I-AXIS Security Model Development Software

Isingeniso
Izinjongo ze-ASDM
I-Axis Security Development Model (ASDM) iwuhlaka oluchaza inqubo namathuluzi asetshenziswa i-Axis ukwakha isofthiwe enokuphepha eyakhelwe ngaphakathi kuwo wonke umjikelezo wempilo, kusukela ekuqaleni kuya ekuyekisweni kwawo.

Izinhloso eziphambili eziqhuba imizamo ye-ASDM yilezi
- Yenza ukuphepha kwesofthiwe kube yingxenye ehlanganisiwe yemisebenzi yokuthuthukisa isofthiwe ye-Axis.
- Yehlisa ubungozi bebhizinisi obuhlobene nokuvikeleka kumakhasimende e-Axis.
- Meet increasing awareness of security considerations by customers and partners.
- Dala amathuba okuncishiswa kwezindleko ngenxa yokutholwa kusenesikhathi nokuxazululwa kwezinkinga
Ububanzi be-ASDM isofthiwe ye-Axis efakwe emikhiqizweni ye-Axis nezisombululo. I-Software Security Group (SSG) ingumnikazi nomnakekeli we-ASDM.
Uhlu lwamagama
| I-ASDM | I-Axis Security Development Model |
| I-SSG | Iqembu Lokuphepha Kwesoftware |
| I-Firmware ukuqondisa iqembu | Ukuphathwa kwe-R&D |
| Isathelayithi | Onjiniyela abanobudlelwane bemvelo bokuphepha kwesoftware |
| Ukuba sengozini ibhodi | Iphoyinti lokuxhumana le-eksisi ngokuhlobene nokuba sengozini okutholwe abacwaningi bangaphandle |
| Ibha yesiphazamisi | Ithagethi yokuphepha yomkhiqizo noma isixazululo |
| I-DFD | Umdwebo wokugeleza kwedatha |
I-ASDM iphelileview
I-ASDM ihlanganisa imisebenzi eminingana esabalale ezigabeni ezinkulu zentuthuko. Imisebenzi yezokuphepha ikhonjwe ngokuhlanganyela njenge-ASDM.

The SSG is responsible for governing the ASDM and evolving the toolbox over time. There is an ASDM roadmap and a rollout plan for implementing new activities and increasing ASDM maturity across the development organization. Both the roadmap and rollout plan are owned by the SSG, but the responsibility for actual implementation in practice (i.e., performing activities related to development phases) is delegated to the R&D teams.
I-Software Security Group (SSG)
I-SSG iyibhizinisi elikhulu lokuxhumana langaphakathi eliqondise ezinhlanganweni zokuthuthukisa ngezinkinga ezihlobene nokuphepha. Ihlanganisa Ukuhola Kwezokuphepha kanye nabanye abanolwazi lwezokuphepha olukhethekile ezindaweni zokuthuthukiswa ezifana nezidingo, ukuklama, ukuqaliswa, ukuqinisekiswa,
kanye nezinqubo ze-DevOps ezisebenzayo.
I-SSG inomthwalo wemfanelo wokuthuthukisa nokugcina i-ASDM yezinqubo zentuthuko ezivikelekile kanye nokuqwashisa ngokuvikeleka enhlanganweni yokuthuthukisa.
Amasathelayithi
Amasathelayithi angamalungu enhlangano yokuthuthukisa achitha ingxenye yesikhathi sawo esebenza nezici zokuphepha zesofthiwe. Izizathu zokuba namasathelayithi yilezi:
- Kala i-ASDM ngaphandle kokwakha i-SSG enkulu emaphakathi
- Nikeza ukwesekwa kwe-ASDM eduze namaqembu okuthuthukisa
- Yenza kube lula ukwabelana ngolwazi, isb, izinqubo ezingcono kakhulu
Isathelayithi izosiza ekuqaliseni imisebenzi emisha kanye nokugcina i-ASDM iyingxenye yamaqembu okuthuthukisa.
Ukukhishwa komsebenzi we-ASDM
Ukukhishwa komsebenzi we-ASDM ethimbeni lokuthuthukisa kunjengobataginqubo ye-ed:
- Ithimba lethulwa kulo msebenzi omusha ngokuqeqeshwa okuqondene nendima ethile.
