
Un framework Pythonic per la modellazione delle minacce.
Il threat modeling tradizionale troppo spesso arriva tardi alla festa, o a volte non arriva affatto. Inoltre, creare flussi di dati e report manuali può richiedere moltissimo tempo. L'obiettivo di pytm è spostare il threat modeling verso sinistra, rendendo il threat modeling più automatizzato e incentrato sullo sviluppatore.
In base al tuo input e alla definizione del progetto architetturale, pytm può generare automaticamente i seguenti elementi:
Il file tm.py è un modello di esempio. Puoi eseguirlo per generare il report e i file immagine dei diagrammi a cui fa riferimento:```
mkdir -p tm
./tm.py --report docs/basic_template.md | pandoc -f markdown -t html > tm/report.html
./tm.py --dfd | dot -Tpng -o tm/dfd.png
./tm.py --seq | java -Djava.awt.headless=true -jar $PLANTUML_PATH -tpng -pipe > tm/seq.png
There's also an example `Makefile` that wraps all these into targets that can be easily shared for multiple models. If you have [GNU make](https://www.gnu.org/software/make/) installed (available by default on Linux distros but not on OSX), simply run:```
make MODEL=the_name_of_your_model_minus_.py
Dovresti avere plantuml.jar nella stessa directory del tuo modello, oppure impostare PLANTUML_PATH.
Per evitare di installare tutte le dipendenze, come pandoc o Java, lo script può essere eseguito all'interno di un container:```
export USE_DOCKER=true make image
make
### Getting Started - Variante Devbox
Per semplificare l'utilizzo di `pytm`, le dipendenze host possono essere completamente isolate usando [`Devbox`](https://github.com/jetify-com/devbox). Questa è di solito un'alternativa più leggera e più comoda rispetto all'approccio container OCI.
- Installa Devbox su Linux/MacOS: `curl -fsSL https://get.jetify.com/devbox | bash`
- Installa Devbox su [Windows/WSL](https://www.jetify.com/docs/devbox/installing-devbox/index#installing-wsl2)
- Aggiorna all'ultima versione di devbox: `devbox version update`
- Imposta il tuo token di accesso GitHub nel file `~/.config/nix/nix.conf`: `access-tokens = github.com=YOUR_TOKEN_HERE`
- Crea un nuovo ambiente shell isolato che includa tutti gli strumenti e i pacchetti specificati nel file `devbox.json` del progetto: `devbox shell`
- Visualizza il percorso completo dell'eseguibile di Python che verrà utilizzato quando digiti semplicemente `python` nel tuo terminale usando il comando which python. L'output dovrebbe essere il seguente percorso: `.devbox/nix/profile/default/bin/python`
- Verifica eseguendo il seguente comando, che dovrebbe generare un DFD come file PNG chiamato `sample.png`: `./tm.py --dfd | dot -Tpng -o sample.png`
- Esci dall'ambiente shell Devbox: `exit`
## Utilizzo
Tutti gli argomenti disponibili:```text
usage: tm.py [-h] [--debug] [--dfd] [--report REPORT] [--exclude EXCLUDE]
[--seq] [--list] [--colormap] [--describe DESCRIBE]
[--list-elements] [--json JSON] [--levels LEVELS [LEVELS ...]]
[--stale_days STALE_DAYS]
options:
-h, --help show this help message and exit
--debug print debug messages
--dfd output DFD
--report REPORT output report using the named template file (sample
template file is under docs/template.md)
--exclude EXCLUDE specify threat IDs to be ignored
--seq output sequential diagram
--list list all available threats
--colormap color the risk in the diagram
--describe DESCRIBE describe the properties available for a given element
--list-elements list all elements which can be part of a threat model
--json JSON output a JSON file
--levels LEVELS [LEVELS ...]
Select levels to be drawn in the threat model (int
separated by comma).
--stale_days STALE_DAYS
checks if the delta between the TM script and the code
described by it is bigger than the specified value in
days
L'argomento stale_days tenta di determinare di quanti giorni è distante lo script del modello (che stai scrivendo) dal codice che implementa il sistema modellato. Idealmente, nella maggior parte dei casi di un sistema sviluppato attivamente, dovrebbero essere abbastanza vicini. Puoi eseguirlo periodicamente per misurare il polso del tuo progetto e la 'freschezza' del tuo modello di minaccia.
Gli elementi attualmente disponibili sono: TM, Element, Server, ExternalEntity, Datastore, Actor, Process, SetOfProcesses, Dataflow, Boundary, Lambda, LLM e Agent.