Skip to content

Latest commit

 

History

History
352 lines (270 loc) · 9.97 KB

File metadata and controls

352 lines (270 loc) · 9.97 KB

Security Implementation Guide

This document describes the security features implemented in Little ISMS Helper, following OWASP Top 10 guidelines and Symfony best practices.

OWASP Top 10 2021 Coverage

A01:2021 – Broken Access Control ✅

Implementation:

  • Voters for fine-grained access control:

    • DocumentVoter - Document access control with multi-tenancy
    • AssetVoter - Asset access control with multi-tenancy
    • RiskVoter - Risk access control with multi-tenancy
    • IncidentVoter - Incident access control with multi-tenancy
    • ControlVoter - Control access control with multi-tenancy
    • ComplianceInheritanceVoter - Compliance inheritance access control
    • EntityVoter - Generic entity access control
    • PermissionVoter - Permission management access control
    • RoleVoter - Role management access control
    • TagVoter - Tag access control
    • UserVoter - User management access control
  • Authorization checks:

    • #[IsGranted('ROLE_USER')] on all controllers
    • $this->denyAccessUnlessGranted('view', $entity) for resource-level permissions
    • Multi-tenancy support in all voters

Testing:

# Test voter permissions
bin/console debug:voter AssetVoter

A02:2021 – Cryptographic Failures ✅

Implementation:

  • Enhanced Session Security (config/packages/framework.yaml):

    • cookie_secure: 'auto' - HTTPS only in production
    • cookie_httponly: true - Prevents JavaScript access to session cookie (XSS protection)
    • cookie_samesite: 'lax' - CSRF protection (cookie sent with same-site and top-level navigation requests)
    • gc_maxlifetime: 3600 - Session lifetime: 1 hour
  • Session Fixation Protection (config/packages/security.yaml):

    • Symfony automatically regenerates session ID on successful authentication (built-in protection)
    • invalidate_session: true on logout - Completely invalidates session on logout
  • Remember Me Cookie Security:

    • secure: auto - HTTPS only in production, HTTP allowed in development
    • httponly: true - No JavaScript access
    • samesite: 'lax' - CSRF protection
    • lifetime: 604800 - 1 week maximum
  • TLS/HTTPS Enforcement:

    • HSTS header with 6 months max-age
    • Automatic HTTP to HTTPS upgrade in CSP policy

A03:2021 – Injection ✅

Implementation:

  1. SQL Injection Prevention:

    • Doctrine ORM with prepared statements
    • Raw SQL limited to backup/restore operations (SET FOREIGN_KEY_CHECKS, batch inserts)
  2. XSS Prevention:

    • Twig auto-escaping enabled (autoescape: 'html')
    • CSP headers in production
    • InputValidationService for additional sanitization
  3. File Upload Injection:

    • FileUploadSecurityService:
      • MIME type validation (server-side via finfo)
      • Magic byte verification
      • Extension whitelist
      • File size limits (10MB)
      • Safe filename generation
  4. Email Header Injection:

    • EmailNotificationService::sanitizeEmailSubject()
    • Removes control characters from email subjects
  5. CSV/Excel Formula Injection:

    • ExcelExportService::sanitizeFormulaInjection()
    • Prefixes dangerous characters with single quote
  6. Path Traversal:

    • DocumentController::download() with realpath validation
    • Filename sanitization

A04:2021 – Insecure Design ✅

Implementation:

  • Rate limiting for brute force prevention:
    • Login: 5 attempts per 15 minutes
    • API: 100 requests per minute
    • Password reset: 3 attempts per hour
    • Document upload: 20 uploads per hour
  • Security event logging for monitoring

A05:2021 – Security Misconfiguration ✅

Implementation:

  • Security headers (SecurityHeadersSubscriber, production only):

    • Content-Security-Policy
    • X-Content-Type-Options: nosniff
    • X-Frame-Options: SAMEORIGIN
    • Strict-Transport-Security (HSTS)
    • Permissions-Policy
    • Referrer-Policy
  • Custom error pages (prevents information disclosure):

    • templates/bundles/TwigBundle/Exception/error{403,404,500}.html.twig
  • Production configuration:

    • Session security hardening
    • Error page customization

A06:2021 – Vulnerable and Outdated Components

Recommendations:

# Regular dependency updates
composer update
composer audit

# Check for security advisories
symfony check:security

A07:2021 – Identification and Authentication Failures ✅

Implementation:

  • Login Rate Limiting (config/packages/rate_limiter.yaml):

    • 5 attempts per 15 minutes
    • Automatic 429 responses when limit exceeded
    • IP-based tracking
  • Session Security (see A02 above):

    • 1-hour session lifetime with garbage collection
    • Secure, HttpOnly, SameSite=lax cookies
    • Session fixation protection (automatic session regeneration on login)
    • Session invalidation on logout
  • Password Security:

