Repository navigation
Version 0.7.0
This new version of coreLang comes with the following changes:
- Refactor the codebase into five separate files, one for each category of assets
- Rework
DataAccess,Read,Write, andDeleteattack steps to follow the same pattern as the rest of the language and only propagate via themselves and one level at time whenDatacontain otherData. - Introduce
Dependenceassociation betweenDataandApplicationsto represent circumstances where modifying a particular set ofDatacan give the attacker control over theApplication(FullAccess) and denying them would prevent theApplicationfrom performing its tasks(Deny). - Have
Usersspread malware to otherHardwaresystems that they have access to in order to depict worm malware replication. This change also introduced theNoRemovableMediaUsagedefence on theUserwhich is enabled by default to not confuse the modeller if they are are not interested in these aspects. - Split network connectivity into two separate components
InspectedandUninspectedtraffic. The inspection is payload inspection specifically.- Uninspected communications do not impose any limitations on the attacker's activities.
- Inspected communications carry some limitations. Such as, preventing the attacker from exploiting
SoftwareVulnerabilities, and limitingReverseReach(which in turn is needed to maximise the impact ofUnsafeUserActivityand preventExtractonData).
- Have
Dataencryption viaCredentialsbypassPayloadInspectiononConnectionRulesthat we know can be used to transfer theData. - Minor fixes, improvements, date updates, and typo corrections.