Skip to content

Commit a6c73b0

Browse files
committed
Rename framework to business logic abuse definition framework
Feedback from @RB-KSDA: A substantial change we see is a move away from the term "attack" toward using "abuse," which implies a continued campaign and provides more scope for downstream mitigations. The term attack could imply an immediate need for remediation and force a binary response, such as blocking or not blocking. In cases of business logic abuse multiple levers could be pulled to assist companies facing these challenges. Customers often need to make a business decision, not just a security decision.
1 parent fdc55a6 commit a6c73b0

9 files changed

Lines changed: 15 additions & 14 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -171,4 +171,5 @@
171171
- None
172172

173173
## Website
174+
- Renamed framework from Business Logic *Attack* Definition Framework to Business Logic *Abuse* Definition Framework and updated terminology accordingly. The term attack could imply an immediate need for remediation and force a binary response, such as blocking or not blocking. In cases of business logic abuse, multiple levers could be pulled to assist companies facing these challenges. Customers often need to make a business decision, not just a security decision
174175
- Tactics and techniques in Matrix and Killchain views are now displayed in alphabetical order

‎_config.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
title: "OWASP BLADE: Business Logic Attack Definition Framework"
1+
title: "OWASP BLADE: Business Logic Abuse Definition Framework"
22
locale: "en-US"
3-
description: "The OWSAP Business Logic Attack Definition (BLADE) Framework, is an open-source knowledge-base created to help cybersecurity professionals fight cyber threats."
3+
description: "The OWASP Business Logic Abuse Definition (BLADE) Framework, is an open-source knowledge-base created to help cybersecurity professionals fight cyber threats."
44
#tagline: "The BLADE framework for Bot attacks"
55
remote_theme: "mmistakes/minimal-mistakes@4.23.0"
66

‎_layouts/home.html‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@
44
---
55

66

7-
<p class="standfirst">The <a href="/matrix">OWASP Business Logic Attack Definition (BLADE) Framework</a>, is an open-source knowledge-base created to help cybersecurity professionals identify the <a href="/phases">phases</a>, <a href="/tactics">tactics</a> and <a href="/techniques">techniques</a> used by adversaries to exploit weaknesses in the business logic of web facing systems (websites and APIs).</p>
7+
<p class="standfirst">The <a href="/matrix">OWASP Business Logic Abuse Definition (BLADE) Framework</a>, is an open-source knowledge-base created to help cybersecurity professionals identify the <a href="/phases">phases</a>, <a href="/tactics">tactics</a> and <a href="/techniques">techniques</a> used by adversaries to exploit weaknesses in the business logic of web facing systems (websites and APIs).</p>
88
<div class="columns">
9-
<p>There are a range of attack frameworks (such as Mitre ATT&CK and Lockheed-Martin Kill Chain) available to allow cyber-security experts to model and respond to traditional cyber-attacks which aimed to exploit technology weaknesses in systems. These frameworks are not well suited for modelling business logic focused attacks yet these kind of attacks are becoming increasingly common.<p>
10-
<p>Netacea's threat research team has worked with a range of security professionals to capture real world experience into a <a href="/matrix">framework</a> that captures the range of business logic attack types into a series of comprehensive <a href="/kill-chains">kill chains</a>, to allow security professionals to take a proactive approach in putting in defences against automated and business logic targeted attacks.</p>
9+
<p>There are a range of attack frameworks (such as Mitre ATT&CK and Lockheed-Martin Kill Chain) available to allow cyber-security experts to model and respond to traditional cyber-attacks which aimed to exploit technology weaknesses in systems. These frameworks are not well suited for modelling business logic focused abuse, yet this kind of abuse is becoming increasingly common.<p>
10+
<p>Netacea's threat research team has worked with a range of security professionals to capture real world experience into a <a href="/matrix">framework</a> that captures the range of business logic abuse types into a series of comprehensive <a href="/kill-chains">kill chains</a>, to allow security professionals to take a proactive approach in putting in defences against automated and business logic targeted abuse.</p>
1111
<p>If you wish to provide feedback or join the project team, please refer to the <a href="/contribute">Contribute</a> page for guidelines on how to do so. For further guidance on how to read and understand the framework please refer to the <a href="/resources">Resources</a> page. </p>
1212
<p>Not sure where to begin? Read our <a href="/assets/pdf/BLADE_guide_2022.pdf">'Getting Started with the OWASP BLADE Framework'</a> guide.</p>
1313
<p><a class="button" href="/matrix">Continue to the OWASP BLADE Framework matrix</a></p>

‎_pages/contribute.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,10 @@ permalink: /contribute.html
1616
<p>If you wish to join the Core Contributors team, then please send an email to <a href="mailto:blade@netacea.com?subject=BLADE Framework - join core contributors">blade@netacea.com</a>. Please include your name, job role, and any associated company with whom you work.</p>
1717