- I-SSG isebenza ndawonye nethimba ukwenza umsebenzi, isb, ukuhlola ubungozi noma ukumodela ubungozi, ezingxenyeni ezikhethiwe zesistimu ephethwe yiqembu.
- Eminye imisebenzi ehlobene nokuhlanganisa ibhokisi lamathuluzi emsebenzini wansuku zonke izonikezwa ithimba nesathelayithi uma isilungele ukusebenza ngokuzimela ngaphandle kokubandakanyeka okuqondile kwe-SSG. Kulesi sigaba, umsebenzi ulawulwa yimenenja yeqembu ngokusebenzisa isimo se-ASDM.
Ukukhishwa kuyaphindwa uma kunezinguqulo ezintsha ze-ASDM ezitholakalayo nemisebenzi eguquliwe kanye/noma eyengeziwe. Isikhathi esichithwa i-SSG neqembu sincike kakhulu kumsebenzi nobunkimbinkimbi bekhodi. Isici esibalulekile sokunikezela ngempumelelo eqenjini ukuba khona kwesathelayithi egxilile engaqhubeka nomsebenzi we-ASDM neqembu. I-SSG ishayela ukufunda nokwabiwa kwesathelayithi ngokuhambisana nokukhishwa komsebenzi.
Isibalo esingezansi sifinyeza indlela yokukhishwa.
Incazelo ye-SSG yokuthi "kwenziwe" yokunikezela ithi:
- Ukuqeqeshwa okuqondene neqhaza okwenziwe
- Isathelayithi yabelwe
- Ithimba selilungele ukwenza umsebenzi we-ASDM
- Imihlangano yesimo ye-ASDM eqhubekayo iyasungulwa
I-SSG isebenzisa okokufaka okuvela emaqenjini ukuze ihlanganise imibiko yesimo kubaphathi abakhulu.
Eminye imisebenzi ye-SSG
Ngokuhambisana nemisebenzi yokukhishwa, i-SSG yenza imisebenzi yokuqeqesha yokuqwashisa ngezokuphepha ebanzi eqondise isb, abasebenzi abasha nabaphathi abakhulu. Ukwengeza, i-SSG igcina imephu yokushisa yokuvikela yezixazululo ze-Axis ngezinhloso zokuhlola ubungozi zizonke/zezakhiwo. Imisebenzi yokuhlaziya ukuphepha okusebenzayo kwamamojuli athile yenziwa ngokusekelwe kumephu yokushisa.
Izindima nezibopho
Njengoba kukhonjisiwe kuthebula elingezansi, kunezinhlaka nezindima ezibalulekile eziyingxenye yohlelo lwe-ASDM. Ithebula elingezansi lifingqa izindima kanye nezibopho maqondana ne-ASDM.
| Indima/Ibhizinisi | Ingxenye ye | Isibopho | Phawula |
| Uchwepheshe wezokuphepha | I-SSG | Lawula i-ASDM, uguqule ibhokisi lamathuluzi futhi uqhube ukukhishwa kwe-ASDM | I-100% inikezwe i-SSG |
| Isathelayithi | Ulayini wokuthuthukiswa | Siza i-SSG ukuthi isebenzise i-ASDM okokuqala, abaqeqeshi bamaqembu, benze ukuqeqeshwa futhi baqinisekise ukuthi iqembu lingaqhubeka nokusebenzisa Ibhokisi lamathuluzi njengengxenye yomsebenzi wansuku zonke, ngaphandle kwe-SSG. Isibopho seqembu elihlangene (amaqembu amaningana) adingekayo ukuze kuncishiswe inani eliphelele lamasathelayithi. | Onjiniyela abanentshisekelo nababambe iqhaza, abaklami bezakhiwo, abaphathi, abahloli, nezindima ezifanayo abanobudlelwane bemvelo bokuvikeleka kwesoftware. Amasathelayithi anika okungenani u-20% wesikhathi sawo emsebenzini ohlobene ne-ASDM. |
| Abaphathi | Ulayini wokuthuthukiswa | Vikela izinsiza zokusetshenziswa kwezinqubo ze-ASDM. Shayela ukulandelela kanye nokubika ngesimo se-ASDM nokuhlanganisa. | Amaqembu okuthuthukisa aphethe ukuqaliswa kwe-ASDM, ne-SSG njengesisetshenziswa sokusekela. |
| I-Firmware Steering Group (FW SG) | Ukuphathwa kwe-R&D | Inquma isu lokuvikeleka futhi isebenza njengesiteshi esikhulu sokubika se-SSG. | I-SSG ibika ku-FW SG njalo. |
Ukubusa kwe-ASDM
Uhlelo lokuphatha luhlanganisa izingxenye ezilandelayo:
- Imephu yokushisa engozini yesistimu ukusiza ukubeka phambili imisebenzi ye-ASDM
- Uhlelo lokukhishwa nesimo sokugxila emizamweni yokuqeqesha
- Umhlahlandlela wokuguqula ibhokisi lamathuluzi
- Isimo sokulinganisa ukuthi imisebenzi ye-ASDM ihlanganiswe kahle kangakanani enhlanganweni
Ngakho-ke uhlelo lwe-ASDM lusekelwa kokubili ngokombono weqhinga/wokusebenza kanye nangokwesu/umbono wokuphatha.
