docs(iwooos): 補齊主流 AISOC 驗證紀錄 [skip ci]
Some checks failed
CD Pipeline / build-and-deploy (push) Has been cancelled
CD Pipeline / tests (push) Has been cancelled
CD Pipeline / post-deploy-checks (push) Has been cancelled
Code Review / ai-code-review (push) Has been cancelled
Ansible / Reboot Recovery Contract / validate (push) Has been cancelled
Some checks failed
CD Pipeline / build-and-deploy (push) Has been cancelled
CD Pipeline / tests (push) Has been cancelled
CD Pipeline / post-deploy-checks (push) Has been cancelled
Code Review / ai-code-review (push) Has been cancelled
Ansible / Reboot Recovery Contract / validate (push) Has been cancelled
This commit is contained in:
@@ -1,3 +1,38 @@
|
||||
## 2026-06-18|IwoooS SOC / AISOC 主流框架補強與 production 驗證完成
|
||||
|
||||
**背景**:使用者要求以資安專業重新補齊 IwoooS 應做項目,參考主流 AISOC / SOC / SIEM / XDR / SOAR / CTI / NDR / AppSec / Supply-chain / AI security 解決方案,並確認正式站前台不要外洩工作視窗、內部對話、個人 namespace 或內網資訊。
|
||||
|
||||
**完成內容**:
|
||||
- `docs/security/MAINSTREAM-AISOC-SECURITY-CONTROL-ROADMAP.md` 已在既有 NIST CSF、CIS Controls、CISA Zero Trust、CISA KEV、MITRE ATT&CK / D3FEND、OWASP、SLSA、Sigstore、NIST AI RMF、OWASP LLM Top 10、MITRE ATLAS、CSA AI Controls Matrix、OCSF、Sigma、MISP / OpenCTI、Wazuh、Suricata、Zeek、TheHive / Cortex 與主流 AISOC 產品能力之外,補強 NIST SP 800-53、ISO/IEC 27001、NIST SP 800-61 Rev. 3、CISA Incident / Vulnerability Response Playbooks、FIRST CSIRT、FIRST EPSS、OpenSSF Scorecard、SPDX / CycloneDX、Falco。
|
||||
- 新增補強待辦:GRC / 例外管理、入侵處置生命週期、CSIRT / RACI / SLA、runtime threat detection gap、SBOM / VEX / provenance intake、EPSS / KEV / CVSS / exposure 合併排序。
|
||||
- 優先序維持:P0-A 資產 / 配置總清冊、P0-B Wazuh / Kali 112 / SIEM evidence envelope、P0-C Nginx / Gateway config-control、P0-D 端點入侵偵測與鑑識、P0-E 告警鏈 no-false-green、P0-F KEV / package / image / SBOM 關聯、P0-G Incident case gate、P0-H AI Agent 權限閘。
|
||||
|
||||
**正式部署與讀回**:
|
||||
- 程式提交:`a1bce808 feat(iwooos): 整合 SOC SIEM Kali Wazuh 控制`。
|
||||
- 後續前端提交鏈:`abe79546 feat(web): 顯示修復候選資產沉澱板`,包含 `a1bce808`。
|
||||
- Deploy marker:`5013ebb7 chore(cd): deploy abe7954 [skip ci]`。
|
||||
- Gitea Actions:CD `4464` 成功,`tests` / `build-and-deploy` / `post-deploy-checks` 全部 success;code-review `4465` success;前一輪 `a1bce808` 的 `4462` / `4463` 因 `abe79546` 後續推送而 cancelled,但內容已由 `4464` 部署。
|
||||
- Production API:`https://awoooi.wooo.work/api/v1/health` 回 `healthy / prod / mock_mode=false`。
|
||||
- Production HTML:`https://awoooi.wooo.work/zh-TW/iwooos?_v=abe79546-soc-aisoc-html-check-3` 已出現 `soc_siem_kali_wazuh_integration_control_visible=true`、`soc_siem_kali_wazuh_integration_control_candidate_count=20`、`security_evidence_tooling_coverage_percent=88` 與「SOC / SIEM / Kali 112 整合控制」marker。
|
||||
|
||||
**正式站瀏覽器 smoke**:
|
||||
- Desktop `1440x1200`:`/zh-TW/iwooos?_v=5013ebb7-soc-aisoc-prod-smoke-desktop`,SOC / SIEM / Kali 112 整合控制卡片可見,boundary 可見,horizontal overflow `0`,page error `0`,工作視窗 / delegation / thread id / 個人 namespace / 內網明確片語命中 `0`。
|
||||
