Repository navigation
Version 0.4.0
This new version of coreLang comes with the following major changes:
- Rework how unsafe user actions are implemented:
- Introduce logic to represent autonomous(where the attacker cannot reach or be reached, but has deployed through other means) malicious code.
- Simplify privileges logic(remove high/low distinction when it comes to unsafe user actions). Privileges are presented via the
Identityasset that is now automatically compromised when a social engineering attack occurs. - Remove unforced unsafe user activity. This was deemed extraneous and was leading to orphan attack graphs that couldn't properly be represented in the visualisation tools.
- Remove many attack steps(
eavesdrop,manInTheMiddle,transmit, andtransmitResponse) from theConnectionRuleasset. The idea is to utilise connection rules more like virtual assets that specify connectivity rather than elements that themselves transmit the data. - Introduce
SendDataandReceiveDataassociations betweenDataandApplicationassets to more easily represent directionality in data flows. - Introduce
IDPS(Intrusion Detection and Prevention System) asset that can be associated with anApplicationto protect it from malicious actions. - Introduce credentials hashing association between
Credentialsassets. - Remove
authenticateddefence on theDataasset and replace it with a signing association that is analogous to theCredentials-Dataencryption relationship. This allows the attacker to also break authentication if they are able to attain theCredentialsused for signing. - Changed deny on
Applicationto occur when all of the networking assets(ConnectionRulesandNetworks) associated with it have been denied. This was done to match the current info strings and git commit messages, it is not seen as a solved issue, see #66. - Remove reverse takeover attack steps as they are now covered by unsafe user actions instead.
- Writing
Credentialsleads to them becoming compromised, the idea being that the attacker overrides them for the authentication mechanism. - Minor documentation and comments updates.
As per usual, due to the the nature of the changes it is assumed that most previous models would no longer be compatible with this version.