1818
<h2>History</h2>
19-
<p>The framework was initially created by the Threat Research Team at Netacea. This team consisted of Matthew Gracey-McMinn, Antony Barnett, and Liam Jones. Netacea is a specialist in handling Business Logic Attacks and providing Bot Management solutions. The Project initially began to aid Netacea in the detection and mitigation of business logic threats, but quickly evolved into an open-source project sponsored by Netacea. The team analysed the extensive data gathered by Netacea, and combined it with the results of focussed research into the stages of different Business Logic Attacks. These were then used to create the basis of a first draft of the BLADE Framework.</p>
19+
<p>The framework was initially created by the Threat Research Team at Netacea. This team consisted of Matthew Gracey-McMinn, Antony Barnett, and Liam Jones. Netacea is a specialist in handling Business Logic Abuse and providing Bot Management solutions. The Project initially began to aid Netacea in the detection and mitigation of business logic threats, but quickly evolved into an open-source project sponsored by Netacea. The team analysed the extensive data gathered by Netacea, and combined it with the results of focussed research into the stages of different cases of Business Logic Abuse. These were then used to create the basis of a first draft of the BLADE Framework.</p>
2020

21-
<p>This first draft was then shared with a variety of individuals (several of whom later joined the Core Contributors team). These individuals provided feedback including new definitions, changes to existing definitions, and removal of unnecessary definitions. Once these changes had been implemented the framework was rolled out to further individuals and began to be employed in the detection and mitigation of Business Logic Attacks in a variety of business cases.
22-
On June 16th, 2021, the BLADE Framework was formally released as an open source framework. Its goal being to provide all defenders with a tool by which to understand and improve their ability to detect and defend against Business Logic Attacks.</p>
21+
<p>This first draft was then shared with a variety of individuals (several of whom later joined the Core Contributors team). These individuals provided feedback including new definitions, changes to existing definitions, and removal of unnecessary definitions. Once these changes had been implemented the framework was rolled out to further individuals and began to be employed in the detection and mitigation of Business Logic Abuse in a variety of business cases.
22+
On June 16th, 2021, the BLADE Framework was formally released as an open source framework. Its goal being to provide all defenders with a tool by which to understand and improve their ability to detect and defend against Business Logic Abuse.</p>
2323

2424
<h2>Original Authors</h2>
2525
<ul>

‎_pages/kill-chains.html‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
---
66
{% capture written_label %}'None'{% endcapture %}
77

8-
<p>Kill chains represent the attack lifecycles of specific business logic attacks. They describe the phases of the attack, the order in which the attack progresses through these phases, and the tactics and techniques employed by the adversary in each phase.</p>
9-
<p>The kill chains for common business logic attacks are provided below:</p>
8+
<p>Kill chains represent the abuse lifecycles of specific business logic abuse cases. They describe the phases of the abuse, the order in which the abuse progresses through these phases, and the tactics and techniques employed by the adversary in each phase.</p>
9+
<p>The kill chains for common business logic abuses are provided below:</p>
1010
<!--{% include page__kc.html %}-->
1111
{% include page__glossary.html %}

‎_pages/matrix.html‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
}
3737
</script>
3838

39-
<p>The BLADE Framework matrix depicts the relationship between the phases, tactics and techniques that may be employed by an adversary during a business logic attack.</p>
39+
<p>The BLADE Framework matrix depicts the relationship between the phases, tactics and techniques that may be employed by an adversary during business logic abuse.</p>
4040

4141
<table id="matrix">
4242
<tr>

‎_pages/phases.html‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
---
66
{% capture written_label %}'None'{% endcapture %}
77

8-
<p>Phases describe the distinct stages that a business logic attack may progress through. The specific phases employed by an adversary during an attack and the order in which the attack progresses through them depend on the adversary's goal.</p>
8+
<p>Phases describe the distinct stages that business logic abuse may progress through. The specific phases employed by an adversary during abuse and the order in which the abuse progresses through them depend on the adversary's goal.</p>
99

1010
<table class="blade-table">
1111
<thead>

‎_pages/tactics.html‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
---
66
{% capture written_label %}'None'{% endcapture %}
77

8-
<p>Tactics describe the strategies that may be employed by adversaries during specific phases of business logic attacks. They are the high level activities that the adversary performs during each phase.</p>
8+
<p>Tactics describe the strategies that may be employed by adversaries during specific phases of business logic abuse. They are the high level activities that the adversary performs during each phase.</p>
99

1010
<table class="blade-table">
1111
<thead>

‎_pages/techniques.html‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
---
66
{% capture written_label %}'None'{% endcapture %}
77

8-
<p>Techniques detail the specific actions or methods that may be employed by adversaries during business logic attacks. They are the low level activies that the adversary performs to achieve their tactical goal.</p>
8+
<p>Techniques detail the specific actions or methods that may be employed by adversaries during business logic abuse. They are the low level activities that the adversary performs to achieve their tactical goal.</p>
99

1010
<table class="blade-table">
1111
<thead>

0 commit comments

Comments
 (0)