๊ธ€ ์ž‘์„ฑ์ž: heogi

STRIDE Framework

Category Definition Policy Violated
Spoofing ์‚ฌ์šฉ์ž ๋˜๋Š” ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ๋ฌด๋‹จ ์•ก์„ธ์Šค Authentication(์ธ๊ฐ€)
Tampering ๋ฐ์ดํ„ฐ ๋˜๋Š” ์ฝ”๋“œ์˜ ๋ฌด๋‹จ ์ˆ˜์ • ๋˜๋Š” ์กฐ์ž‘ Integrity(๋ฌด๊ฒฐ์„ฑ)
Repudiation ์ˆ˜ํ–‰๋œ ํ–‰๋™์— ๋Œ€ํ•œ ๋ถ€์ธ Non-Repudiation(๋ถ€์ธ๋ฐฉ์ง€)
Information Disclosure ๋ฏผ๊ฐ ์ •๋ณด์— ๋Œ€ํ•œ ๋ฌด๋‹จ ์ ‘๊ทผ Confidentiality(๊ธฐ๋ฐ€์„ฑ)
Denial of Service ์‹œ์Šคํ…œ ๋˜๋Š” ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ๊ฐ€์šฉ์„ฑ ์ค‘๋‹จ Availability(๊ฐ€์šฉ์„ฑ)
Elevation of Privilege ์ ‘๊ทผ๊ถŒํ•œ์˜ ๋ฌด๋‹จ ์ƒ์Šน Authorisation(์ธ์ฆ)

 

'๐ŸชฌIncident Respose' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Threat Modelling  (0) 2023.12.06
๋ณด์•ˆ ๋™ํ–ฅ ์ฐธ๊ณ  ์‚ฌ์ดํŠธ  (0) 2023.10.15
MITRE ATT&CK  (0) 2023.08.20
Cyber Kill Chain  (0) 2023.08.15