Isiqondiso esiphezulu ngakwesokunene sesibalo sigxile ekutheni inhlangano ingathuthukiswa kanjani ukuze isebenze kahle ngokuhambisana nezinjongo zebhizinisi le-Axis. Okubalulekile kulokhu ukubikwa kwesimo se-ASDM okwenziwa yi-SSG ku-Firmware Steering Group, i-CTO kanye nokuphathwa komkhiqizo.

Isakhiwo sesimo se-ASDM
Isakhiwo sesimo se-ASDM sinemibono emibili: iqembu elilodwa eligxile ekulingiseni ithimba lethu nesakhiwo somnyango, kanye nesixazululo esisodwa esigxile ezisombululweni esiziletha emakethe.
Isibalo esingezansi sibonisa ukwakheka kwesimo se-ASDM.
Isimo seqembu
Isimo seqembu siqukethe ukuzihlolela kweqembu ukukhula kwalo kwe-ASDM, amamethrikhi ahlobene nemisebenzi yalo yokuhlaziya ukuphepha kanye nokuhlanganiswa kwesimo sokuvikeleka sezingxenye ababhekele kuzo.

I-axis ichaza ukukhula kwe-ASDM njengenguqulo ye-ASDM iqembu eliyisebenzisayo njengamanje. Njengoba i-ASDM ithuthuka, sichaze inguqulo ye-ASDM lapho inguqulo ngayinye ye-ASDM iqukethe isethi ehlukile yemisebenzi. Okwesiboneloampfuthi, inguqulo yethu yokuqala ye-ASDM igxile ekufanekiseni usongo.
I-Axis ichaze izinguqulo ezilandelayo ze-ASDM:
| Inguqulo ye-ASDM | Imisebenzi emisha |
| I-ASDM 1.0 | Ukuhlolwa kobungozi kanye nokumodela ubungozi |
| I-ASDM 2.0 | Ikhodi engashintshi kabushaview |
| I-ASDM 2.1 | Ubumfihlo ngokuklama |
| I-ASDM 2.2 | Ukuhlaziywa kokwakheka kwesoftware |
| I-ASDM 2.3 | Ukuhlolwa kokungena kwangaphandle |
| I-ASDM 2.4 | Ukuskena kokuba sengozini kanye nokuprakthiza umlilo |
| I-ASDM 2.5 | Isimo sokuphepha komkhiqizo/Isixazululo |
Ukunikeza ubunikazi beqembu ukuthi iyiphi inguqulo ye-ASDM abayisebenzisayo kusho ukuthi ngumphathi obhekele ukwamukelwa kwezinguqulo ezintsha ze-ASDM. Ngakho esikhundleni sokusethwa lapho i-SSG iphusha khona uhlelo olumaphakathi lokukhishwa kwe-ASDM manje isiba yidonsa futhi ilawulwe ngabaphathi.
Isimo sengxenye
- Sinencazelo ebanzi yengxenye njengoba sidinga ukumboza zonke izinhlobo zezinhlangano zezakhiwo kusukela kumademoni e-Linux endaweni yesikhulumi, ngokusebenzisa isofthiwe yeseva yonke indlela yokuvala izinsiza (ezincane).
