📝 用户指南 数据安全 文档中加入 威胁模型 章节 Fix https://github.com/siyuan-note/siyuan/issues/5250

This commit is contained in:
Liang Ding 2022-06-26 21:48:38 +08:00
parent 5ca22dc691
commit aa691726e0
No known key found for this signature in database
GPG key ID: 136F30F901A2231D
3 changed files with 2341 additions and 3 deletions

View file

@ -6,7 +6,7 @@
"id": "20210117215840-jcl17fx",
"title": "Data Security",
"type": "doc",
"updated": "20220111133319"
"updated": "20220626214710"
},
"Children": [
{
@ -346,6 +346,788 @@
]
}
]
},
{
"ID": "20220626214041-sz90qpf",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626214041-sz90qpf",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Threat Model"
}
]
},
{
"ID": "20220626214041-68ld138",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-68ld138",
"updated": "20220626214048"
},
"Children": [
{
"Type": "NodeText",
"Data": "It mainly evaluates local data security and SiYuan cloud storage security."
}
]
},
{
"ID": "20220626214041-mu28gc4",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214041-mu28gc4",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Premise"
}
]
},
{
"ID": "20220626214041-susd3su",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-susd3su",
"updated": "20220626214653"
},
"Children": [
{
"ID": "20220626214041-r7wqevv",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-r7wqevv",
"updated": "20220626214653"
},
"Children": [
{
"ID": "20220626214041-0ji5vg8",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-0ji5vg8",
"updated": "20220626214131"
},
"Children": [
{
"Type": "NodeText",
"Data": "The local host operating system is a fully trusted environment. This is the most basic premise of data security, and it can only be guaranteed based on this premise."
}
]
},
{
"ID": "20220626214041-0m7kunu",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-0m7kunu",
"updated": "20220626214653"
},
"Children": [
{
"ID": "20220626214041-v8p0as0",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-v8p0as0",
"updated": "20220626214653"
},
"Children": [
{
"ID": "20220626214041-asg2zwy",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-asg2zwy",
"updated": "20220626214653"
},
"Children": [
{
"Type": "NodeText",
"Data": "Availability of original data"
}
]
}
]
},
{
"ID": "20220626214041-4a0wgmi",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-4a0wgmi",
"updated": "20220626214649"
},
"Children": [
{
"ID": "20220626214041-xd159p7",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-xd159p7",
"updated": "20220626214649"
},
"Children": [
{
"Type": "NodeText",
"Data": "Rriginal data is not leaked"
}
]
}
]
},
{
"ID": "20220626214041-7x7h5tv",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-7x7h5tv",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-trypmwy",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-trypmwy",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Key security"
}
]
}
]
}
]
}
]
},
{
"ID": "20220626214041-walongz",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-walongz",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-qmyo4ov",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-qmyo4ov",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Users do not leak keys to attackers"
}
]
}
]
},
{
"ID": "20220626214041-r0gnkdl",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-r0gnkdl",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-rtbhm04",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-rtbhm04",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Data in cloud storage will not be deleted"
}
]
}
]
},
{
"ID": "20220626214041-w7h0sju",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-w7h0sju",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-2s2zb0n",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-2s2zb0n",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "AES-GCM encryption algorithm is not broken"
}
]
}
]
},
{
"ID": "20220626214041-ttywl0b",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-ttywl0b",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-3eek7k1",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-3eek7k1",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "The attacker cannot provide the computing power required for brute force cracking"
}
]
}
]
}
]
},
{
"ID": "20220626214041-ku1495e",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214041-ku1495e",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Cloud storage can guarantee"
}
]
},
{
"ID": "20220626214041-pmwe9u7",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-pmwe9u7",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-dcrtsao",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-dcrtsao",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-1ozs7g3",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-1ozs7g3",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Data can only be decrypted with the correct key"
}
]
}
]
},
{
"ID": "20220626214041-n2epubs",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-n2epubs",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-ofy8fcf",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-ofy8fcf",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Data cannot be decrypted after being tampered with"
}
]
}
]
}
]
},
{
"ID": "20220626214041-2i5mpyi",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214041-2i5mpyi",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Normal example"
}
]
},
{
"ID": "20220626214041-hxlxq6f",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-hxlxq6f",
"updated": "20220626214555"
},
"Children": [
{
"Type": "NodeText",
"Data": "Based on the above premises and guarantees, the following are examples of what an attacker can achieve."
