lowRISC / lowRISC/opentitan

[doc] Refine terminology describing countermeasures

Open
#17,285 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component:Doc Component:Security Earlgrey-PROD Triaged
Dominant language
SystemVerilog
Stars
3.6k
Forks
1.1k
Avg merge
2d 22h
Merged PRs (30d)
141

Description

In the future we could use more explicit terminology. When referring to countermeasures, we can say they are implemented to either 1) detect, 2) mitigate, or 3) respond to a potential attack. It is expected that a countermeasure alone is not going to completely be able to completely deter a potential attack from the perspective of the threat model. For those not familiar with security, it could be useful to explicitly state this in the threat model.

Originally posted by @moidx in https://github.com/lowRISC/opentitan/pull/17262#discussion_r1106426561

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the threat model documentation and the terminology discussion in PR #17262, which is referenced by this issue. The documentation should distinguish countermeasures that detect, mitigate, or respond to attacks, and explain that a countermeasure need not completely deter an attack under the threat model.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.