-
Notifications
You must be signed in to change notification settings - Fork 0
/
TODO
46 lines (36 loc) · 1.4 KB
/
TODO
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
*N*E*W*
Configurable tree drawing parameters.
-----
SB - see below
01.07.2019
DONE: direct cost in the pareto frontier dots
DONE: BUG: invalid value in "Max flow to the target: 0.0035"
WIP: justification of the flows (categories of easiness of exploitation) and costs
WIP: patching as a control (SQL injection for example)
08.07.2019
recovery controls (as a tool feature) (how?)
SB: iterative optimisation (for spending all the budgets)
? WIP: CVSS (CVE score system)
? hackmageddon.com
before 12.08.2019
SB: iterative optimisation gives the same results as noniterative??
done: selectable controls
done: initial flows from the case study
done: refactoring
12.08.2019
DONE: Basic as default Password Policy
target impacts selectable in the tool
web user -> root - weak admin password!
write in todo about use cases - highest point of return on the pareto frontier
SB: iterative optimisation - wait for checked math results
before 02.09.2019
SB: Should pentesting and automated analysis stack??
02.09.2019
DONE: Constant -> Bound {indirect ,}cost
DONE: doubled portfolios on pareto frontier (floating point inaccuracy)
high pentesting includes automated analysis
SB: iterative optimisation: turn off edges connected to the target keeping everything connected earlier on!
before 09.09.2019
iterative optimisation saga: talk through the new algorithm
O(|E|) optimisations
step added for pareto, progress bar, default target