From 2993aae60e019804e249de3f56e48eca365723df Mon Sep 17 00:00:00 2001 From: stefan Date: Tue, 24 Feb 2026 20:36:44 +0100 Subject: Risk/Security Overlay im Business/Motivation Layer angefangen --- .../100-GnuPG-Keysigning-DFD.png | Bin 57333 -> 57256 bytes .../100-GnuPG-Keysigning-SEQ-KSP-WoT.png | Bin 121553 -> 121488 bytes .../101-Multiple-GnuPG-signatures-Trust.png | Bin 27016 -> 26981 bytes .../200-ThreatModel-SLSA1-DownloadSig.png | Bin 38288 -> 38334 bytes .../201-ThreatModel-SLSA4-ReproducibleBuilds.png | Bin 63781 -> 63829 bytes ...tModel-SLSA4-ReproducibleBuilds-TrustAnchor.png | Bin 0 -> 127749 bytes ...Model-SLSA4-ReproducibleBuilds-TrustAnchor.puml | 135 +++++++++++++++++++++ ...tModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg | 1 + .../203-SLSA4-ReproducibleBuilds-L1-Motivation.png | Bin 0 -> 55015 bytes ...203-SLSA4-ReproducibleBuilds-L1-Motivation.puml | 87 +++++++++++++ .../203-SLSA4-ReproducibleBuilds-L1-Motivation.svg | 1 + .../300-NetBSD-RelEng-STRIDE.png | Bin 78625 -> 78574 bytes .../GnuPG-WoT-Download/README.adoc | 14 +++ .../GnuPG-WoT-Download/pumlit.sh | 4 +- 14 files changed, 240 insertions(+), 2 deletions(-) create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.puml create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.svg diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png index fb17d9f..7270246 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png index 66befaa..6ef113d 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/101-Multiple-GnuPG-signatures-Trust.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/101-Multiple-GnuPG-signatures-Trust.png index c5a7dac..ca49d75 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/101-Multiple-GnuPG-signatures-Trust.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/101-Multiple-GnuPG-signatures-Trust.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png index daac44f..87b48d4 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/200-ThreatModel-SLSA1-DownloadSig.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png index fb7b8c4..8efef97 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/201-ThreatModel-SLSA4-ReproducibleBuilds.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png new file mode 100644 index 0000000..c550c51 Binary files /dev/null and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml new file mode 100644 index 0000000..f183b2a --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.puml @@ -0,0 +1,135 @@ +@startuml +!include + +left to right direction +skinparam rectangle { + BackgroundColor #FFF6F6 + BorderColor #550000 +} +skinparam note { + BackgroundColor #FFFFCC +} + +' makes Rel_ green +skinparam ArrowFontColor<> green + + +' Anchor as SVG sprite +sprite $anchor + + + + + + +right header += Threat Model - Reproducible Builds according to SLSA Level 4 +using independent GnuPG signatures and keys +as well as Reproducible Builds according to SLSA Level 4 +corresponding to the Tor Browser release process, as well as NixOS, Debian and NetBSD += %date("yyyy-MM-dd hh:mm") +endheader + +right footer += Advantages: +* Consistency between source code and binaries through Reproducible Builds +* No single trust anchor -> at least 2 independent builders +* Subsequent manipulation detectable through checksums in the Git Transparency Log +* Insider attacks made more difficult through multiple signatures +* Key misuse detectable through checksums in the Git Transparency Log and temporal correlation via timestamps +* Each box is a trust boarder +endfooter + + + +caption += Threat Model - Reproducible Builds according to SLSA Level 4 +endcaption + +actor "Downloader\n(Verifier)" as User #Green +actor "Internet\n(Insecure)" as Net +actor "NTP Server 1" as NTP1 +actor "NTP Server 2 " as NTP2 +actor "Attacker\n(Insider / External)" as Attacker #Red +'actor "Trusted Commiter 1" as Committer1 +'actor "Trusted Commiter 2" as Committer2 + +actor "Keyserver 1" as Keyserver1 +actor "Keyserver 2" as Keyserver2 + + +rectangle "Maintainer" { + rectangle "Source Code\n(in Git) <$anchor{scale=0.1,color=green}>" as Source + rectangle "Git Release Tag\n(GnuPG-signed) <$anchor{scale=0.1,color=green}>" as Tag +} + +rectangle "Independent build pipelines\n(at least 