From eb4668408ceac440972213053ab0d97f6fa7ae89 Mon Sep 17 00:00:00 2001 From: stefan Date: Mon, 23 Feb 2026 18:53:35 +0100 Subject: SLSA models added Signed-off-by: stefan --- PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg') diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg index 6f3cbac..16b0263 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg @@ -1 +1 @@ -Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)Attack Flows and Trust BoundariesTimestamp: 2026-02-22 15:47 +0100Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)InternetDMZInternal NetworkBlack HatPublic Web Server:T, I, DoS, EoPCVS RelEngT, R, EoPRelease RepoHVTS, T, R, I, DoS, EoPSecurity Officer(DF1) Publish ISO + Checksums(DF2) Sign Checksums (GnuPG)(DF3) Deploy Artifacts(AT2) Pivot to RepoEoP(DF4) Distribute ISO + Checksums + Signature(AT1) Exploit Webserver VulnEoP(AT3) Replace ISO&& Checksum&& SignatureTamperSTRIDEAbbreviationSSpoofingTTamperingRRepudiationIInformation DisclosureDoSDenial of ServiceEoPElevation of Privilege Relationship ColourColourAttack PhaseRedInitial ExploitDeep PurpleLateral MovementOrangeIntegrity ViolationGreenLegitimate Signing LightGray box: Trust BoundaryNotes on Relation: STRIDE categoryDF: Data FlowAT: Attack Path \ No newline at end of file +Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)Attack Flows and Trust BoundariesTimestamp: 2026-02-23 18:52 +0100Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)InternetDMZInternal NetworkBlack HatPublic Web Server:T, I, DoS, EoPCVS RelEngT, R, EoPRelease RepoHVTS, T, R, I, DoS, EoPSecurity Officer(DF1) Publish ISO + Checksums(DF2) Sign Checksums (GnuPG)(DF3) Deploy Artifacts(AT2) Pivot to RepoEoP(DF4) Distribute ISO + Checksums + Signature(AT1) Exploit Webserver VulnEoP(AT3) Replace ISO&& Checksum&& SignatureTamperSTRIDEAbbreviationSSpoofingTTamperingRRepudiationIInformation DisclosureDoSDenial of ServiceEoPElevation of Privilege Relationship ColourColourAttack PhaseRedInitial ExploitDeep PurpleLateral MovementOrangeIntegrity ViolationGreenLegitimate Signing LightGray box: Trust BoundaryNotes on Relation: STRIDE categoryDF: Data FlowAT: Attack Path \ No newline at end of file -- cgit v1.2.3