}
]
},
{
"ID": "20220626214041-zhwz3ln",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-zhwz3ln",
"updated": "20220626214434"
},
"Children": [
{
"Type": "NodeText",
"Data": "If an attacker has read-only access to cloud storage, he can:"
}
]
},
{
"ID": "20220626214041-7fc1xei",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-7fc1xei",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-3w8hwp2",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-3w8hwp2",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-f2315iq",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-f2315iq",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Get the encrypted data and try brute force cracking"
}
]
}
]
},
{
"ID": "20220626214041-zx44bbo",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-zx44bbo",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-9424m7p",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-9424m7p",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Infer data size from index information"
}
]
}
]
}
]
},
{
"ID": "20220626214041-m3wwddi",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-m3wwddi",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "If an attacker is able to hijack the network, then he can:"
}
]
},
{
"ID": "20220626214041-mz2bu3y",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-mz2bu3y",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-3eofuvg",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-3eofuvg",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-ml4720h",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-ml4720h",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Tampering with data makes data unavailable"
}
]
}
]
},
{
"ID": "20220626214041-v1d69l9",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-v1d69l9",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-66rla1o",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-66rla1o",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Get user ID information"
}
]
}
]
},
{
"ID": "20220626214041-4sk5r3x",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-4sk5r3x",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-495954g",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-495954g",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Infer data size from traffic"
}
]
}
]
}
]
},
{
"ID": "20220626214041-eikbmi8",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626214041-eikbmi8",
"updated": "20220626214222"
},
"Children": [
{
"Type": "NodeText",
"Data": "Exception example"
}
]
},
{
"ID": "20220626214041-844aaoz",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-844aaoz",
"updated": "20220626214558"
},
"Children": [
{
"Type": "NodeText",
"Data": "If the above premises or guarantees are violated, the following are examples of what an attacker can achieve."
}
]
},
{
"ID": "20220626214041-tqyy2wg",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-tqyy2wg",
"updated": "20220626214626"
},
"Children": [
{
"Type": "NodeText",
"Data": "If an attacker is able to compromise the local host operating system, then he can:"
}
]
},
{
"ID": "20220626214041-t2pukqz",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-t2pukqz",
"updated": "20220626214644"
},
"Children": [
{
"ID": "20220626214041-vqdjcfd",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-vqdjcfd",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-55vp65s",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-55vp65s",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Modify or delete the original data, making the original data unavailable"
}
]
}
]
},
{
"ID": "20220626214041-081qsim",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-081qsim",
"updated": "20220626214642"
},
"Children": [
{
"ID": "20220626214041-csmhiio",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-csmhiio",
"updated": "20220626214642"
},
"Children": [
{
"Type": "NodeText",
"Data": "Get original data"
}
]
}
]
},
{
"ID": "20220626214041-77tr01l",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-77tr01l",
"updated": "20220626214644"
},
"Children": [
{
"ID": "20220626214041-wo4tkf4",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-wo4tkf4",
"updated": "20220626214644"
},
"Children": [
{
"Type": "NodeText",
"Data": "Get the key"
}
]
}
]
}
]
},
{
"ID": "20220626214041-9sz5qad",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-9sz5qad",
"updated": "20220626214710"
},
"Children": [
{
"Type": "NodeText",
"Data": "If an attacker has write access to cloud storage, he can:"
}
]
},
{
"ID": "20220626214041-bfgt82v",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214041-bfgt82v",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-qjop563",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214041-qjop563",
"updated": "20220626214041"
},
"Children": [
{
"ID": "20220626214041-pu5jrjr",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214041-pu5jrjr",
