docs(iwooos): 補齊主流 AISOC 驗證紀錄 [skip ci]
Some checks failed
CD Pipeline / build-and-deploy (push) Has been cancelled
CD Pipeline / tests (push) Has been cancelled
CD Pipeline / post-deploy-checks (push) Has been cancelled
Code Review / ai-code-review (push) Has been cancelled
Ansible / Reboot Recovery Contract / validate (push) Has been cancelled

This commit is contained in:
Your Name
2026-06-18 12:24:26 +08:00
parent 68c528f4d9
commit 2b17ed5f44
2 changed files with 49 additions and 0 deletions

View File

@@ -1,3 +1,38 @@
## 2026-06-18IwoooS SOC / AISOC 主流框架補強與 production 驗證完成
**背景**:使用者要求以資安專業重新補齊 IwoooS 應做項目,參考主流 AISOC / SOC / SIEM / XDR / SOAR / CTI / NDR / AppSec / Supply-chain / AI security 解決方案,並確認正式站前台不要外洩工作視窗、內部對話、個人 namespace 或內網資訊。
**完成內容**
- `docs/security/MAINSTREAM-AISOC-SECURITY-CONTROL-ROADMAP.md` 已在既有 NIST CSF、CIS Controls、CISA Zero Trust、CISA KEV、MITRE ATT&CK / D3FEND、OWASP、SLSA、Sigstore、NIST AI RMF、OWASP LLM Top 10、MITRE ATLAS、CSA AI Controls Matrix、OCSF、Sigma、MISP / OpenCTI、Wazuh、Suricata、Zeek、TheHive / Cortex 與主流 AISOC 產品能力之外,補強 NIST SP 800-53、ISO/IEC 27001、NIST SP 800-61 Rev. 3、CISA Incident / Vulnerability Response Playbooks、FIRST CSIRT、FIRST EPSS、OpenSSF Scorecard、SPDX / CycloneDX、Falco。
- 新增補強待辦GRC / 例外管理、入侵處置生命週期、CSIRT / RACI / SLA、runtime threat detection gap、SBOM / VEX / provenance intake、EPSS / KEV / CVSS / exposure 合併排序。
- 優先序維持P0-A 資產 / 配置總清冊、P0-B Wazuh / Kali 112 / SIEM evidence envelope、P0-C Nginx / Gateway config-control、P0-D 端點入侵偵測與鑑識、P0-E 告警鏈 no-false-green、P0-F KEV / package / image / SBOM 關聯、P0-G Incident case gate、P0-H AI Agent 權限閘。
**正式部署與讀回**
- 程式提交:`a1bce808 feat(iwooos): 整合 SOC SIEM Kali Wazuh 控制`
- 後續前端提交鏈:`abe79546 feat(web): 顯示修復候選資產沉澱板`,包含 `a1bce808`
- Deploy marker`5013ebb7 chore(cd): deploy abe7954 [skip ci]`
- Gitea ActionsCD `4464` 成功,`tests` / `build-and-deploy` / `post-deploy-checks` 全部 successcode-review `4465` success前一輪 `a1bce808``4462` / `4463``abe79546` 後續推送而 cancelled但內容已由 `4464` 部署。
- Production API`https://awoooi.wooo.work/api/v1/health``healthy / prod / mock_mode=false`
- Production HTML`https://awoooi.wooo.work/zh-TW/iwooos?_v=abe79546-soc-aisoc-html-check-3` 已出現 `soc_siem_kali_wazuh_integration_control_visible=true``soc_siem_kali_wazuh_integration_control_candidate_count=20``security_evidence_tooling_coverage_percent=88` 與「SOC / SIEM / Kali 112 整合控制」marker。
**正式站瀏覽器 smoke**
- Desktop `1440x1200``/zh-TW/iwooos?_v=5013ebb7-soc-aisoc-prod-smoke-desktop`SOC / SIEM / Kali 112 整合控制卡片可見boundary 可見horizontal overflow `0`page error `0`,工作視窗 / delegation / thread id / 個人 namespace / 內網明確片語命中 `0`
- Mobile `390x844``/zh-TW/iwooos?_v=5013ebb7-soc-aisoc-prod-smoke-mobile`SOC / SIEM / Kali 112 整合控制卡片可見boundary 可見horizontal overflow `0`page error `0`,工作視窗 / delegation / thread id / 個人 namespace / 內網明確片語命中 `0`