- Mobile `390x844`:`/zh-TW/iwooos?_v=5013ebb7-soc-aisoc-prod-smoke-mobile`,SOC / SIEM / Kali 112 整合控制卡片可見,boundary 可見,horizontal overflow `0`,page error `0`,工作視窗 / delegation / thread id / 個人 namespace / 內網明確片語命中 `0`。
|
||||
- 截圖:`/tmp/iwooos-soc-aisoc-prod-desktop-5013ebb7.png`、`/tmp/iwooos-soc-aisoc-prod-mobile-5013ebb7.png`。
|
||||
- 備註:Next.js route prefetch 有 `_rsc` request `ERR_ABORTED`,屬頁面互動期間預取取消,不影響目標路由可見性、overflow 或 page error 結果。
|
||||
|
||||
**完成度同步**:
|
||||
- SOC / SIEM / Kali 112 / Wazuh repo artifact / snapshot / guard:`100%`。
|
||||
- IwoooS 前台脫敏可視化:正式站 `100%`。
|
||||
- 主流 AISOC / GRC / IR / CSIRT / SBOM / runtime detection 路線圖:`100%` 文件化。
|
||||
- 高價值配置控管只讀成熟度:`73%`。
|
||||
- monitoring / alerting / observability 只讀成熟度:`78%`。
|
||||
- security evidence tooling 只讀成熟度:`88%`。
|
||||
- IwoooS headline:仍維持 `64%`,不得因 UI 可見、部署成功或 smoke pass 假性拉高。
|
||||
- Wazuh active response、Kali active scan、Kali `/execute`、host write、firewall change、Nginx reload、Prometheus reload、Alertmanager reload、Telegram send、SOAR case、auto block、package upgrade、runtime execution、action button:全部仍為 `0 / false`。
|
||||
|
||||
**邊界**:本輪只補 repo 文件、snapshot / guard、前台只讀可視化與 production smoke;未 SSH、未改 Nginx、未改 firewall、未 reload、未 kubectl / ArgoCD sync、未 Wazuh active response、未 Kali active scan、未 Kali `/execute`、未更新套件、未讀或保存 secret、未建立 SOAR case、未送 Telegram、未做 production runtime 寫入。
|
||||
|
||||
## 2026-06-18|重啟 live cold-start readback:服務可用但保留 stale failed Job warning
|
||||
|
||||
**背景**:重啟 SOP / Plan B / repo-side readiness blockers 已推上 `gitea/main=63d8361f` 後,為避免把 repo-side readiness 誤講成 live full green,本輪立即用只讀方式重跑 cold-start gate 並追蹤剛好同時發生的 AWOOOI rollout 自然收斂。
|
||||
|
||||
@@ -16,14 +16,21 @@
|
||||
| 類別 | 主流來源 | IwoooS 採用方式 |
|
||||
|------|----------|-----------------|
|
||||
| 企業資安治理 | [NIST CSF 2.0](https://www.nist.gov/cyberframework) | 以 Govern / Identify / Protect / Detect / Respond / Recover 建立總控管框架 |
|
||||
| 控制庫 / GRC | [NIST SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) | 把 access control、audit、configuration、incident response、contingency、supply-chain controls 轉成 IwoooS evidence backlog |
|
||||
| ISMS 管理系統 | [ISO/IEC 27001](https://www.iso.org/standard/27001) | 建立 risk register、control owner、exception register、內部稽核與持續改善節奏;目前只做對照,不宣稱認證 |
|
||||
| 基礎控制優先序 | [CIS Controls v8.1](https://www.cisecurity.org/controls/v8-1) | 轉成資產、帳號、弱點、告警、備份、稽核與應變的 P0/P1 清單 |
|
||||
| 零信任 | [CISA Zero Trust Maturity Model 2.0](https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model) | 補 identity、device、network、application、data、visibility / automation 五大成熟度 |
|
||||
| 已遭利用弱點 | [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) | 弱點優先序不可只看 CVSS,必須關聯 KEV、公開入口與 exploit exposure |
|
||||
| 弱點風險排序 | [FIRST EPSS](https://www.first.org/epss/) | 將 CVSS、KEV、EPSS、公開入口、可利用性與資產重要性合併,形成修補 SLA |
|
||||
| 攻擊技術 | [MITRE ATT&CK Enterprise](https://attack.mitre.org/matrices/) | 偵測規則、告警分類、hunt playbook 與 coverage gap 用 ATT&CK 映射 |
|
||||
| 防禦技術 | [MITRE D3FEND](https://d3fend.mitre.org/) | 每個 ATT&CK technique 必須映射防禦 countermeasure 與 evidence |
|
||||
