
खतरे के मॉडलिंग के लिए एक पायथोनिक ढांचा
पारंपरिक धमकी मॉडलिंग अक्सर बहुत देर से आती है, या कभी-कभी बिल्कुल नहीं आती। इसके अलावा, मैन्युअल डेटा फ्लो और रिपोर्ट बनाना बेहद समय लेने वाला हो सकता है। pytm का लक्ष्य धमकी मॉडलिंग को बाईं ओर स्थानांतरित करना है, जिससे धमकी मॉडलिंग अधिक स्वचालित और डेवलपर-केंद्रित हो जाए।
आपके इनपुट और आर्किटेक्चरल डिज़ाइन की परिभाषा के आधार पर, pytm स्वचालित रूप से निम्नलिखित आइटम उत्पन्न कर सकता है:
tm.py एक उदाहरण मॉडल है। आप इसे चलाकर उन रिपोर्ट और डायग्राम इमेज फ़ाइलों को उत्पन्न कर सकते हैं जिनका यह संदर्भ देता है:```
mkdir -p tm
./tm.py --report docs/basic_template.md | pandoc -f markdown -t html > tm/report.html
./tm.py --dfd | dot -Tpng -o tm/dfd.png
./tm.py --seq | java -Djava.awt.headless=true -jar $PLANTUML_PATH -tpng -pipe > tm/seq.png
एक उदाहरण `Makefile` भी है जो इन सभी को लक्ष्यों में लपेटता है जिन्हें कई मॉडलों के लिए आसानी से साझा किया जा सकता है। यदि आपके पास [GNU make](https://www.gnu.org/software/make/) स्थापित है (लिनक्स वितरणों पर डिफ़ॉल्ट रूप से उपलब्ध, पर OSX पर नहीं), तो बस चलाएँ:
```bash
make help
make MODEL=the_name_of_your_model_minus_.py
आपके पास या तो अपने मॉडल के समान निर्देशिका में plantuml.jar होना चाहिए, या PLANTUML_PATH सेट करना चाहिए। सभी निर्भरताओं, जैसे `pandoc` या `Java` को स्थापित करने से बचने के लिए, स्क्रिप्ट को एक कंटेनर के अंदर चलाया जा सकता है:```
# do this only once
export USE_DOCKER=true
make image
# call this after every change in your model
make
pytm के उपयोग को सरल बनाने के लिए, होस्ट निर्भरताओं को Devbox का उपयोग करके पूरी तरह से अलग किया जा सकता है। यह आमतौर पर OCI कंटेनर दृष्टिकोण की तुलना में कम ओवरहेड और अधिक सुविधाजनक विकल्प है।
curl -fsSL https://get.jetify.com/devbox | bashdevbox version update~/.config/nix/nix.conf फ़ाइल फ़ाइल में सेट करें: access-tokens = github.com=YOUR_TOKEN_HEREdevbox.json फ़ाइल में निर्दिष्ट सभी टूल्स और पैकेजों को शामिल करते हुए एक नया, पृथक शेल वातावरण बनाएं: devbox shellpython टाइप करते हैं तो उपयोग किए जाने वाले Python निष्पादन योग्य का पूर्ण पथ प्रदर्शित करने के लिए which python कमांड का उपयोग करें। आउटपुट निम्न पथ होना चाहिए: .devbox/nix/profile/default/bin/pythonsample.png नामक PNG फ़ाइल के रूप में DFD उत्पन्न करना चाहिए: ./tm.py --dfd | dot -Tpng -o sample.pngexitसभी उपलब्ध तर्क:```text usage: tm.py [-h] [--debug] [--dfd] [--report REPORT] [--exclude EXCLUDE] [--seq] [--list] [--describe DESCRIBE] [--list-elements] [--json JSON] [--levels LEVELS [LEVELS ...]] [--stale_days STALE_DAYS]
optional arguments: -h, --help show this help message and exit --debug print debug messages --dfd output DFD --report REPORT output report using the named template file (sample template file is under docs/template.md) --exclude EXCLUDE specify threat IDs to be ignored --seq output sequential diagram --list list all available threats --colormap color the risk in the diagram --describe DESCRIBE describe the properties available for a given element --list-elements list all elements which can be part of a threat model --json JSON output a JSON file --levels LEVELS [LEVELS ...] Select levels to be drawn in the threat model (int separated by comma). --stale_days STALE_DAYS checks if the delta between the TM script and the code described by it is bigger than the specified value in days
