威胁模型生成器
告诉 AI 扫描器项目中的重要事项
大多数误报都是因为扫描器误解了攻击者是谁。简短的威胁模型可以解决这个问题。勾选相应选项,将文件复制到 .oss-scanner/threat_model.md,ossscanner.org 和 Anthropic 的 OSS Scanner 都会遵循其中的说明。
候选补丁
去重
.oss-scanner/threat_model.md
# Threat model ## About the project _Describe what the project does and who runs it._ ## Untrusted input (treat as adversarial) - Bytes received over the network (sockets, protocol messages, peers). - Files that users open or upload (documents, images, media, fonts). ## Out of scope (do not report) - Test code, fixtures and fuzzing harnesses. - Examples, demos and documentation snippets. - Build scripts, CI configuration and developer-only tooling. - Denial of service that needs very large inputs or sustained traffic. ## Severity rubric - **critical**: Remote code execution or full authentication bypass on a default configuration. - **high**: Memory corruption, privilege escalation or exposure of other users' data with a realistic attack path. - **medium**: Limited impact, or significant preconditions such as non-default settings or an authenticated attacker. - **low**: Hardening issues with no demonstrated security impact. ## Report format - Keep reports short: one-paragraph summary first, then affected file and lines, impact, reproducer and fix. - Candidate patches: minimal, enough to show the root cause and how to fix it. - Deduplicate by root cause: one report per underlying bug even if it is reachable from several places.
将此文件作为 .oss-scanner/threat_model.md 提交到你的仓库。生成的文件为英文,因此所有扫描器和贡献者都能阅读。你也可以将其粘贴到 ossscanner.org 上已登记项目的设置中。
威胁模型为何重要
AI 扫描器善于发现可能出现异常行为的代码,但它们无法知道在你的项目中,给定输入是否由攻击者控制。配置文件是由运维人员写入,还是由匿名用户写入?CLI 是具有特权的 setuid 二进制文件,还是开发者工具?缺少这些背景信息,它们就会报告你根本不会修复的漏洞,并错误评定严重性。
Anthropic 正是出于这个原因建议提供威胁模型文件;测试过其扫描器的维护者表示,最常见的问题是严重性被夸大,以及对威胁模型的理解有误。
应包含哪些内容
- 项目的功能,以及由谁运行。
- 不可信数据的入口:网络、文件、请求、插件。
- 可信内容:运维人员配置、本地用户、构建环境。
- 不在范围内的内容:测试、示例、仅限本地的问题、使用超大输入的 DoS。
- 如何评定严重性,以便你和扫描器对“严重”有相同的理解。
- 报告应采用什么形式:补丁风格、有用的概念验证、去重。
保持简短即可。一页足够。
文件放置位置
默认情况下,两个扫描器都会从仓库根目录读取 .oss-scanner/threat_model.md。对于 Anthropic 的扫描器,你也可以在 project.yaml 中设置其他路径,或将 threat_model.md 放在其仓库中的 project.yaml 旁边。在 ossscanner.org 上,你可以将其粘贴到已登记项目的设置中。更改将在下一次扫描时生效。