| 事件應變 | [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)、[CISA Incident / Vulnerability Response Playbooks](https://www.cisa.gov/resources-tools/resources/federal-government-cybersecurity-incident-and-vulnerability-response-playbooks) | incident case、triage、containment、eradication、recovery、post-incident、vulnerability response 統一成 case gate |
|
||||
| CSIRT 能力 | [FIRST CSIRT Services Framework](https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1) | 定義 IwoooS / AwoooP / owner / reviewer / responder 的服務目錄、交接與升級分工 |
|
||||
| AppSec | [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/) | 前後台、API、auth、session、input / output、logging 與 access-control 驗收 |
|
||||
| SSDLC 成熟度 | [OWASP SAMM](https://owasp.org/www-project-samm/) | 把治理、設計、實作、驗證、營運納入軟體安全成熟度 |
|
||||
| 供應鏈 | [OpenSSF SLSA](https://slsa.dev/) | 建立 provenance、hosted build、artifact integrity 與防竄改基準 |
|
||||
| OSS 風險評分 | [OpenSSF Scorecard](https://openssf.org/projects/scorecard/) | 針對第三方 repo / package 做 branch protection、dependency update、token permissions、signed release 等風險分級 |
|
||||
| SBOM 標準 | [SPDX](https://spdx.dev/) / [CycloneDX](https://cyclonedx.org/) | Harbor、image、npm、Python、K8s manifest、AI model / dataset metadata 都要能產出或接收 BOM evidence |
|
||||
| Artifact 簽章 | [Sigstore / Cosign](https://docs.sigstore.dev/cosign/signing/signing_with_containers/) | Harbor / container image / SBOM 先做簽章與驗章路線圖,不立即改 pipeline |
|
||||
| GitHub / repo security | [GitHub Secret Scanning](https://docs.github.com/code-security/secret-scanning/about-secret-scanning) | 對齊 secret scanning、push protection、code scanning、dependency review 缺口 |
|
||||
| 元件驗證 | [OWASP SCVS](https://owasp.org/www-project-software-component-verification-standard/) | 補 SBOM、dependency、license、來源可信度與修補優先序 |
|
||||
@@ -37,6 +44,7 @@
|
||||
| Open SIEM / XDR | [Wazuh](https://wazuh.com/) | 端點、FIM、vulnerability、config assessment、compliance 與 SIEM 的第一層 |
|
||||
| NDR / IDS | [Suricata](https://suricata.io/) / [Zeek](https://zeek.org/) | Kali 112 或獨立 sensor 先做被動 network evidence,不先開 IPS |
|
||||
| Case / SOAR | [TheHive / Cortex](https://strangebee.com/thehive/) | Incident case、observable enrichment、人工審查與 playbook 草案 |
|
||||
| 雲原生 runtime 偵測 | [Falco](https://falco.org/) | Docker / K8s syscall、container escape、privilege escalation、suspicious shell、secret access 先列成 P1 passive detection gap |
|
||||
| 雲端 SIEM / AISOC | Microsoft Sentinel + Security Copilot、Google SecOps / Agentic SOC、Palo Alto Cortex XSIAM、CrowdStrike Falcon Next-Gen SIEM / Charlotte AI、Splunk ES / SOAR、Elastic AI SOC Engine、IBM QRadar SOAR、SentinelOne Purple AI | 只借鑑能力模型:AI-ready data、triage、investigation、case、SOAR、UEBA、TI、AI assistant 與 human-in-the-loop |
|
||||
| K8s / 容器硬化 | [NSA / CISA Kubernetes Hardening Guidance](https://www.cisa.gov/news-events/alerts/2022/03/15/updated-kubernetes-hardening-guide)、[CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes)、[CIS Docker Benchmark](https://www.cisecurity.org/benchmark/docker) | K8s / Docker / registry / runtime policy 先做只讀差距盤點,再開維護窗口 |
|
||||
