« Matrice DISARM » : différence entre les versions
Aucun résumé des modifications |
Aucun résumé des modifications |
||
(Une version intermédiaire par le même utilisateur non affichée) | |||
Ligne 20 : | Ligne 20 : | ||
==DISARM V.1== | ==DISARM V.1== | ||
*[[Plan]] | *'''[[Plan]]''' | ||
**[[TA01: Plan Strategy]] | **[[TA01: Plan Strategy]] | ||
***[[T0074: Determine Strategic Ends]] | ***[[T0074: Determine Strategic Ends]] | ||
Ligne 93 : | Ligne 93 : | ||
****[[T0072.004: Psychographic Segmentation]] | ****[[T0072.004: Psychographic Segmentation]] | ||
*[[Prepare]] | *'''[[Prepare]]''' | ||
**[[TA14: Develop Narratives]] | **[[TA14: Develop Narratives]] | ||
***[[T0040: Demand Insurmountable Proof]] | ***[[T0040: Demand Insurmountable Proof]] | ||
Ligne 320 : | Ligne 320 : | ||
****[[T0111.001: TV]] | ****[[T0111.001: TV]] | ||
*[[Execute]] | *'''[[Execute]]''' | ||
**[[TA08: Conduct Pump Priming]] | **[[TA08: Conduct Pump Priming]] | ||
***[[T0044: Seed Distortions]] | ***[[T0044: Seed Distortions]] | ||
Ligne 419 : | Ligne 419 : | ||
***[[T0059: Play the Long Game]] | ***[[T0059: Play the Long Game]] | ||
*[[Assess]] | *'''[[Assess]]''' | ||
**[[TA12: Assess Effectiveness]] | **[[TA12: Assess Effectiveness]] | ||
***[[T0133: Measure Effectiveness]] | ***[[T0133: Measure Effectiveness]] |
Dernière version du 22 mars 2025 à 22:34
Présentation
DISARM est une matrice qui permet de décrire et de comprendre les incidents liés à la désinformation et la manipulation de l'information. Elle est inspirée des pratiques de la sécurité de l’information et est conçue pour faciliter le suivi et la lutte contre les manipulations de l’information. DISARM s’appuie sur la structure de la matrice MITRE ATT&CK. Ainsi, son design lui permet d’intégrer les outils et les pratiques de la sécurité de l’information.
La matrice DISARM Red Team
La matrice DISARM red Team décrit les TTPs employés par un attaquant. Cette matrice est un modèle classique qui fait partie du programme MISP. La version Navigator permet de créer rapidement une liste des TTPs employées. La matrice se présente sous forme de phases, tactiques et techniques.
- Les phases regroupent les tactiques de haut niveau.
- Les tactiques décrivent les étapes qu'une personne menant un incident de désinformation est susceptible d'utiliser.
- Les techniques décrivent les activités qui peuvent être observées à chaque étape.
La matrice DISARM originale et sa traduction sont sous licence libre CC-BY-4.0
DISARM is a framework designed for describing and understanding disinformation incidents. DISARM is part of work on adapting information security (infosec) practices to help track and counter disinformation and other information harms, and is designed to fit existing infosec practices and tools.
DISARM's style is based on the MITRE ATT&CK framework. STIX templates for DISARM objects are available in the DISARM_CTI repo - these make it easy for DISARM data to be passed between ISAOs and similar bodies using standards like TAXII.
DISARM V.1
- Plan
- TA01: Plan Strategy
- TA02: Plan Objectives
- TA13: Target Audience Analysis
- T0081: Identify Social and Technical Vulnerabilities
- T0081.001: Find Echo Chambers
- T0081.002: Identify Data Voids
- T0081.005: Identify Existing Conspiracy Narratives/Suspicions
- T0081.004: Identify Existing Fissures
- T0081.003: Identify Existing Prejudices
- T0081.008: Identify Media System Vulnerabilities
- T0081.007: Identify Target Audience Adversaries
- T0081.006: Identify Wedge Issues
- T0080: Map Target Audience Information Environment
- T0072: Segment Audiences
- T0081: Identify Social and Technical Vulnerabilities
- Prepare
- TA14: Develop Narratives
- T0040: Demand Insurmountable Proof
- T0004: Develop Competing Narratives
- T0082: Develop New Narratives
- T0083: Integrate Target Audience Vulnerabilities into Narrative
- T0022: Leverage Conspiracy Theory Narratives
- T0003: Leverage Existing Narratives
- T0068: Respond to Breaking News Event or Active Crisis
- TA06: Develop Content
- TA15: Establish Assets
- T0146: Account Asset
- T0093: Acquire/Recruit Network
- T0150: Asset Origin
- T0092: Build Network
- T0010: Cultivate Ignorant Agents
- T0095: Develop Owned Media Assets
- T0113: Employ Commercial Analytic Firms
- T0145: Establish Account Imagery
