跳转到内容
ossscanner.org

威胁模型生成器

告诉 AI 扫描器项目中的重要事项

大多数误报都是因为扫描器误解了攻击者是谁。简短的威胁模型可以解决这个问题。勾选相应选项,将文件复制到 .oss-scanner/threat_model.md,ossscanner.org 和 Anthropic 的 OSS Scanner 都会遵循其中的说明。

不可信输入——应视为恶意输入
不在范围内——请勿报告

候选补丁

去重

.oss-scanner/threat_model.md

# Threat model

## About the project

_Describe what the project does and who runs it._

## Untrusted input (treat as adversarial)

- Bytes received over the network (sockets, protocol messages, peers).
- Files that users open or upload (documents, images, media, fonts).

## Out of scope (do not report)

- Test code, fixtures and fuzzing harnesses.
- Examples, demos and documentation snippets.
- Build scripts, CI configuration and developer-only tooling.
- Denial of service that needs very large inputs or sustained traffic.

## Severity rubric

- **critical**: Remote code execution or full authentication bypass on a default configuration.
- **high**: Memory corruption, privilege escalation or exposure of other users' data with a realistic attack path.
- **medium**: Limited impact, or significant preconditions such as non-default settings or an authenticated attacker.
- **low**: Hardening issues with no demonstrated security impact.

## Report format

- Keep reports short: one-paragraph summary first, then affected file and lines, impact, reproducer and fix.
- Candidate patches: minimal, enough to show the root cause and how to fix it.
- Deduplicate by root cause: one report per underlying bug even if it is reachable from several places.

将此文件作为 .oss-scanner/threat_model.md 提交到你的仓库。生成的文件为英文,因此所有扫描器和贡献者都能阅读。你也可以将其粘贴到 ossscanner.org 上已登记项目的设置中。

威胁模型为何重要

AI 扫描器善于发现可能出现异常行为的代码,但它们无法知道在你的项目中,给定输入是否由攻击者控制。配置文件是由运维人员写入,还是由匿名用户写入?CLI 是具有特权的 setuid 二进制文件,还是开发者工具?缺少这些背景信息,它们就会报告你根本不会修复的漏洞,并错误评定严重性。

Anthropic 正是出于这个原因建议提供威胁模型文件;测试过其扫描器的维护者表示,最常见的问题是严重性被夸大,以及对威胁模型的理解有误。

应包含哪些内容

  • 项目的功能,以及由谁运行。
  • 不可信数据的入口:网络、文件、请求、插件。
  • 可信内容:运维人员配置、本地用户、构建环境。
  • 不在范围内的内容:测试、示例、仅限本地的问题、使用超大输入的 DoS。
  • 如何评定严重性,以便你和扫描器对“严重”有相同的理解。
  • 报告应采用什么形式:补丁风格、有用的概念验证、去重。

保持简短即可。一页足够。

文件放置位置

默认情况下,两个扫描器都会从仓库根目录读取 .oss-scanner/threat_model.md。对于 Anthropic 的扫描器,你也可以在 project.yaml 中设置其他路径,或将 threat_model.md 放在其仓库中的 project.yaml 旁边。在 ossscanner.org 上,你可以将其粘贴到已登记项目的设置中。更改将在下一次扫描时生效。