위협 모델 작성기
AI 스캐너에 프로젝트에서 중요한 사항을 알려 주세요
오탐의 대부분은 스캐너가 공격자가 누구인지 잘못 이해해서 발생합니다. 간단한 위협 모델로 이를 바로잡을 수 있습니다. 항목을 선택하고 파일을 .oss-scanner/threat_model.md에 복사하면 ossscanner.org와 Anthropic OSS Scanner 모두 이를 따릅니다.
패치 후보
중복 제거
.oss-scanner/threat_model.md
# Threat model ## About the project _Describe what the project does and who runs it._ ## Untrusted input (treat as adversarial) - Bytes received over the network (sockets, protocol messages, peers). - Files that users open or upload (documents, images, media, fonts). ## Out of scope (do not report) - Test code, fixtures and fuzzing harnesses. - Examples, demos and documentation snippets. - Build scripts, CI configuration and developer-only tooling. - Denial of service that needs very large inputs or sustained traffic. ## Severity rubric - **critical**: Remote code execution or full authentication bypass on a default configuration. - **high**: Memory corruption, privilege escalation or exposure of other users' data with a realistic attack path. - **medium**: Limited impact, or significant preconditions such as non-default settings or an authenticated attacker. - **low**: Hardening issues with no demonstrated security impact. ## Report format - Keep reports short: one-paragraph summary first, then affected file and lines, impact, reproducer and fix. - Candidate patches: minimal, enough to show the root cause and how to fix it. - Deduplicate by root cause: one report per underlying bug even if it is reachable from several places.
이 파일을 저장소의 .oss-scanner/threat_model.md로 커밋하세요. 생성된 파일은 모든 스캐너와 기여자가 읽을 수 있도록 영어로 작성됩니다. ossscanner.org에서 등록된 프로젝트의 설정에 직접 붙여넣을 수도 있습니다.
위협 모델이 중요한 이유
AI 스캐너는 오동작할 수 있는 코드를 잘 찾아내지만, 프로젝트에서 특정 입력을 공격자가 제어할 수 있는지는 알 수 없습니다. 설정 파일은 운영자가 작성하나요, 아니면 익명의 사용자가 작성하나요? CLI는 권한이 높은 setuid 바이너리인가요, 아니면 개발자 도구인가요? 이런 맥락이 없으면 실제로는 수정하지 않을 버그를 보고하고 심각도를 잘못 평가합니다.
Anthropic은 바로 이런 이유로 위협 모델 파일을 권장합니다. 스캐너를 테스트한 유지관리자들은 가장 흔한 오류로 과도하게 높게 평가된 심각도와 잘못 이해된 위협 모델을 꼽았습니다.
포함할 내용
- 프로젝트의 기능과 사용자를 설명합니다.
- 신뢰할 수 없는 데이터가 들어오는 경로를 설명합니다. 예: 네트워크, 파일, 요청, 플러그인.
- 신뢰할 수 있는 항목을 설명합니다. 예: 운영자 설정, 로컬 사용자, 빌드 환경.
- 범위에서 제외되는 항목을 설명합니다. 예: 테스트, 예제, 로컬에서만 발생하는 문제, 대용량 입력으로 인한 DoS.
- 심각도를 평가하는 기준을 설명하여, 심각도가 스캐너와 동일한 의미로 통하도록 합니다.
- 보고서의 형식을 설명합니다. 예: 패치 형식, 유용한 PoC, 중복 제거.
간결하게 작성하세요. 한 페이지면 충분합니다.
파일 위치
두 스캐너 모두 기본적으로 repo 루트에 있는 .oss-scanner/threat_model.md를 읽습니다. Anthropic 스캐너의 경우 project.yaml에서 다른 경로를 지정하거나, 해당 repo에서 project.yaml과 같은 위치에 threat_model.md를 둘 수도 있습니다. ossscanner.org에서는 등록된 프로젝트의 설정에 내용을 붙여 넣을 수 있습니다. 변경 사항은 다음 스캔부터 적용됩니다.