- 截圖:`/tmp/iwooos-soc-aisoc-prod-desktop-5013ebb7.png``/tmp/iwooos-soc-aisoc-prod-mobile-5013ebb7.png`
- 備註Next.js route prefetch 有 `_rsc` request `ERR_ABORTED`屬頁面互動期間預取取消不影響目標路由可見性、overflow 或 page error 結果。
**完成度同步**
- SOC / SIEM / Kali 112 / Wazuh repo artifact / snapshot / guard`100%`
- IwoooS 前台脫敏可視化:正式站 `100%`
- 主流 AISOC / GRC / IR / CSIRT / SBOM / runtime detection 路線圖:`100%` 文件化。
- 高價值配置控管只讀成熟度:`73%`
- monitoring / alerting / observability 只讀成熟度:`78%`
- security evidence tooling 只讀成熟度:`88%`
- IwoooS headline仍維持 `64%`,不得因 UI 可見、部署成功或 smoke pass 假性拉高。
- Wazuh active response、Kali active scan、Kali `/execute`、host write、firewall change、Nginx reload、Prometheus reload、Alertmanager reload、Telegram send、SOAR case、auto block、package upgrade、runtime execution、action button全部仍為 `0 / false`
**邊界**:本輪只補 repo 文件、snapshot / guard、前台只讀可視化與 production smoke未 SSH、未改 Nginx、未改 firewall、未 reload、未 kubectl / ArgoCD sync、未 Wazuh active response、未 Kali active scan、未 Kali `/execute`、未更新套件、未讀或保存 secret、未建立 SOAR case、未送 Telegram、未做 production runtime 寫入。
## 2026-06-18重啟 live cold-start readback服務可用但保留 stale failed Job warning
**背景**:重啟 SOP / Plan B / repo-side readiness blockers 已推上 `gitea/main=63d8361f` 後,為避免把 repo-side readiness 誤講成 live full green本輪立即用只讀方式重跑 cold-start gate 並追蹤剛好同時發生的 AWOOOI rollout 自然收斂。

View File

@@ -16,14 +16,21 @@
| 類別 | 主流來源 | IwoooS 採用方式 |
|------|----------|-----------------|
| 企業資安治理 | [NIST CSF 2.0](https://www.nist.gov/cyberframework) | 以 Govern / Identify / Protect / Detect / Respond / Recover 建立總控管框架 |
| 控制庫 / GRC | [NIST SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) | 把 access control、audit、configuration、incident response、contingency、supply-chain controls 轉成 IwoooS evidence backlog |
| ISMS 管理系統 | [ISO/IEC 27001](https://www.iso.org/standard/27001) | 建立 risk register、control owner、exception register、內部稽核與持續改善節奏目前只做對照不宣稱認證 |
| 基礎控制優先序 | [CIS Controls v8.1](https://www.cisecurity.org/controls/v8-1) | 轉成資產、帳號、弱點、告警、備份、稽核與應變的 P0/P1 清單 |
| 零信任 | [CISA Zero Trust Maturity Model 2.0](https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model) | 補 identity、device、network、application、data、visibility / automation 五大成熟度 |
| 已遭利用弱點 | [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) | 弱點優先序不可只看 CVSS必須關聯 KEV、公開入口與 exploit exposure |
| 弱點風險排序 | [FIRST EPSS](https://www.first.org/epss/) | 將 CVSS、KEV、EPSS、公開入口、可利用性與資產重要性合併形成修補 SLA |
| 攻擊技術 | [MITRE ATT&CK Enterprise](https://attack.mitre.org/matrices/) | 偵測規則、告警分類、hunt playbook 與 coverage gap 用 ATT&CK 映射 |
| 防禦技術 | [MITRE D3FEND](https://d3fend.mitre.org/) | 每個 ATT&CK technique 必須映射防禦 countermeasure 與 evidence |
| 事件應變 | [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)、[CISA Incident / Vulnerability Response Playbooks](https://www.cisa.gov/resources-tools/resources/federal-government-cybersecurity-incident-and-vulnerability-response-playbooks) | incident case、triage、containment、eradication、recovery、post-incident、vulnerability response 統一成 case gate |
