《電子技術應用》
您所在的位置:首頁 > 通信與網絡 > 業(yè)界動態(tài) > 美國國家安全局發(fā)布D3FEND工具改進網絡防御和信息共享

美國國家安全局發(fā)布D3FEND工具改進網絡防御和信息共享

2021-07-10
來源: 網電空間戰(zhàn)

微信圖片_20210710100716.jpg

  華盛頓消息:美國國家安全局發(fā)布了一個全新的工具,幫助網絡戰(zhàn)士理解、溝通和選擇防御措施來阻止網絡攻擊

  D3FEND工具,正如它所稱的那樣,旨在補充MITRE ATT&CK 框架。ATT&CK 專注于標準化網絡戰(zhàn)士理解和談論進攻的方式,而 D3FEND 則專注于網絡防御。

  這些框架共同為網絡戰(zhàn)士提供了對網絡概念的共同理解和在談論它們時使用的標準化術語,這應該有助于更清晰的溝通,以便在組織內部和組織之間共享信息和協調防御行動。

  ATT&CK 可用于構建威脅模型以及實際事件的網絡殺傷鏈,以包括對手的行為及其戰(zhàn)術、技術和程序 (TTP),部分原因是 ATT&CK 基于現實世界的威脅。

  同樣,D3FEND 可用于通過“說明 [ing] 計算機網絡架構、威脅和網絡對策之間復雜的相互作用……闡明 [ing] 以前未指定的防御和進攻方法之間的關系來開發(fā)網絡防御。”

  由于 D3FEND 非常詳細,因此它可以作為構建、設計和實施網絡防御的有用指南。

  據其網站稱,D3FEND 部分基于過去二十年的 500 項對策專利。然而,值得注意的是,D3FEND 和 ATT&CK 是與供應商無關的框架,可用于保護廣泛的 IT 環(huán)境,包括國家安全系統、國防部網絡和國防工業(yè)基礎資產。

  美國國家安全局(NSA)資助了MITRE開發(fā) D3FEND的研究,但與 ATT&CK 一樣,它現在可以在線免費獲得。網絡專業(yè)人員可以在D3FEND 網站上提供意見和改進建議。

  Break Defense 聯系了美國國家安全局(NSA)征求意見,但在發(fā)布之前沒有收到任何評論。

  NSA Releases D3FEND To Improve Cyber Defenses, Info Sharing

  While ATT&CK focuses on standardizing the way cyber warriors understand and talk about offensive cyber, D3FEND focuses on common defensive measures.

  By   BRAD D. WILLIAMSon June 24, 2021 at 5:57 PM

  WASHINGTON: The National Security Agency has released a brand-new tool to help cyber warriors understand, communicate, and choose defensive measures to stop cyberattacks.

  D3FEND, as it's dubbed, is intended to complement the MITRE ATT&CK framework. Whereas ATT&CK focuses on standardizing the way cyber warriors understand and talk about offense, D3FEND focuses on cyber defenses.

  Together, the frameworks provide cyber warriors with a common understanding of cyber concepts and a standardized vocabulary to use when talking about them, which should facilitate clearer communication for sharing information and coordinating defensive operations both in and between organizations.

  ATT&CK can be used to build threat models, as well as cyber kill chains of actual incidents, to include adversaries' behaviors and their tactics, techniques, and procedures (TTPs), in part because ATT&CK is based on real-world threats.

  Likewise, D3FEND can be used to develop cyber defenses by “illustrat[ing] the complex interplay between computer network architectures, threats, and cyber countermeasures… illuminat[ing] previously-unspecified relationships between defensive and offensive methods.”

  Because D3FEND is so detailed, it can serve as a useful guide for architecting, designing, and implementing cyber defenses.

  D3FEND is based, in part, on 500 countermeasure patents from the last two decades, according to its website. Notably, however, D3FEND and ATT&CK are vendor-agnostic frameworks, which can be applied to safeguarding a wide range of IT environments, including national security systems, Defense Department networks, and defense industrial base assets.

  NSA funded MITRE's research for developing D3FEND, but like ATT&CK, it's freely available online now. Cyber professionals can provide comments and recommend improvements at the D3FEND website.

  Breaking Defense reached out to NSA for comments, but did not receive any before publication.




電子技術圖片.png

本站內容除特別聲明的原創(chuàng)文章之外,轉載內容只為傳遞更多信息,并不代表本網站贊同其觀點。轉載的所有的文章、圖片、音/視頻文件等資料的版權歸版權所有權人所有。本站采用的非本站原創(chuàng)文章及圖片等內容無法一一聯系確認版權者。如涉及作品內容、版權和其它問題,請及時通過電子郵件或電話通知我們,以便迅速采取適當措施,避免給雙方造成不必要的經濟損失。聯系電話:010-82306118;郵箱:aet@chinaaet.com。
主站蜘蛛池模板: 亚洲大片免费看| 无码任你躁久久久久久久| 国产精品v片在线观看不卡| 亚州三级久久电影| 里番acg※里番acg本子全彩| 把水管开水放b里是什么感觉| 亚洲激情视频图片| 五月婷婷六月天| 婷婷国产成人精品视频| 久久综合综合久久综合| 老师好大好爽办公室视频| 娇妻借朋友高h繁交h| 久久综合网欧美色妞网| 深夜福利视频网站| 国产精品videossex国产高清| 一级毛片无遮挡免费全部| 波多野结衣在丈夫面前| 国产中文在线视频| japanese21hdxxxx喷潮| 欧美日韩亚洲一区二区精品 | 人妻有码中文字幕| 试看120秒做暖暖免费体验区| 国产精品亚洲一区二区三区在线| 久久久久成人片免费观看蜜芽| 欧美精品国产综合久久| 动漫美女人物被黄漫小说| 黑冰女王踩踏视频免费专区| 成人免费v片在线观看| 亚洲AV无码成人精品区在线观看 | 久久国产精品77777| 精品久久久无码中文字幕| 国产肉丝袜在线观看| 中文字幕手机在线播放| 毛片网站免费在线观看| 和僧侣的交行之夜樱花| 黄色福利视频网站| 国产精品无码永久免费888| j8又粗又大又长又爽又硬男男| 无人视频免费观看免费直播在线观看| 亚洲综合色丁香婷婷六月图片 | 最刺激黄a大片免费网站|