"updated": "20220626214041"
},
"Children": [
{
"Type": "NodeText",
"Data": "Modify or delete cloud storage, causing cloud storage data to be unavailable"
}
]
}
]
}
]
}
]
}

View file

@ -6,7 +6,7 @@
"id": "20210117211155-56n4odu",
"title": "数据安全",
"type": "doc",
"updated": "20220111133217"
"updated": "20220626213935"
},
"Children": [
{
@ -400,6 +400,780 @@
]
}
]
},
{
"ID": "20220626205507-zakjqo5",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626205507-zakjqo5",
"updated": "20220626205745"
},
"Children": [
{
"Type": "NodeText",
"Data": "威胁模型"
}
]
},
{
"ID": "20220626210804-d1iir4r",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210804-d1iir4r",
"updated": "20220626213925"
},
"Children": [
{
"Type": "NodeText",
"Data": "主要针对本地数据安全和思源云端存储安全进行评估。"
}
]
},
{
"ID": "20220626210024-c045aps",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626210024-c045aps",
"updated": "20220626213021"
},
"Children": [
{
"Type": "NodeText",
"Data": "前提假设"
}
]
},
{
"ID": "20220626210038-joi74n0",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626210038-joi74n0",
"updated": "20220626211139"
},
"Children": [
{
"ID": "20220626210038-412dnfz",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210038-412dnfz",
"updated": "20220626210038"
},
"Children": [
{
"ID": "20220626210038-us3tpf5",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210038-us3tpf5",
"updated": "20220626210326"
},
"Children": [
{
"Type": "NodeText",
"Data": "本地操作系统是完全受信任的环境。这是数据安全最基础的前提,基于该前提才能保证"
}
]
},
{
"ID": "20220626210254-707f04m",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626210254-707f04m"
},
"Children": [
{
"ID": "20220626210254-fr4kbsa",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210254-fr4kbsa"
},
"Children": [
{
"ID": "20220626210254-ldlvsgr",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210254-ldlvsgr",
"updated": "20220626210532"
},
"Children": [
{
"Type": "NodeText",
"Data": "原始数据的可用性"
}
]
}
]
},
{
"ID": "20220626210411-15gniy2",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210411-15gniy2"
},
"Children": [
{
"ID": "20220626210411-abr4ep7",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210411-abr4ep7",
"updated": "20220626210723"
},
"Children": [
{
"Type": "NodeText",
"Data": "原始数据不被泄漏"
}
]
}
]
},
{
"ID": "20220626210401-9o0os4g",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210401-9o0os4g"
},
"Children": [
{
"ID": "20220626210401-64ngms3",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210401-64ngms3",
"updated": "20220626210417"
},
"Children": [
{
"Type": "NodeText",
"Data": "密钥的安全性"
}
]
}
]
}
]
}
]
},
{
"ID": "20220626210629-dleyp1j",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210629-dleyp1j"
},
"Children": [
{
"ID": "20220626210629-7yee6s7",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210629-7yee6s7",
"updated": "20220626210707"
},
"Children": [
{
"Type": "NodeText",
"Data": "用户不泄漏密钥给攻击者"
}
]
}
]
},
{
"ID": "20220626210739-9bgfjnr",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626210739-9bgfjnr"
},
"Children": [
{
"ID": "20220626210739-2zabs74",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626210739-2zabs74",
"updated": "20220626210932"
},
"Children": [
{
"Type": "NodeText",
"Data": "云端存储中的数据不被删除"
}
]
}
]
},
{
"ID": "20220626211010-vq0mwwm",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626211010-vq0mwwm",
"updated": "20220626211025"
},
"Children": [
{
"ID": "20220626211010-6k8ivhp",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211010-6k8ivhp",
"updated": "20220626211025"
},
"Children": [
{
"Type": "NodeText",
"Data": "AES-GCM 加密算法未被攻破"
}
]
}
]
},
{
"ID": "20220626211022-6h7y6bs",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626211022-6h7y6bs",
"updated": "20220626211139"
},
"Children": [
{
"ID": "20220626211022-3n1z0hp",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211022-3n1z0hp",
"updated": "20220626211139"
},
"Children": [
{
"Type": "NodeText",
"Data": "攻击者无法提供暴力破解所需算力"
}
]
}
]
}
]
},
{
"ID": "20220626210027-hhtc2a6",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626210027-hhtc2a6",
"updated": "20220626213850"
},
"Children": [
{
"Type": "NodeText",
"Data": "云端存储能够保证"
}
]
},
{
"ID": "20220626211230-el1oox9",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626211230-el1oox9",
"updated": "20220626211249"
},
"Children": [
{
"ID": "20220626211249-wrkarxp",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626211249-wrkarxp",
"updated": "20220626211249"
},
"Children": [
{
"ID": "20220626211249-2ovxrgo",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211249-2ovxrgo",
"updated": "20220626211503"
},
"Children": [
{
"Type": "NodeText",
"Data": "只有通过正确的密钥才能解密数据"
}
]
}
]
},
{
"ID": "20220626211459-k8c0zvf",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626211459-k8c0zvf"
},
"Children": [
{
"ID": "20220626211459-w4e8ch7",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211459-w4e8ch7",