| CSIRT 能力 | [FIRST CSIRT Services Framework](https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1) | 定義 IwoooS / AwoooP / owner / reviewer / responder 的服務目錄、交接與升級分工 |
| AppSec | [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) | 前後台、API、auth、session、input / output、logging 與 access-control 驗收 |
| SSDLC 成熟度 | [OWASP SAMM](https://owasp.org/www-project-samm/) | 把治理、設計、實作、驗證、營運納入軟體安全成熟度 |
| 供應鏈 | [OpenSSF SLSA](https://slsa.dev/) | 建立 provenance、hosted build、artifact integrity 與防竄改基準 |
| OSS 風險評分 | [OpenSSF Scorecard](https://openssf.org/projects/scorecard/) | 針對第三方 repo / package 做 branch protection、dependency update、token permissions、signed release 等風險分級 |
| SBOM 標準 | [SPDX](https://spdx.dev/) / [CycloneDX](https://cyclonedx.org/) | Harbor、image、npm、Python、K8s manifest、AI model / dataset metadata 都要能產出或接收 BOM evidence |
| Artifact 簽章 | [Sigstore / Cosign](https://docs.sigstore.dev/cosign/signing/signing_with_containers/) | Harbor / container image / SBOM 先做簽章與驗章路線圖,不立即改 pipeline |
| GitHub / repo security | [GitHub Secret Scanning](https://docs.github.com/code-security/secret-scanning/about-secret-scanning) | 對齊 secret scanning、push protection、code scanning、dependency review 缺口 |
| 元件驗證 | [OWASP SCVS](https://owasp.org/www-project-software-component-verification-standard/) | 補 SBOM、dependency、license、來源可信度與修補優先序 |
@@ -37,6 +44,7 @@
| Open SIEM / XDR | [Wazuh](https://wazuh.com/) | 端點、FIM、vulnerability、config assessment、compliance 與 SIEM 的第一層 |
| NDR / IDS | [Suricata](https://suricata.io/) / [Zeek](https://zeek.org/) | Kali 112 或獨立 sensor 先做被動 network evidence不先開 IPS |
| Case / SOAR | [TheHive / Cortex](https://strangebee.com/thehive/) | Incident case、observable enrichment、人工審查與 playbook 草案 |
| 雲原生 runtime 偵測 | [Falco](https://falco.org/) | Docker / K8s syscall、container escape、privilege escalation、suspicious shell、secret access 先列成 P1 passive detection gap |
| 雲端 SIEM / AISOC | Microsoft Sentinel + Security Copilot、Google SecOps / Agentic SOC、Palo Alto Cortex XSIAM、CrowdStrike Falcon Next-Gen SIEM / Charlotte AI、Splunk ES / SOAR、Elastic AI SOC Engine、IBM QRadar SOAR、SentinelOne Purple AI | 只借鑑能力模型AI-ready data、triage、investigation、case、SOAR、UEBA、TI、AI assistant 與 human-in-the-loop |
| K8s / 容器硬化 | [NSA / CISA Kubernetes Hardening Guidance](https://www.cisa.gov/news-events/alerts/2022/03/15/updated-kubernetes-hardening-guide)、[CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes)、[CIS Docker Benchmark](https://www.cisecurity.org/benchmark/docker) | K8s / Docker / registry / runtime policy 先做只讀差距盤點,再開維護窗口 |