- T0148: Financial Instrument
- T0148.002: Bank Account Asset
- T0148.006: Crowdfunding Platform
- T0148.008: Cryptocurrency Exchange Platform
- T0148.009: Cryptocurrency Wallet
- T0148.007: eCommerce Platform
- T0148.001: Online Banking Platform
- T0148.004: Payment Processing Capability
- T0148.003: Payment Processing Platform
- T0148.005: Subscription Processing Capability
- T0094: Infiltrate Existing Networks
- T0096: Leverage Content Farms
- T0149: Online Infrastructure
- T0014: Prepare Fundraising Campaigns
- T0065: Prepare Physical Broadcast Capabilities
- T0091: Recruit Malign Actors
- T0147: Software Asset
- TA16: Establish Legitimacy
- T0100: Co-Opt Trusted Sources
- T0098: Establish Inauthentic News Sites
- T0143: Persona Legitimacy
- T0144: Persona Legitimacy Evidence
- T0097: Present Persona
- T0097.103: Activist Persona
- T0097.205: Business Persona
- T0097.108: Expert Persona
- T0097.203: Fact Checking Organisation Persona
- T0097.112: Government Employee Persona
- T0097.206: Government Institution Persona
- T0097.111: Government Official Persona
- T0097.104: Hacktivist Persona
- T0097.100: Individual Persona
- T0097.200: Institutional Persona
- T0097.102: Journalist Persona
- T0097.201: Local Institution Persona
- T0097.101: Local Persona
- T0097.105: Military Personnel Persona
- T0097.202: News Outlet Persona
- T0097.207: NGO Persona
- T0097.110: Party Official Persona
- T0097.106: Recruiter Persona
- T0097.107: Researcher Persona
- T0097.109: Romantic Suitor Persona
- T0097.208: Social Cause Persona
- T0097.204: Think Tank Persona
- TA05: Microtarget
- TA07: Select Channels and Affordances
- T0107: Bookmarking and Content Curation
- T0109: Consumer Review Networks
- T0151: Digital Community Hosting Asset
- T0151.007: Chat Broadcast Group
- T0151.005: Chat Community Server
- T0151.004: Chat Platform
- T0151.006: Chat Room
- T0151.014: Comments Section
- T0151.010: Community Forum Platform
- T0151.011: Community Sub-Forum
- T0151.017: Dating Platform
- T0151.012: Image Board Platform
- T0151.009: Legacy Online Forum Platform
- T0151.008: Microblogging Platform
- T0151.002: Online Community Group
- T0151.003: Online Community Page
- T0151.015: Online Game Platform
- T0151.016: Online Game Session
- T0151.013: Question and Answer Platform
- T0151.001: Social Media Platform
- T0154: Digital Content Creation Asset
- T0153: Digital Content Delivery Asset
- T0152: Digital Content Hosting Asset
- T0152.007: Audio Platform
- T0152.002: Blog Asset
- T0152.001: Blogging Platform
- T0152.010: File Hosting Platform
- T0152.008: Live Streaming Platform
- T0152.005: Paste Platform
- T0152.009: Software Delivery Platform
- T0152.012: Subscription Service Platform
- T0152.006: Video Platform
- T0152.004: Website Asset
- T0152.003: Website Hosting Platform
- T0152.011: Wiki Platform
- T0110: Formal Diplomatic Channels
- T0155: Gated Asset
- T0029: Online Polls
- T0111: Traditional Media
- TA14: Develop Narratives
- Execute
- TA08: Conduct Pump Priming
- TA09: Deliver Content
- TA17: Maximise Exposure
- T0118: Amplify Existing Narrative
- T0039: Bait Influencer
- T0119: Cross-Posting
- T0122: Direct Users to Alternative Platforms
- T0049: Flood Information Space
- T0049.003: Bots Amplify via Automated Forwarding and Reposting
- T0049.006: Conduct Keyword Squatting
- T0049.005: Conduct Swarming
- T0049.002: Flood Existing Hashtag
- T0049.008: Generate Information Pollution
- T0049.007: Inauthentic Sites Amplify News and Narratives
- T0049.001: Trolls Amplify and Manipulate
- T0049.004: Utilise Spamoflauge
- T0120: Incentivize Sharing
- T0121: Manipulate Platform Algorithm
- TA18: Drive Online Harms
- TA10: Drive Offline Activity
- TA11: Persist in the Information Environment
- T0128: Conceal Information Assets
- T0130: Conceal Infrastructure
- T0129: Conceal Operational Activity
- T0129.003: Break Association with Content
- T0129.001: Conceal Network Identity
- T0129.005: Coordinate on Encrypted/Closed Networks
- T0129.007: Delete Accounts/Account Activity
- T0129.004: Delete URLs
- T0129.006: Deny Involvement
- T0129.002: Generate Content Unrelated to Narrative
- T0129.010: Misattribute Activity
- T0129.009: Remove Post Origins
- T0060: Continue to Amplify
- T0131: Exploit TOS/Content Moderation
- T0059: Play the Long Game