"updated": "20220626211539"
},
"Children": [
{
"Type": "NodeText",
"Data": "数据被篡改后无法解密"
}
]
}
]
}
]
},
{
"ID": "20220626213039-vc4f1ts",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626213039-vc4f1ts",
"updated": "20220626213102"
},
"Children": [
{
"Type": "NodeText",
"Data": "正常示例"
}
]
},
{
"ID": "20220626211621-yw8d4zb",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211621-yw8d4zb",
"updated": "20220626211919"
},
"Children": [
{
"Type": "NodeText",
"Data": "基于上述假设和保证,下面是攻击者能够达成的目标示例。"
}
]
},
{
"ID": "20220626211754-ftwoqz4",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626211754-ftwoqz4",
"updated": "20220626212025"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻击者对云端存储具有只读权限,那么他能够:"
}
]
},
{
"ID": "20220626212000-iri4fhz",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626212000-iri4fhz",
"updated": "20220626212909"
},
"Children": [
{
"ID": "20220626212007-152nmb6",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626212007-152nmb6",
"updated": "20220626212007"
},
"Children": [
{
"ID": "20220626212007-sj2d1y0",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212007-sj2d1y0",
"updated": "20220626212245"
},
"Children": [
{
"Type": "NodeText",
"Data": "获取到已经加密的数据,尝试暴力破解"
}
]
}
]
},
{
"ID": "20220626212247-3ldjbn9",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626212247-3ldjbn9",
"updated": "20220626212909"
},
"Children": [
{
"ID": "20220626212247-bdfgh5c",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212247-bdfgh5c",
"updated": "20220626212909"
},
"Children": [
{
"Type": "NodeText",
"Data": "通过索引信息推断出数据大小"
}
]
}
]
}
]
},
{
"ID": "20220626212515-ap79woa",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212515-ap79woa",
"updated": "20220626212650"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻击者能够劫持网络,那么他能够:"
}
]
},
{
"ID": "20220626212651-jmsl9e0",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626212651-jmsl9e0",
"updated": "20220626212914"
},
"Children": [
{
"ID": "20220626212658-td3mom4",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626212658-td3mom4",
"updated": "20220626212658"
},
"Children": [
{
"ID": "20220626212658-cil0rtv",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212658-cil0rtv",
"updated": "20220626212759"
},
"Children": [
{
"Type": "NodeText",
"Data": "篡改数据造成数据不可用"
}
]
}
]
},
{
"ID": "20220626212804-op12pak",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626212804-op12pak"
},
"Children": [
{
"ID": "20220626212804-2kb2439",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212804-2kb2439",
"updated": "20220626212836"
},
"Children": [
{
"Type": "NodeText",
"Data": "获得用户 ID 信息"
}
]
}
]
},
{
"ID": "20220626212854-jn95j1j",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626212854-jn95j1j",
"updated": "20220626212914"
},
"Children": [
{
"ID": "20220626212854-4vfflua",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626212854-4vfflua",
"updated": "20220626212914"
},
"Children": [
{
"Type": "NodeText",
"Data": "通过流量推断出数据大小"
}
]
}
]
}
]
},
{
"ID": "20220626211209-ok2rvht",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626211209-ok2rvht",
"updated": "20220626213125"
},
"Children": [
{
"Type": "NodeText",
"Data": "异常示例"
}
]
},
{
"ID": "20220626213125-y4dolh0",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213125-y4dolh0",
"updated": "20220626213144"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果违反了上述假设或保证,下面是攻击者能够达成的目标和示例。"
}
]
},
{
"ID": "20220626213144-2t86jkw",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213144-2t86jkw",
"updated": "20220626213227"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻击者能够入侵本地操作系统,那么他能够:"
}
]
},
{
"ID": "20220626213227-y3lsr2u",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626213227-y3lsr2u",
"updated": "20220626213836"
},
"Children": [
{
"ID": "20220626213228-5y4ooc5",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626213228-5y4ooc5",
"updated": "20220626213653"
},
"Children": [
{
"ID": "20220626213228-mcfm0xy",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213228-mcfm0xy",
"updated": "20220626213653"
},
"Children": [
{
"Type": "NodeText",
"Data": "修改或删除原始数据,造成原始数据不可用"
}
]
}
]
},
{
"ID": "20220626213330-4qecgfd",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626213330-4qecgfd",
"updated": "20220626213831"
},
"Children": [
{
"ID": "20220626213330-ycd3hae",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213330-ycd3hae",
"updated": "20220626213831"
},
"Children": [
{
"Type": "NodeText",
"Data": "获得原始数据"
}
]
}
]
},
{
"ID": "20220626213347-bm66fsj",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626213347-bm66fsj",
"updated": "20220626213836"
},
"Children": [
{
"ID": "20220626213347-6a376wm",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213347-6a376wm",
"updated": "20220626213836"
},
"Children": [
{
"Type": "NodeText",
"Data": "获得密钥"
}
]
}
]
}
]
},
{
"ID": "20220626213353-klg8vw5",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213353-klg8vw5",
