<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Library on PlumePHP</title><link>https://plumephp.com/tags/threat-library/</link><description>Recent content in Threat-Library on PlumePHP</description><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Sat, 26 Sep 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://plumephp.com/tags/threat-library/index.xml" rel="self" type="application/rss+xml"/><item><title>威胁建模与安全评审：从 STRIDE 分析到发布门禁的完整流程</title><link>https://plumephp.com/security-threat-modeling-review/</link><pubDate>Sat, 26 Sep 2026 00:00:00 +0800</pubDate><guid>https://plumephp.com/security-threat-modeling-review/</guid><description>&lt;p&gt;安全漏洞很少是&amp;quot;一个坏函数&amp;quot;造成的，而是&lt;strong&gt;设计层面的缺陷&lt;/strong&gt;——没做输入校验、信任了不存在的边界、遗漏了某个流程环节。威胁建模（Threat Modeling）正是&amp;quot;在设计阶段识别风险&amp;quot;的系统方法：在写代码之前，先画出系统的数据流，逐环节问&amp;quot;这里能被怎样攻击？&amp;quot;，再按风险排序投入防御。本指南从威胁建模方法论出发，系统覆盖 STRIDE 分类、数据流分析、威胁库、攻击树，以及安全评审清单与发布门禁的落地流程。&lt;/p&gt;</description></item></channel></rss>