- Ithimba ngalinye kufanele lizenzele owalo umqondo wezinga lokungabonakali elisebenzela lona endaweni yalo kanye nezakhiwo. Njengomthetho wesithupha, amaqembu kufanele agweme ukusungula ileveli entsha yokukhipha futhi agcine noma yini asevele eyisebenzisa emsebenzini wawo wansuku zonke.
- Umbono wukuthi iqembu ngalinye kufanele libe nencazelo ecacile view yazo zonke izingxenye ezinobungozi obukhulu, obufaka izingxenye ezintsha kanye nezakudala. Isisusa sale ntshisekelo eyengeziwe ezingxenyeni zefa sixhunywe nekhono lethu lokubheka isimo sokuvikeleka ukuze sithole izixazululo. Esimeni sesixazululo, sifuna ukubonakala kusimo sokuphepha sazo zonke izingxenye zesixazululo ezintsha nezindala.
- Ekwenzeni lokhu kusho ukuthi iqembu ngalinye kufanele libheke uhlu lwazo lwezingxenye bese lenza ukuhlolwa kobungozi.
- Into yokuqala okudingeka siyazi ukuthi ingxenye ihloliwe yini ukuphepha. Uma ingakakwenzi, empeleni asazi lutho mayelana nekhwalithi yokuphepha yengxenye.
Lokhu sikubiza ngekhava yezakhiwo futhi sichaze amazinga alandelayo okukhava:
| Ukuhlanganisa | Incazelo |
| Ukuhlaziya akwenziwa | Ingxenye ayikahlaziywa |
| Ukuhlaziya kuyaqhubeka | Ingxenye iyahlaziywa |
| Ukuhlaziya kwenziwe | Ingxenye ihlaziyiwe |
Amamethrikhi esiwasebenzisayo ukuze sithwebule ikhwalithi yokuvikeleka yengxenye asekelwe ezintweni zomsebenzi wokuvikela eziku-backlog ezixhunywe engxenyeni. Lokhu kungaba izindlela zokuphikisa ezingakenziwa, amacala okuhlola angazange asetshenziswe kanye neziphazamisi zokuphepha ezingakenziwa.
Isimo sesixazululo
Isimo sesixazululo sihlanganisa isimo sokuphepha sesethi yezingxenye ezenza isisombululo.
Ingxenye yokuqala yesimo sesixazululo ukumbozwa kokuhlaziywa kwezingxenye. Lokhu kusiza abanikazi besixazululo ukuthi baqonde ukuthi isimo sokuphepha sesixazululo saziwa yini noma asaziwa. Kokunye kusiza ukukhomba izindawo eziyizimpumputhe. Esinye isimo sesixazululo siqukethe amamethrikhi athwebula ikhwalithi yokuvikeleka yesixazululo. Senza lokho ngokubheka izinto zomsebenzi wezokuphepha ezixhunywe kuzingxenye ezisesixazululweni. Isici esibalulekile sesimo sokuvikeleka ibha yesiphazamisi echazwa abanikazi besixazululo. Abanikazi besixazululo kufanele bachaze ileveli yokuphepha efanelekile yesixazululo sabo. Okwesiboneloample, lokhu kusho ukuthi isixazululo akufanele sibe nezinto zokusebenza ezibucayi ezisasele noma ezinzima ezivulwa lapho zikhishwa emakethe.
Imisebenzi ye-ASDM
Ukuhlola ingozi
Inhloso enkulu yokuhlola ubungozi ukuhlunga ukuthi yimiphi imisebenzi yentuthuko ezodinga futhi umsebenzi wokuphepha eqenjini.
Ukuhlolwa kwengozi kwenziwa ngokwahlulela ukuthi umkhiqizo omusha noma isici esengeziwe/esilungisiwe emikhiqizweni ekhona kwandisa ukuchayeka engozini. Qaphela ukuthi lokhu kufaka phakathi izici zobumfihlo bedatha kanye nezidingo zokuthobelana. Exampizinguquko ezimbalwa ezinomthelela engcupheni ama-API amasha, izinguquko ezidingweni zokugunyazwa, i-middleware entsha, njll.
Ubumfihlo bedatha
Ukuthembana kuyindawo eyinhloko okugxilwe kuyo ye-Axis futhi, ngenxa yalokho, kubalulekile ukulandela izinqubo ezingcono kakhulu lapho usebenza nedatha eyimfihlo eqoqwe imikhiqizo yethu, izixazululo namasevisi.
