Skip to content

Version 0.4.0

Choose a tag to compare

@andrewbwm andrewbwm released this 05 Nov 19:02
· 119 commits to master since this release

This new version of coreLang comes with the following major changes:

  • Rework how unsafe user actions are implemented:
    • Introduce logic to represent autonomous(where the attacker cannot reach or be reached, but has deployed through other means) malicious code.
    • Simplify privileges logic(remove high/low distinction when it comes to unsafe user actions). Privileges are presented via the Identity asset that is now automatically compromised when a social engineering attack occurs.
    • Remove unforced unsafe user activity. This was deemed extraneous and was leading to orphan attack graphs that couldn't properly be represented in the visualisation tools.
  • Remove many attack steps(eavesdrop, manInTheMiddle, transmit, and transmitResponse) from the ConnectionRule asset. The idea is to utilise connection rules more like virtual assets that specify connectivity rather than elements that themselves transmit the data.
  • Introduce SendData and ReceiveData associations between Data and Application assets to more easily represent directionality in data flows.
  • Introduce IDPS(Intrusion Detection and Prevention System) asset that can be associated with an Application to protect it from malicious actions.
  • Introduce credentials hashing association between Credentials assets.
  • Remove authenticated defence on the Data asset and replace it with a signing association that is analogous to the Credentials - Data encryption relationship. This allows the attacker to also break authentication if they are able to attain the Credentials used for signing.
  • Changed deny on Application to occur when all of the networking assets(ConnectionRules and Networks) associated with it have been denied. This was done to match the current info strings and git commit messages, it is not seen as a solved issue, see #66.
  • Remove reverse takeover attack steps as they are now covered by unsafe user actions instead.
  • Writing Credentials leads to them becoming compromised, the idea being that the attacker overrides them for the authentication mechanism.
  • Minor documentation and comments updates.

As per usual, due to the the nature of the changes it is assumed that most previous models would no longer be compatible with this version.