usnistgov / mobile-threat-catalogue

NIST/NCCoE Mobile Threat Catalogue
https://pages.nist.gov/mobile-threat-catalogue
Other
142 stars 40 forks source link

WERB Review comment: Threats given attack types #119

Closed sdog-nist closed 7 years ago

sdog-nist commented 7 years ago

Entered on behalf of Jeffrey Chichonski, NIST

General Comment

Threat ID:

Type of Comment:

Proposed Change: Additional metadata for an Attack Type (i.e., eavesdropping, denial of service, replay attack, masquerade attack, MiTM, SQL Injection).

Justification: Cool if an organization that is interested in preventing certain types of attacks (e.g., DoS) could just search for 'DoS' and see all current threats within the catalog thus expanding the ways organization would be able to utilize the MTC.

boos commented 7 years ago

What about following my proposal? https://github.com/usnistgov/mobile-threat-catalogue/issues/120

I had the chance to talk about threats categorization using CVSS (instead of vulnerabilities categorization) with a guy that was involved in the definition of CVSS v3.0 and he confirmed that CVSS can be easily used to organize/categorize/classify threats as well.

cjb9 commented 7 years ago

Thanks. In the short and medium term, we will link to the appropriate ATT&CK type. See comment in #120

cjb9 commented 7 years ago

Closed per #128