Defensive measures
272 pages, showing 101–200, ordered by identifier.
- D3-FCDC — File Content Decompression Checking Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further...
- D3-FCOA — File Content Analysis Employing a pattern matching algorithm to statically analyze the content of files.
- D3-FCR — File Content Rules Employing a pattern matching rule language to analyze the content of files.
- D3-FE — File Encryption Encrypting a file using a cryptographic key.
- D3-FEMC — Firmware Embedded Monitoring Code Monitoring code is injected into firmware for integrity monitoring of firmware and firmware data.
- D3-FEV — File Eviction File eviction techniques delete files from system storage.
- D3-FFV — File Format Verification Verifying that a file conforms to its expected format specifications
- D3-FH — File Hashing Employing file hash comparisons to detect known malware.
- D3-FHRA — File Hash Reputation Analysis Analyzing the reputation of a file hash.
- D3-FIM — File Integrity Monitoring Detecting any suspicious changes to files in a computer system.
- D3-FISV — File Internal Structure Verification The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure...
- D3-FMBV — File Magic Byte Verification Utilizing the magic number to verify the file
- D3-FMCV — File Metadata Consistency Validation The process of validating the consistency between a file's metadata and its actual content, ensuring that elements...
- D3-FMVV — File Metadata Value Verification The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure...
- D3-FRDDL — Forward Resolution Domain Denylisting Blocking a lookup based on the query's domain name value.
- D3-FRIDL — Forward Resolution IP Denylisting Blocking a DNS lookup's answer's IP address value.
- D3-FV — Firmware Verification Cryptographically verifying firmware integrity.
- D3-HBPI — Hardware-based Process Isolation Preventing one process from writing to the memory space of another process through hardware based address manager...
- D3-HBWP — Hardware-based Write Protection Physical methods of preventing data from being written to computer storage.
- D3-HCI — Hardware Component Inventory Hardware component inventorying identifies and records the hardware items in the organization's architecture.
- D3-HD — Homoglyph Detection Comparing strings using a variety of techniques to determine if a deceptive or malicious string is being presented to a user.
- D3-HDDL — Hierarchical Domain Denylisting Blocking the resolution of any subdomain of a specified domain name.
- D3-HDL — Homoglyph Denylisting Blocking DNS queries that are deceptively similar to legitimate domain names.
- D3-HR — Host Reboot Initiating a host's reboot sequence to terminate all running processes.
- D3-HS — Host Shutdown Initiating a host's shutdown sequence to terminate all running processes.
- D3-IAA — Identifier Activity Analysis Taking known malicious identifiers and determining if they are present in a system.
- D3-IBCA — Indirect Branch Call Analysis Analyzing vendor specific branch call recording in order to detect ROP style attacks.
- D3-ID — Identifier Analysis Analyzing identifier artifacts such as IP address, domain names, or URL(I)s.
- D3-IDA — Input Device Analysis Operating system level mechanisms to prevent abusive input device exploitation.
- D3-IHN — Integrated Honeynet The practice of setting decoys in a production environment to entice interaction from attackers.
- D3-IOPR — IO Port Restriction Limiting access to computer input/output (IO) ports to restrict unauthorized devices.
- D3-IPCTA — IPC Traffic Analysis Analyzing standard inter process communication (IPC) protocols to detect deviations from normal protocol activity.
- D3-IPRA — IP Reputation Analysis Analyzing the reputation of an IP address.
- D3-IRA — Identifier Reputation Analysis Analyzing the reputation of an identifier.
- D3-IRV — Integer Range Validation Ensuring that an integer is within a valid range.
- D3-ISVA — Inbound Session Volume Analysis Analyzing inbound network session or connection attempt volume.
- D3-ITF — Inbound Traffic Filtering Restricting network traffic originating from untrusted networks destined towards a private host or enclave.
- D3-JFAPA — Job Function Access Pattern Analysis Detecting anomalies in user access patterns by comparing user access activity to behavioral profiles that categorize...
- D3-KBPI — Kernel-based Process Isolation Using kernel-level capabilities to isolate processes.
- D3-LAM — Local Account Monitoring Analyzing local user accounts to detect unauthorized activity.
- D3-LAMED — LAN Access Mediation LAN access mediation encompasses the application of strict access control policies, systematic verification of...
- D3-LFAM — Local File Access Mediation Local file access mediation is the process of an operating system granting or denying a specific access request to a...
- D3-LFP — Local File Permissions Local file permissions is the systematic process of defining, implementing, and managing access control policies...
- D3-LLM — Logical Link Mapping Logical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata.
- D3-MA — Message Analysis Analyzing email or instant message content to detect unauthorized activity.
- D3-MAN — Message Authentication Authenticating the sender of a message and ensuring message integrity.
- D3-MBSV — Memory Block Start Validation Ensuring that a pointer accurately references the beginning of a designated memory block.
- D3-MBT — Memory Boundary Tracking Analyzing a call stack for return addresses which point to unexpected memory locations.
- D3-MENCR — Message Encryption Encrypting a message body using a cryptographic key.
- D3-MFA — Multi-factor Authentication Requiring proof of two or more pieces of evidence in order to authenticate a user.
- D3-MH — Message Hardening The application of security controls to user-to-user and system-to-system communications so messages remain...