| Nginx / Gateway | [NGINX Security Controls](https://docs.nginx.com/nginx/admin-guide/security-controls/) | Nginx 變更需版本化、diff、owner、rollback、route smoke、TLS 與 upstream evidence |
|
||||
@@ -57,10 +65,13 @@
|
||||
| P0 | 已知遭利用弱點 | CISA KEV、公開入口、服務版本、container image、package、Nginx / K8s / Docker / Git / runner / Wazuh / Harbor 關聯 | KEV 命中需高於一般 CVSS 優先處理 |
|
||||
| P0 | 備份 / 還原 / 鑑識 | backup freshness、offsite、restore drill、forensic preservation、chain of custody、evidence retention | 沒有 restore drill 不能宣告 DR 完成 |
|
||||
| P0 | AI Agent 安全 | AI agent 權限、tool allowlist、prompt redaction、output validation、cost gate、human review、excessive agency 防護 | AI 不可直接 host write / secret read / auto block / production deploy |
|
||||
| P0 | GRC / 例外管理 | risk register、control owner、exception register、accepted risk、expiry、review cadence、audit evidence | 沒有有效期限與 owner 的例外不可長期存在 |
|
||||
| P0 | 入侵處置生命週期 | preparation、detection / analysis、containment、eradication、recovery、post-incident 全部形成 case fields | 不可只用「服務恢復」宣告入侵處置完成 |
|
||||
| P1 | NDR / 網路觀測 | Suricata / Zeek passive sensor、DNS / TLS / HTTP / flow logs、east-west visibility、egress anomaly | 先 passive,不開 IPS / auto block |
|
||||
| P1 | SOAR / Playbook | TheHive / Cortex 類 case 與 enrichment model,先做 playbook 草案、dry-run、approval gate | SOAR action 預設 `0 / false`,只允許人工批准後執行 |
|
||||
| P1 | Threat Intelligence | MISP / OpenCTI 類 IOC / TTP / campaign / actor / malware / CVE 關聯 | IOC 不可直接封鎖,需 evidence / owner / blast radius |
|
||||
| P1 | K8s / Docker 硬化 | CIS / NSA-CISA 對照:RBAC、NetworkPolicy、Pod Security、image scan、least privilege、audit log、secret mount | 先盤點,不直接 kubectl / helm / ArgoCD sync |
|
||||
| P1 | Runtime threat detection | Falco 類 syscall / container / K8s event detection、rule owner、false-positive budget、SIEM forwarding | 先寫 detection gap,不開自動 kill / quarantine |
|
||||
| P1 | 供應鏈與 artifact | SLSA、SBOM、Cosign、provenance、dependency review、CodeQL / SAST、secret scanning、license | 先產生缺口矩陣,不立即改 workflow 或切 GitHub primary |
|
||||
| P1 | AppSec / API | ASVS / SAMM:auth、authorization、session、input validation、rate limit、CORS、CSRF、security headers、audit log | 高風險 API 需 contract、test、owner 與 abuse case |
|
||||
| P1 | AISOC AI 助理 | 借鑑 Sentinel / Google SecOps / XSIAM / Charlotte AI / Splunk / Elastic / QRadar / Purple AI:摘要、查詢、triage、case draft | AI 只能建議與摘要,不可直接處置 |
|
||||
@@ -100,6 +111,9 @@
|
||||
11. **P1-C Supply-chain hardening**:SLSA / SBOM / Cosign / secret scanning / CodeQL / dependency review / artifact provenance。
|
||||
12. **P1-D K8s / Docker benchmark**:CIS / NSA-CISA 差距盤點與維護窗口草案。
|
||||
13. **P1-E AISOC triage assistant**:AI 先做 read-only triage / summary / case draft;不可執行 response。
|
||||
14. **P1-F CSIRT / GRC operating model**:定義事件服務目錄、RACI、例外期限、accepted risk、audit evidence、升級 SLA。
|
||||
15. **P1-G Runtime threat detection gap**:Falco / Wazuh / Docker event / K8s audit event 的資料源與 rule backlog。
|
||||
16. **P1-H SBOM / VEX / provenance intake**:SPDX / CycloneDX、VEX、Cosign verify、OpenSSF Scorecard 與 package freshness 先進 inventory。
|
||||
|
||||
## 5. 驗收與停止線
|
||||
|
||||
|
||||
Reference in New Issue
Block a user