| Nginx / Gateway | [NGINX Security Controls](https://docs.nginx.com/nginx/admin-guide/security-controls/) | Nginx 變更需版本化、diff、owner、rollback、route smoke、TLS 與 upstream evidence |
@@ -57,10 +65,13 @@
| P0 | 已知遭利用弱點 | CISA KEV、公開入口、服務版本、container image、package、Nginx / K8s / Docker / Git / runner / Wazuh / Harbor 關聯 | KEV 命中需高於一般 CVSS 優先處理 |
| P0 | 備份 / 還原 / 鑑識 | backup freshness、offsite、restore drill、forensic preservation、chain of custody、evidence retention | 沒有 restore drill 不能宣告 DR 完成 |
| P0 | AI Agent 安全 | AI agent 權限、tool allowlist、prompt redaction、output validation、cost gate、human review、excessive agency 防護 | AI 不可直接 host write / secret read / auto block / production deploy |
| P0 | GRC / 例外管理 | risk register、control owner、exception register、accepted risk、expiry、review cadence、audit evidence | 沒有有效期限與 owner 的例外不可長期存在 |
| P0 | 入侵處置生命週期 | preparation、detection / analysis、containment、eradication、recovery、post-incident 全部形成 case fields | 不可只用「服務恢復」宣告入侵處置完成 |
| P1 | NDR / 網路觀測 | Suricata / Zeek passive sensor、DNS / TLS / HTTP / flow logs、east-west visibility、egress anomaly | 先 passive不開 IPS / auto block |
| P1 | SOAR / Playbook | TheHive / Cortex 類 case 與 enrichment model先做 playbook 草案、dry-run、approval gate | SOAR action 預設 `0 / false`,只允許人工批准後執行 |
| P1 | Threat Intelligence | MISP / OpenCTI 類 IOC / TTP / campaign / actor / malware / CVE 關聯 | IOC 不可直接封鎖,需 evidence / owner / blast radius |
| P1 | K8s / Docker 硬化 | CIS / NSA-CISA 對照RBAC、NetworkPolicy、Pod Security、image scan、least privilege、audit log、secret mount | 先盤點,不直接 kubectl / helm / ArgoCD sync |
| P1 | Runtime threat detection | Falco 類 syscall / container / K8s event detection、rule owner、false-positive budget、SIEM forwarding | 先寫 detection gap不開自動 kill / quarantine |
| P1 | 供應鏈與 artifact | SLSA、SBOM、Cosign、provenance、dependency review、CodeQL / SAST、secret scanning、license | 先產生缺口矩陣,不立即改 workflow 或切 GitHub primary |
| P1 | AppSec / API | ASVS / SAMMauth、authorization、session、input validation、rate limit、CORS、CSRF、security headers、audit log | 高風險 API 需 contract、test、owner 與 abuse case |
| P1 | AISOC AI 助理 | 借鑑 Sentinel / Google SecOps / XSIAM / Charlotte AI / Splunk / Elastic / QRadar / Purple AI摘要、查詢、triage、case draft | AI 只能建議與摘要,不可直接處置 |
@@ -100,6 +111,9 @@
11. **P1-C Supply-chain hardening**SLSA / SBOM / Cosign / secret scanning / CodeQL / dependency review / artifact provenance。
12. **P1-D K8s / Docker benchmark**CIS / NSA-CISA 差距盤點與維護窗口草案。
13. **P1-E AISOC triage assistant**AI 先做 read-only triage / summary / case draft不可執行 response。
14. **P1-F CSIRT / GRC operating model**定義事件服務目錄、RACI、例外期限、accepted risk、audit evidence、升級 SLA。
15. **P1-G Runtime threat detection gap**Falco / Wazuh / Docker event / K8s audit event 的資料源與 rule backlog。
16. **P1-H SBOM / VEX / provenance intake**SPDX / CycloneDX、VEX、Cosign verify、OpenSSF Scorecard 與 package freshness 先進 inventory。
## 5. 驗收與停止線