    • Automatic bcrypt/argon2 hashing
    • High cost factor for production
    • Password hashing algorithm: auto (uses best available)
  • CSRF Protection:

    • Enabled on all forms (enable_csrf: true)
    • SameSite cookie attribute (lax)
    • Token validation on form submissions

Recommendations:

  • Implement progressive account lockout after failed attempts
  • Add password breach detection (HaveIBeenPwned API)

A08:2021 – Software and Data Integrity Failures ⚠️

Recommendations:

  • Implement Subresource Integrity (SRI) for CDN resources
  • Add code signing for deployments
  • Implement file integrity monitoring

A09:2021 – Security Logging and Monitoring Failures ✅

Implementation:

  • SecurityEventLogger service:

    • Login success/failure
    • Logout events
    • Access denied (authorization failures)
    • File upload success/failure
    • Data modifications (CREATE, UPDATE, DELETE)
    • Rate limit hits
    • Suspicious activity
  • SecurityEventSubscriber:

    • Automatic logging for authentication events
    • Exception logging

Usage:

// In controllers
$this->securityLogger->logFileUpload($filename, $mimeType, $size, $success);
$this->securityLogger->logDataChange('Asset', $id, 'UPDATE', $changes);
$this->securityLogger->logAccessDenied($resource, $action, $user);

Log Location:

  • Development: var/log/dev.log
  • Production: var/log/prod.log

A10:2021 – Server-Side Request Forgery (SSRF) ✅

Implementation:

  • PDF generation: isRemoteEnabled: false (prevents SSRF)
  • URL validation in InputValidationService

Services Overview

FileUploadSecurityService

Comprehensive file upload security:

// Validate file upload
$this->fileUploadSecurity->validateUploadedFile($file);

// Generate safe filename
$safeFilename = $this->fileUploadSecurity->generateSafeFilename($file);

Features:

  • MIME type validation (server-side)
  • Magic byte verification
  • Extension whitelist
  • File size limits
  • Safe filename generation

SecurityEventLogger

Centralized security event logging:

// Log events
$this->securityLogger->logLoginSuccess($user);
$this->securityLogger->logAccessDenied($resource, $action, $user);
$this->securityLogger->logFileUpload($filename, $mimeType, $size, $success);
$this->securityLogger->logSuspiciousActivity($description, $details);

InputValidationService

Input validation and sanitization:

// Validate and sanitize
$email = $this->inputValidation->validateEmail($input);
$int = $this->inputValidation->validateInteger($input);
$safeFilename = $this->inputValidation->sanitizeFilename($filename);
$safeHtml = $this->inputValidation->sanitizeHtml($html);

// Detect attacks
if ($this->inputValidation->detectXssPatterns($input)) {
    // Log and reject
}

Security Headers (Production Only)

All security headers are automatically applied in production environment:

  • CSP: Restricts resource loading
  • HSTS: Forces HTTPS (6 months)
  • X-Frame-Options: Prevents clickjacking
  • X-Content-Type-Options: Prevents MIME sniffing
  • Permissions-Policy: Restricts browser features

Testing Security

Manual Testing

  1. File Upload:
# Try uploading malicious files
curl -F "file=@malicious.php.jpg" http://localhost/document/new
  1. Access Control:
# Try accessing other tenant's resources
curl -H "Cookie: PHPSESSID=..." http://localhost/asset/1
  1. Rate Limiting:
# Try brute forcing login
for i in {1..10}; do curl -X POST http://localhost/login; done

Automated Testing

# Run security audit
composer audit

# Check for vulnerabilities
symfony check:security

# Run tests with coverage
php bin/phpunit --coverage-html coverage/

Deployment Checklist

Before deploying to production:

  • Enable HTTPS
  • Configure proper session storage (Redis/Memcached)
  • Set up log rotation
  • Configure monitoring and alerting
  • Test all security headers
  • Verify error pages
  • Test file upload restrictions
  • Verify rate limiting works
  • Test access control for all resources
  • Enable security event logging monitoring

Incident Response

If a security incident is detected:

  1. Check logs:
tail -f var/log/prod.log | grep SECURITY
  1. Identify affected users:
SELECT * FROM audit_log WHERE created_at > 'incident_time';
  1. Block attacker:
# config/packages/rate_limiter.yaml
# Reduce limits temporarily
  1. Review security events:
grep "SUSPICIOUS_ACTIVITY\|ACCESS_DENIED" var/log/prod.log

Future Enhancements

Priority improvements:

  1. ✅ Multi-Factor Authentication (MFA) - IMPLEMENTED
  2. ✅ Password complexity requirements - IMPLEMENTED (PasswordPolicyResolver)
  3. Account lockout mechanism
  4. IP whitelisting for admin panel
  5. API authentication (JWT/OAuth)
  6. ✅ Enhanced audit logging (database) - IMPLEMENTED
  7. Real-time security monitoring
  8. Automated vulnerability scanning

References