Ububanzi bemizamo ye-Axis ehlobene nobumfihlo bedatha buchazwa ngendlela yokuthi:
- Gcwalisa izibopho zomthetho
- Gcwalisa izibopho zenkontileka
- Siza amakhasimende afeze izibopho zawo
Sihlukanisa umsebenzi wobumfihlo bedatha ezintweni ezimbili ezincane:
- Ukuhlolwa kobumfihlo bedatha
- Kwenziwe ngesikhathi sokuhlolwa kwengozi
- Ikhomba ukuthi ukuhlaziya ubumfihlo bedatha kuyadingeka yini
- Ukuhlaziywa kobumfihlo bedatha
- Kwenziwe, lapho kusebenza, ngesikhathi sokumodela okusongelayo
- Ihlonza idatha yomuntu siqu kanye nezinsongo kudatha yomuntu siqu
- Ichaza izidingo zobumfihlo
Ukumodela okusongelayo
Ngaphambi kokuba siqale ukukhomba izinsongo, sidinga ukunquma ngobubanzi bemodeli yosongo. Indlela yokuchaza ububanzi ukuchaza abahlaseli okudingeka sibacabangele. Le ndlela izophinde isivumele ukuthi sibone izindawo zokuhlasela ezisezingeni eliphezulu okufanele sizifake ekuhlaziyeni.

- Ukugxila ngesikhathi sokuthola izinsongo kusekutholeni nasekuhlukaniseni abahlaseli esifuna ukubaphatha sisebenzisa incazelo yezinga eliphezulu yesistimu. Ngokukhethekile incazelo yenziwa kusetshenziswa idayagramu yokugeleza kwedatha (DFD) njengoba yenza kube lula ukuhlobanisa izincazelo ezinemininingwane yokusetshenziswa ezisetshenziswa lapho kwenziwa imodeli yokusongela.
- Lokhu akusho ukuthi bonke abahlaseli esibakhombayo badinga ukucatshangelwa, kumane kusho ukuthi sibeka obala futhi asiguquguquki kubahlaseli esizobhekana nabo kumodeli yosongo. Ngakho, empeleni abahlaseli esikhetha ukubacabangela bazochaza ileveli yokuphepha yesistimu esiyihlolayo.
Qaphela ukuthi incazelo yethu yomhlaseli ayihlanganisi amandla omhlaseli noma ugqozi. Sikhethe le ndlela yokwenza lula kanye nokwenza lula ukumodeliswa kwezinsongo ngangokunokwenzeka.
Ukumodela okusongelayo kunezinyathelo ezintathu ezingaphindwa njengoba iqembu libona kufanele:
- Chaza isistimu usebenzisa isethi yama-DFD
- Sebenzisa ama-DFD ukuze ubone izinsongo futhi uzichaze ngendlela yokuhlukumeza
- 3. Chaza izinyathelo eziphikisanayo nokuqinisekiswa kwezinsongo
Umphumela womsebenzi wokulingisa usongo uyimodeli yosongo equkethe izinsongo ezibekwe phambili kanye nezinyathelo zokulwa nazo. Umsebenzi wokuthuthukisa odingekayo ukuze kubhekwane nezinyathelo eziphikisayo uphethwe ngokudalwa kwamathikithi e-Jira kokubili okusetshenziswa nokuqinisekiswa kwesinyathelo esiphikisayo.