"updated": "20220626213537"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻击者对云端存储具有写入权限,那么他能够:"
}
]
},
{
"ID": "20220626213507-6er6cfn",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626213507-6er6cfn",
"updated": "20220626213935"
},
"Children": [
{
"ID": "20220626213541-93non0e",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626213541-93non0e",
"updated": "20220626213935"
},
"Children": [
{
"ID": "20220626213541-t09iiuw",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626213541-t09iiuw",
"updated": "20220626213935"
},
"Children": [
{
"Type": "NodeText",
"Data": "修改或删除云端存储,造成云端存储数据不可用"
}
]
}
]
}
]
}
]
}

View file

@ -5,7 +5,7 @@
"icon": "1f50f",
"id": "20211226115043-afhev0g",
"title": "資料安全",
"updated": "20220111133353"
"updated": "20220626214021"
},
"Children": [
{
@ -357,6 +357,788 @@
]
}
]
},
{
"ID": "20220626214021-in5zyhv",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626214021-in5zyhv",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "威脅模型"
}
]
},
{
"ID": "20220626214021-6tofzu0",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-6tofzu0",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "主要針對本地數據安全和思源雲端存儲安全進行評估。"
}
]
},
{
"ID": "20220626214021-viqft4z",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214021-viqft4z",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "前提假設"
}
]
},
{
"ID": "20220626214021-x8i173y",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-x8i173y",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-7gox8eu",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-7gox8eu",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-2wsjz7h",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-2wsjz7h",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "本地操作系統是完全受信任的環境。這是數據安全最基礎的前提,基於該前提才能保證"
}
]
},
{
"ID": "20220626214021-vlffl2a",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-vlffl2a",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-dsnclyw",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-dsnclyw",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-1n601ag",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-1n601ag",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "原始數據的可用性"
}
]
}
]
},
{
"ID": "20220626214021-w7t53bu",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-w7t53bu",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-ahy7fhq",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-ahy7fhq",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "原始數據不被洩漏"
}
]
}
]
},
{
"ID": "20220626214021-y8k9lz5",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-y8k9lz5",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-h2gyyuo",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-h2gyyuo",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "密鑰的安全性"
}
]
}
]
}
]
}
]
},
{
"ID": "20220626214021-ergkh2g",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-ergkh2g",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-hao852y",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-hao852y",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "用戶不洩漏密鑰給攻擊者"
}
]
}
]
},
{
"ID": "20220626214021-g0xbo70",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-g0xbo70",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-tblyjo1",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-tblyjo1",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "雲端存儲中的數據不被刪除"
}
]
}
]
},
{
"ID": "20220626214021-xdngup7",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-xdngup7",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-lebj0c9",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-lebj0c9",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "AES-GCM 加密算法未被攻破"
}
]
}
]
},
{
"ID": "20220626214021-axp1ikp",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-axp1ikp",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-jdn7lut",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-jdn7lut",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "攻擊者無法提供暴力破解所需算力"
}
]
}
]
}
]
},
{
"ID": "20220626214021-75a1qb0",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214021-75a1qb0",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "雲端存儲能夠保證"
}
]
},
{
"ID": "20220626214021-gz8p50i",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-gz8p50i",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-6mh42fa",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-6mh42fa",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-3268c0b",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-3268c0b",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "只有通過正確的密鑰才能解密數據"
}
]
}
]
},
{
"ID": "20220626214021-6qmxb8n",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-6qmxb8n",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-b8dnd5h",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-b8dnd5h",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "數據被篡改後無法解密"