The *stale_days* तर्क यह निर्धारित करने का प्रयास करता है कि मॉडल स्क्रिप्ट (जिसे आप लिख रहे हैं) और उस कोड के बीच दिनों में कितना अंतर है, जो मॉडल किए जा रहे सिस्टम को लागू करता है। आदर्श रूप से, सक्रिय रूप से विकसित सिस्टम के अधिकांश मामलों में वे काफी करीब होने चाहिए। आप अपने प्रोजेक्ट की धड़कन और अपने थ्रेट मॉडल की 'ताजगी' को मापने के लिए इसे समय-समय पर चला सकते हैं।
वर्तमान में उपलब्ध तत्व हैं: TM, Element, Server, ExternalEntity, Datastore, Actor, Process, SetOfProcesses, Dataflow, Boundary, Lambda, LLM और Agent।
एक तत्व के उपलब्ध गुणों को तत्व के नाम के बाद `--describe` का उपयोग करके सूचीबद्ध किया जा सकता है:```text
(pytm) ➜ pytm git:(master) ✗ ./tm.py --describe Element
Element class attributes:
OS
definesConnectionTimeout default: False
description
handlesResources default: False
implementsAuthenticationScheme default: False
implementsNonce default: False
inBoundary
inScope Is the element in scope of the threat model, default: True
isAdmin default: False
isHardened default: False
name required
onAWS default: False
The colormap तर्क, dfd के साथ उपयोग किया जाता है, एक रंग-कोडित DFD आउटपुट करता है जहां तत्वों को उनके जोखिम स्तर (नियमों को चलाकर पहचाने गए) के आधार पर लाल, पीले या हरे रंग में चित्रित किया जाता है।
devbox shellpytm का उपयोग हमेशा की तरह करेंexitनिम्नलिखित एक नमूना tm.py फ़ाइल है जो एक सरल एप्लिकेशन का वर्णन करती है जहां एक उपयोगकर्ता एप्लिकेशन में लॉग इन करता है और ऐप पर टिप्पणियाँ पोस्ट करता है। ऐप सर्वर उन टिप्पणियों को डेटाबेस में संग्रहीत करता है। एक AWS Lambda है जो समय-समय पर डेटाबेस को साफ करता है।```python
#!/usr/bin/env python3
from pytm import TM, Server, Datastore, Dataflow, Boundary, Actor, Lambda, LLM, Data, Classification
tm = TM("my test tm") tm.description = "another test tm" tm.isOrdered = True
User_Web = Boundary("User/Web") Web_DB = Boundary("Web/DB")
user = Actor("User") user.inBoundary = User_Web
web = Server("Web Server") web.OS = "CloudOS" web.isHardened = True web.sourceCode = "server/web.cc"
db = Datastore("SQL Database (*)") db.OS = "CentOS" db.isHardened = False db.inBoundary = Web_DB db.isSql = True db.inScope = False db.sourceCode = "model/schema.sql"
comments = Data(
name="Comments",
description="Comments in HTML or Markdown",
classification=Classification.PUBLIC,
isPII=False,
isCredentials=False,
# credentialsLife=Lifetime.LONG,
isStored=True,
isSourceEncryptedAtRest=False,
isDestEncryptedAtRest=True
)
results = Data(
name="results",
description="Results of insert op",
classification=Classification.SENSITIVE,
isPII=False,
isCredentials=False,
# credentialsLife=Lifetime.LONG,
isStored=True,
isSourceEncryptedAtRest=False,
isDestEncryptedAtRest=True
)
my_lambda = Lambda("cleanDBevery6hours") my_lambda.hasAccessControl = True my_lambda.inBoundary = Web_DB
llm_api = LLM("AI Writing Assistant") llm_api.isThirdParty = True llm_api.processesPersonalData = True llm_api.hasContentFiltering = False llm_api.hasSystemPrompt = True llm_api.processesUntrustedInput = True