- D3-MSM — Motion Sensor Monitoring Monitoring events from motion detectors (e.g., passive IR, microwave, dual-technology) to detect presence or...
- D3-NAM — Network Access Mediation Network access mediation is the control method for authorizing access to a system by a user (or a process acting on...
- D3-NI — Network Isolation Network Isolation techniques prevent network hosts from accessing non-essential system network resources.
- D3-NM — Network Mapping Network mapping encompasses the techniques to identify and model the physical layer, network layer, and data...
- D3-NNI — Network Node Inventory Network node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.)...
- D3-NPC — Null Pointer Checking Checking if a pointer is NULL.
- D3-NRAM — Network Resource Access Mediation Control of access to organizational systems and services by users or processes over a network.
- D3-NTA — Network Traffic Analysis Analyzing intercepted or summarized computer network traffic to detect unauthorized activity.
- D3-NTCD — Network Traffic Community Deviation Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication.
- D3-NTF — Network Traffic Filtering Restricting network traffic originating from any location.
- D3-NTPM — Network Traffic Policy Mapping Network traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or...
- D3-NTSA — Network Traffic Signature Analysis Analyzing network traffic and compares it to known signatures
- D3-NVA — Network Vulnerability Assessment Network vulnerability assessment relates all the vulnerabilities of a network's components in the context of their...
- D3-OAM — Operational Activity Mapping Operational activity mapping identifies activities of the organization and the organization's suborganizations,...
- D3-ODM — Operational Dependency Mapping Operational dependency mapping identifies and models the dependencies of the organization's activities on each other...
- D3-OE — Object Eviction Terminate or remove an object from a host machine. This is the broadest class for object eviction.
- D3-OLV — Operational Logic Validation Validation of variable state in the context of the control logic of the operational application.
- D3-OM — Organization Mapping Organization mapping identifies and models the people, roles, and groups with an organization and the relations between them.
- D3-OMM — Operating Mode Monitoring Detects operating modes such as Program, Run, Remote, or Stop.
- D3-OPM — Operational Process Monitoring Monitoring physical parameters and operator actions related to an operational environment.
- D3-OPR — Operating Mode Restriction Restricting unauthorized changes to the operating mode prevents devices from switching into inappropriate or...
- D3-ORA — Operational Risk Assessment Operational risk assessment identifies and models the vulnerabilities of, and risks to, an organization's activities...
- D3-OSM — Operating System Monitoring The operating system software, for D3FEND's purposes, includes the kernel and its process management functions,...
- D3-OTF — Outbound Traffic Filtering Restricting network traffic originating from a private host or enclave destined towards untrusted networks.
- D3-OTP — One-time Password A one-time password is valid for only one user authentication.
- D3-OVAR — OT Variable Access Restriction Assign read/write access controls on designated registers or data tags to prevent unauthorized writes.
- D3-PA — Process Analysis Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors...
- D3-PAM — Physical Access Mediation Physical access mediation is the process of granting or denying specific requests to enter specific physical...
- D3-PAN — Pointer Authentication Comparing the cryptographic hash or derivative of a pointer's value to an expected value.
- D3-PBWSAM — Proxy-based Web Server Access Mediation Proxy-based web server access mediation focuses on the regulation of web server access through intermediary proxy servers.
- D3-PCA — Passive Certificate Analysis Collecting host certificates from network traffic or other passive sources like a certificate transparency log and...
- D3-PCSV — Process Code Segment Verification Comparing the 'text' or 'code' memory segments to a source of truth.
- D3-PE — Process Eviction Process eviction techniques terminate or remove running process.
- D3-PEH — Physical Enclosure Hardening Physical changes to a computer enclosure which reduce the ability for agents or the environment to affect the...
- D3-PFV — Peripheral Firmware Verification Cryptographically verifying peripheral firmware integrity.
- D3-PH — Platform Hardening Hardening components of a Platform with the intention of making them more difficult to exploit. Platforms includes...
- D3-PHAM — Physical Access Monitoring Monitoring the physical access of a specified environment through detection, recording, reviewing, and logging of...
- D3-PHDURA — Per Host Download-Upload Ratio Analysis Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded...
- D3-PLA — Process Lineage Analysis Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a...
- D3-PLLM — Passive Logical Link Mapping Passive logical link mapping only listens to network traffic as a means to map the the whole data link layer, where...
- D3-PLM — Physical Link Mapping Physical link mapping identifies and models the link connectivity of the network devices within a physical network.
- D3-PM — Platform Monitoring Monitoring platform components such as operating systems software, hardware devices, or firmware.
- D3-PMAD — Protocol Metadata Anomaly Detection Collecting network communication protocol metadata and identifying statistical outliers.
- D3-PR — Password Rotation Password rotation is a security policy that mandates the periodic change of user account passwords to mitigate the...
- D3-PS — Process Suspension Suspending a running process on a computer system.
- D3-PSA — Process Spawn Analysis Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.
- D3-PSEP — Process Segment Execution Prevention Preventing execution of any address in a memory region other than the code segment.
- D3-PSM — Proximity Sensor Monitoring Monitoring events from proximity sensors that indicate a credential or tagged asset is within the sensor’s read...
- D3-PSMD — Process Self-Modification Detection Detects processes that modify, change, or replace their own code at runtime.
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.