trusted combination of hardware and software and continues until the operating system has fully booted and applications are running. Sometimes called Static Root of Trust Measurement (STRM).HardenPlatformHardening00D3-TBToken BindingToken binding is a security mechanism used to enhance the protection of tokens, such as cookies or OAuth tokens, by binding them to a specific connection.HardenCredentialHardening07D3-TBAToken-based AuthenticationToken-based authentication is an authentication protocol where users verify their identity in exchange for a unique access token. Users can then access the website, application, or resource for the life of the token without having to re-enter their credentials.HardenAgentAuthentication07D3-TAANTransfer Agent AuthenticationValidating that server components of a messaging infrastructure are authorized to send a particular message.HardenMessageHardening00D3-TLTrusted LibraryA trusted library is a collection of pre-verified and secure code modules or components that are used within software applications to perform specific functions. These libraries are considered reliable and have been vetted for security vulnerabilities, ensuring they do not introduce risks into the application.HardenSourceCodeHardening02D3-UAURL AnalysisDetermining if a URL is benign or malicious by analyzing the URL or its components.DetectIdentifierAnalysis05D3-URAURL Reputation AnalysisAnalyzing the reputation of a URL.DetectIdentifierReputationAnalysis05D3-ULAUnlock AccountRestoring a user account's access to resources by unlocking a locked User Account.RestoreRestoreUserAccountAccess019D3-UAPUser Account PermissionsRestricting a user account's access to resources.IsolateAccessPolicyAdministration019D3-UBAUser Behavior AnalysisUser behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.Detect--110D3-UDTAUser Data Transfer AnalysisAnalyzing the amount of data transferred by a user.DetectUserBehaviorAnalysis00D3-UGLPAUser Geolocation Logon Pattern AnalysisMonitoring geolocation data of user logon attempts and comparing it to a baseline user behavior profile to identify anomalies in logon location.DetectUserBehaviorAnalysis090D3-UGPHUser Group PermissionsAccess control where access is determined based on attributes associated with users and the objects being accessed.IsolateAccessPolicyAdministration00D3-USICAUser Session Init Config AnalysisAnalyzing modifications to user session config files such as .bashrc or .bash_profile.DetectOperatingSystemMonitoring02D3-VIVariable InitializationSetting variables to a known value before use.HardenSourceCodeHardening02D3-VTVVariable Type ValidationEnsuring that a variable has the correct type.HardenSourceCodeHardening00D3-VSVideo SurveillanceMonitoring of physical areas via camera video feeds to deter, detect, and investigate unauthorized access and related security events.DetectPhysicalAccessMonitoring01