Ukuhlaziywa kwekhodi engashintshi
Ku-ASDM, amaqembu angasebenzisa ukuhlaziya ikhodi emile ngezindlela ezintathu:
- Ukugeleza komsebenzi kanjiniyela: onjiniyela bahlaziya ikhodi abasebenza kuyo
- Ukugeleza komsebenzi kaGerrit: onjiniyela bathola impendulo ku-Gerrit
- Ukugeleza komsebenzi kwefa: amaqembu ahlaziya izingxenye zefa ezisengozini enkulu

Ukuskena kokuba sengozini
Ukuskena okuvamise ukuba sengozini kuvumela amaqembu okuthuthukisa ukuthi akhombe futhi abhacise ubungozi besofthiwe ngaphambi kokuba imikhiqizo ikhishelwe emphakathini, kunciphisa ubungozi bamakhasimende lapho bethumela umkhiqizo noma isevisi. Ukuskena kwenziwa ngaphambi kokukhishwa ngakunye kwezingxenyekazi zekhompuyutha, isofthiwe) noma kushejuli esebenzayo (amasevisi) kusetshenziswa womabili amaphakheji wokuskena womthombo ovulekile nawentengiso wokuba sengozini. Imiphumela yokuskena isetshenziselwa ukukhiqiza amathikithi kunkundla yokulandelela udaba lwe-Jira. Amathikithi anikezwa isipesheli tag ukuze zikhonjwe ngamathimba okuthuthukisa njengavela ekuhlolweni kobungozi nokuthi kufanele anikezwe indawo yokuqala ephezulu. Zonke izikena zokuba sengozini kanye namathikithi e-Jira agcinwa endaweni eyodwa ukuze alandeleke futhi ahlole. Ukuba sengozini okubalulekile kufanele kuxazululwe ngaphambi kokukhishwa noma ekukhishweni kwesevisi okukhethekile nokunye, ubungozi obungabalulekile,
kulandelelwe futhi kuxazululwe ngokuhambisana ne-firmware noma umjikelezo wokukhishwa kwesoftware. noma ulwazi olwengeziwe mayelana nokuthi ubungozi butholwa futhi bulawulwa kanjani, bheka Ukuphathwa Kobungozi ekhasini 12
Ukuhlolwa kokungena kwangaphandle
Ezimweni ezikhethiwe, ukuhlola ukungena kwenkampani yangaphandle kwenziwa kuzingxenyekazi zekhompuyutha ze-Axis noma imikhiqizo yesofthiwe. Injongo eyinhloko yokwenza lezi zivivinyo ukunikeza ukuqonda nesiqiniseko mayelana nokuphepha kwe-platrorm ngesikhathi esithile kanye nobubanzi obuthile. Enye yezinhloso zethu eziyinhloko nge-ASDM wukwenza izinto obala ngakho sikhuthaza amakhasimende ethu ukuthi enze ukuhlola kwangaphandle kokungena emikhiqizweni yethu futhi siyajabula ukubambisana lapho sichaza imingcele efanele yokuhlola kanye nezingxoxo mayelana nokutolika imiphumela.
Ukuphathwa kobungozi
I-Axis, kusukela ngo-2021, iyisiphathimandla esibhalisiwe se-CVE (i-CNA) futhi ngenxa yalokho iyakwazi ukushicilela imibiko evamile ye-CVE kusizindalwazi se-MITER ukuze isetshenziswe izikena zezinkampani zangaphandle ezisengozini namanye amathuluzi. Ibhodi le-vulnerability (VB) indawo yokuxhumana yangaphakathi ye-Axis ngobungozi obutholwe abacwaningi bangaphandle. Ukubika kwe
ubungozi obutholakele kanye nezinhlelo zokulungisa ezilandelayo zidluliswa nge- product-security@axis.com ikheli le-imeyili.
Umsebenzi oyinhloko webhodi labasengozini ukuhlaziya nokubeka phambili ubuthakathaka obubikiwe ngokombono webhizinisi, ngokusekelwe
- Ukuhlukaniswa kwezobuchwepheshe kuhlinzekwa yi-SSG
- Ubungozi obungaba khona kubasebenzisi bokugcina endaweni lapho idivayisi ye-Axis isebenza khona
- Ukutholakala kwezilawuli zokuphepha ezinxephezela ukwehlisa ubungozi ngaphandle kokuchibiyela)
I-VB ibhalisa inombolo ye-CVE futhi isebenze nentatheli ukuze yabele amaphuzu e-CVSS ekubeni sengozini. I-VB futhi ishayela ukuxhumana kwangaphandle kozakwethu namakhasimende ngesevisi yesaziso sezokuphepha ye-Axis, ukukhishwa kwabezindaba, nezindatshana zezindaba.

Imodeli Yokuthuthukiswa Kokuphepha kwe-Axis © Axis Communications AB, 2022
Amadokhumenti / Izinsiza
![]() |
I-AXIS Security Model Development Software [pdf] Imaniwali yosebenzisayo Imodeli Yokuthuthukiswa Kokuphepha, Isofthiwe, Imodeli Yokuthuthukisa Ukuphepha |