}
]
}
]
}
]
},
{
"ID": "20220626214021-k0l9w1q",
"Type": "NodeHeading",
"HeadingLevel": 3,
"Properties": {
"id": "20220626214021-k0l9w1q",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "正常示例"
}
]
},
{
"ID": "20220626214021-h6pm7s8",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-h6pm7s8",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "基於上述假設和保證,下面是攻擊者能夠達成的目標示例。"
}
]
},
{
"ID": "20220626214021-n88bvde",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-n88bvde",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻擊者對雲端存儲具有隻讀權限,那麼他能夠:"
}
]
},
{
"ID": "20220626214021-bu1nuv1",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-bu1nuv1",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-3i7p5ux",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-3i7p5ux",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-u08ygc7",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-u08ygc7",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "獲取到已經加密的數據,嘗試暴力破解"
}
]
}
]
},
{
"ID": "20220626214021-udnvdb5",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-udnvdb5",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-v3l2lpa",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-v3l2lpa",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "通過索引信息推斷出數據大小"
}
]
}
]
}
]
},
{
"ID": "20220626214021-v7wq31z",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-v7wq31z",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻擊者能夠劫持網絡,那麼他能夠:"
}
]
},
{
"ID": "20220626214021-o83u6yc",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-o83u6yc",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-ly7r5qb",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-ly7r5qb",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-3utkkjt",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-3utkkjt",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "篡改數據造成數據不可用"
}
]
}
]
},
{
"ID": "20220626214021-lr58bwm",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-lr58bwm",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-qmq9vxb",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-qmq9vxb",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "獲得用戶 ID 信息"
}
]
}
]
},
{
"ID": "20220626214021-i53soj1",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-i53soj1",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-8nqmuhl",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-8nqmuhl",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "通過流量推斷出數據大小"
}
]
}
]
}
]
},
{
"ID": "20220626214021-v89v1l5",
"Type": "NodeHeading",
"HeadingLevel": 2,
"Properties": {
"id": "20220626214021-v89v1l5",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "異常示例"
}
]
},
{
"ID": "20220626214021-07gbtjr",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-07gbtjr",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果違反了上述假設或保證,下面是攻擊者能夠達成的目標和示例。"
}
]
},
{
"ID": "20220626214021-5mz1301",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-5mz1301",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻擊者能夠入侵本地操作系統,那麼他能夠:"
}
]
},
{
"ID": "20220626214021-57coq7j",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-57coq7j",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-m7n7mzh",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-m7n7mzh",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-j7hqbfp",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-j7hqbfp",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "修改或刪除原始數據,造成原始數據不可用"
}
]
}
]
},
{
"ID": "20220626214021-2b6ovit",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-2b6ovit",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-giszicf",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-giszicf",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "獲得原始數據"
}
]
}
]
},
{
"ID": "20220626214021-54puka1",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-54puka1",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-mcxeo69",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-mcxeo69",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "獲得密鑰"
}
]
}
]
}
]
},
{
"ID": "20220626214021-oxtgu33",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-oxtgu33",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "如果攻擊者對雲端存儲具有寫入權限,那麼他能夠:"
}
]
},
{
"ID": "20220626214021-8dj1v35",
"Type": "NodeList",
"ListData": {},
"Properties": {
"id": "20220626214021-8dj1v35",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-i8s5ai0",
"Type": "NodeListItem",
"ListData": {
"BulletChar": 42,
"Marker": "Kg=="
},
"Properties": {
"id": "20220626214021-i8s5ai0",
"updated": "20220626214021"
},
"Children": [
{
"ID": "20220626214021-ye9pf1i",
"Type": "NodeParagraph",
"Properties": {
"id": "20220626214021-ye9pf1i",
"updated": "20220626214021"
},
"Children": [
{
"Type": "NodeText",
"Data": "修改或刪除雲端存儲,造成雲端存儲數據不可用"
}
]
}
]
}
]
}
]
}