2)" { + rectangle "Pipe A <$anchor{scale=0.1,color=lightgreen}>b1" as B1 + rectangle "Pipe B <$anchor{scale=0.1,color=lightgreen}>b2" as B2 +} + +Motivation_Goal(TAb, "combined Trust") +' Rel_Aggregation(TAb, B1, "combines", $lineColor="green", $textColor="green") +TAb o-- B1 : combines TA +TAb o-- B2 : combines TA + + + + + + +rectangle "Download artefacts" { + rectangle "Artefact A\n(Checksum)" as A1 + rectangle "Artefact B\n(Checksum)" as A2 +} + +rectangle "Git Transparency Log\n(tamper-hardened) <$anchor{scale=0.1,color=green}>" as Log +rectangle "Distributed ledger with\n Merkle Tree records\n (Blockchain) <$anchor{scale=0.1,color=green}>" as Ledger + +rectangle "Operational environment\n(of the downloader)" { + rectangle "Known public signing keys\n(obtained from at least\n 2 independent trust paths)" as Keys + rectangle "Rebuild pipeline\n(Reproducible)" as Rebuild + rectangle "Verification policy\n (organisational measure\n from BSI TR)" as Policy +} + +NTP1 --> Log : Time +NTP2 --> Log : Time + +Keyserver1 --> Keys : retrieves +Keyserver2 --> Keys : retrieves + +Source --> B1 +Source --> B2 + +B1 --> A1 +B2 --> A2 + +A1 --> Log : Checksum +A2 --> Log : Checksum + +A1 --> Ledger : Checksum +A2 --> Ledger : Checksum + +Tag --> Source + +Net --> User +Attacker -[#Red]-> B1 : compromises +Attacker -[#Red]-> Net : controls +Attacker -[#Red]-> Tag : compromises private key +'// Commiter1 --> Tag : generates valid signature +'// Commiter2 --> Tag : generates valid signature + + +User --> Rebuild +User --> Log +Keys --> Policy +Rebuild --> Policy +Policy --> User : ACCEPT / REJECT +@enduml diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg new file mode 100644 index 0000000..a1071dc --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.svg @@ -0,0 +1 @@ +Threat Model - Reproducible Builds according to SLSA Level 4using independent GnuPG signatures and keysas well as Reproducible Builds according to SLSA Level 4corresponding to the Tor Browser release process, as well as NixOS, Debian and NetBSD2026-02-24 12:20MaintainerIndependent build pipelines(at least 2)Download artefactsOperational environment(of the downloader)Source Code(in Git)   Git Release Tag(GnuPG-signed)   Pipe A  b1Pipe B  b2Artefact A(Checksum)Artefact B(Checksum)Known public signing keys(obtained from at least 2 independent trust paths)Rebuild pipeline(Reproducible)Verification policy (organisational measure from BSI TR)Downloader(Verifier)Internet(Insecure)NTP Server 1NTP Server 2Attacker(Insider / External)Keyserver 1Keyserver 2combined TrustGit Transparency Log(tamper-hardened)  Distributed ledger with Merkle Tree records (Blockchain)  combines TAcombines TATimeTimeretrievesretrievesChecksumChecksumChecksumChecksumcompromisescontrolscompromises private keyACCEPT / REJECTThreat Model - Reproducible Builds according to SLSA Level 4Advantages:Consistency between source code and binaries through Reproducible BuildsNo single trust anchor -> at least 2 independent buildersSubsequent manipulation detectable through checksums in the Git Transparency LogInsider attacks made more difficult through multiple signaturesKey misuse detectable through checksums in the Git Transparency Log and temporal correlation via timestampsEach box is a trust boarder \ No newline at end of file diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png new file mode 100644 index 0000000..4197e78 Binary files /dev/null and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.puml b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.puml new file mode 100644 index 0000000..edb377d --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.puml @@ -0,0 +1,87 @@ +@startuml +!include +left to right direction +skinparam linetype polyline + + +Title SLSA4 - Risk and Security Overlay + +' grouping +Grouping(riskex, "Risk Experience"){ + +Motivation_Assessment(hazard_ass, "Hazard Assessment") + +' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' STRATEGY +' together{ +Strategy_Resource(threat_enabler, "Threat Enabler\nGnuPG Signature Secret Key") +Strategy_Resource(asset, "Asset at Risk\nISO-Image gets manipulated") +Strategy_Capability(vuln, "Vulnerability Capability\n") +' } + +' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' business +' together{ +Business_Actor(threat_agent, "Threat Agent\nBlackHat manipulates ISO-Image") +Business_Event(threat_event, "Business Threat Event\nManipulated ISO-Image gets installed") +Business_Event(loss_event, "Business Loss Event\nNetBSD-Server has to be shutdown") +' } +Business_Service(control, "Implemented Control Measure\n") + +' grouping +} + +' ''''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' Motivation +together{ +Motivation_Goal(global_goal, "Gloabl Goal:Run NetBSD-Server that is free from manipulation") +Motivation_Assessment(risk_assessment, "Risk Assessment\nISO-Image might be manipulated") +Motivation_Goal(goal, "<>\nGoal") +Motivation_Driver(risk_driver, "Risk Driver\nInstall Non-Manipulated ISO-Image") +Motivation_Stakeholder(risk_assessor, "Risk Assessor\nInstall-Admin verifying Signature") +Motivation_Stakeholder(risk_subj, "Risk Subject\nService Owner running NetBSD") +Motivation_Requirement(sec_req, "sec. requirement\nIntegrity of ISO-Image") +Motivation_Requirement(control_req, "control requirement\nInstall Non-Manipulated ISO-Image") +Motivation_Principle(sec_princ, "Security_Principle\n") +} + + +' Beziehungen +Rel_Association(hazard_ass, threat_event) +Rel_Association(vuln, threat_event) +Rel_Association(vuln, threat_enabler) +Rel_Association(vuln, loss_event) +Rel_Association(vuln, asset) + +Rel_Association(control, threat_enabler) +Rel_Association(control, asset) + +Rel_Association(threat_event, threat_enabler) +Rel_Association(loss_event, asset) + + +Rel_Association(riskex, risk_driver) + + +Rel_Association(risk_subj,global_goal) +Rel_Association(risk_assessment,risk_driver) +Rel_Association(risk_assessment,risk_assessor) +Rel_Association(risk_assessment,goal) + ' Rel_Association(, ) + +Rel_Realization(sec_req,goal,Realise) +Rel_Realization(sec_princ,goal,Realise) +Rel_Realization(control_req,sec_princ,Realise) + +' Rel_Realization(control,sec_princ,Realise) + +Rel_Realization(control,control_req,Realise) + +Rel_Flow(loss_event,global_goal,Flow) + +Rel_Assignment(threat_agent,threat_event,Assign) + + + +@enduml + diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.svg new file mode 100644 index 0000000..690d46d --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/203-SLSA4-ReproducibleBuilds-L1-Motivation.svg @@ -0,0 +1 @@ +SLSA4 - Risk and Security OverlaySLSA4 - Risk and Security OverlayRisk ExperienceHazard AssessmentThreat EnablerGnuPG Signature Secret KeyAsset at RiskISO-Image gets manipulatedVulnerability Capability Threat AgentBlackHat manipulates ISO-ImageBusiness Threat EventManipulated ISO-Image gets installedBusiness Loss EventNetBSD-Server has to be shutdownImplemented Control Measure Gloabl Goal:Run NetBSD-Server that is free from manipulationRisk AssessmentISO-Image might be manipulated«ControlObjective»GoalRisk DriverInstall Non-Manipulated ISO-ImageRisk AssessorInstall-Admin verifying SignatureRisk SubjectService Owner running NetBSDsec. requirementIntegrity of ISO-Imagecontrol requirementInstall Non-Manipulated ISO-ImageSecurity_Principle               RealiseRealiseRealiseRealiseFlowAssign \ No newline at end of file diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png index 1bf7971..6eeff72 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc index fe1010a..e3e62b6 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc @@ -35,5 +35,19 @@ image::200-ThreatModel-SLSA1-DownloadSig.png[] +=== Reproducible Builds SLSA L4 + +Modeling Trust, Trust Anchors and Boundaries and Attack Vectors + +==== The whole implementation + +* Trust Boundaries: Rectangles +* Attack Vectors: Red Arrows + image::201-ThreatModel-SLSA4-ReproducibleBuilds.png[] +* Trust Anchor: Green Anchor + +image::202-ThreatModel-SLSA4-ReproducibleBuilds-TrustAnchor.png[] + + diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/pumlit.sh b/PlantUML-ModelingTrust/GnuPG-WoT-Download/pumlit.sh index b20b927..3214510 100755 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/pumlit.sh +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/pumlit.sh @@ -1,3 +1,3 @@ -plantuml -v --skip-fresh -svg *.puml -plantuml -v --skip-fresh -png *.puml +plantuml --skip-fresh -svg *.puml +plantuml --skip-fresh -png *.puml #asciidoctor index.adoc -- cgit v1.2.3