本文へ移動

概要に戻る

AV-2 Integrated Dictionary

Architecture data repository with definitions of all terms used throughout the architecture data and presentations.

ビューポイント: All Viewpoint · https://mithril.fund/ontology/dm2/2.02/views#AV-2

このモデルでの Mithril

種類 DM2 クラス 件数 根拠
運営者 Organization 1 DM2 Organization: "A specific real-world assemblage of people and other resources organized for an on-going purpose." The named public operator of mithril.fund is one specific company, an individual — not a type.
法人(twin) Organization 3 DM2 Organization (an individual). The enterprise twin's LegalEntity / OperatorOrg records are specific legal persons, each with its own jurisdiction.
組織アカウント Organization 0 DM2 Organization (an individual): each registered org is one did:webvh organization (com-<handle>.kotoba.cloud) with members.
製品ベンダー Organization 272 DM2 Organization (an individual): each product record names the company that provides it.
VC ファンド Organization 8 DM2 Organization (an individual): each fund record is one named firm with its own source URL.
投資先企業 Organization 6 DM2 Organization (an individual): each record is one named company.
法務機関 Organization 37 DM2 Organization (an individual): courts, agencies, bar associations and prosecutors are specific bodies organized for an on-going purpose.
脅威アクター Organization 176 DM2 Organization (an individual): an ATT&CK intrusion set is reported as one specific group of people acting for an on-going purpose. The record is a reported association, not an attribution made here.
過去のランサムウェア集団 Organization 219 DM2 Organization (an individual): each Ransomwatch record names one group. The records are historical and unconfirmed, as the catalog labels them.
組織の種類(アカウント) OrganizationType 1 DM2 OrganizationType: "A type of Organization." Every Mithril organization account has the same shape (roles, did:webvh, membership VCs); that shape is the type, the registered orgs its members.
組織の種類(カタログ) OrganizationType 4 DM2 OrganizationType: the catalogs group organizations by kind (VC fund, portfolio company, intrusion set, historical group); each kind is a type of Organization.
参照組織モデル OrganizationType 1 DM2 OrganizationType: orgbrain's ontology describes a kind of company (its roles, authorities, processes) that a customer's org is compared against — a type, not a particular company.
組織ロール PersonRoleType 4 DM2 PersonRoleType: "A category of person roles defined by the role or roles they share that are relevant to an architecture." owner / admin / member / billing are categories of person roles; DM2 has no plain PersonRole class, and no individual person is published.
職務ロール(orgbrain) PersonRoleType 8 DM2 PersonRoleType: CEO, CFO, IT Admin … are categories of person roles in the reference model (with a minimum headcount), not individuals.
業務プロセス Activity 6 DM2 Activity: "Work, not specific to a single organization, weapon system or individual that transforms inputs (Resources) into outputs (Resources) or changes their state." Each BPMN process is such work, defined for the reference organization.
プロセスのタスク Activity 39 DM2 Activity: each BPMN task is a unit of work, part of its process.
RACI タスク Activity 15 DM2 Activity: each RACI task (annual budget, payroll run …) is recurring work with a responsible role.
攻撃手法 Activity 498 DM2 Activity: an ATT&CK technique is reported adversary work that changes the state of the systems it acts on; it is not specific to one group.
権限 Rule 6 DM2 Rule: "A principle or condition that governs behavior; a prescribed guide for conduct or action." An authority (approve-spend, sign-contract …) is the condition under which a task may be done.
セキュリティサービス Service 8 DM2 Service: "A mechanism to enable access to a set of one or more capabilities, where the access is provided using a prescribed interface and is exercised consistent with constraints and policies as specified by the service description." Each of the eight services is offered through a documented interface with stated capabilities.
サービスの API 窓口 ServicePort 3 DM2 ServicePort: "A part of a Performer that specifics a interaction component through which the Performer interacts with other Performers." POST /v1/security/govern | respond | recover are those interaction points.
外部サービス Service 2 DM2 Service: Stripe (billing) and Cloudflare (Workers, R2, Durable Objects, custom domains) are mechanisms giving Mithril access to capabilities through prescribed interfaces.
ケイパビリティ Capability 31 DM2 Capability: "The ability to achieve a Desired Effect under specified [performance] standards and conditions through combinations of ways and means [activities and resources] to perform a set of activities." Each service lists the abilities it provides.
Mithril プラットフォーム System 1 DM2 System: "A functionally, physically, and/or behaviorally related group of regularly interacting or interdependent elements." Mithril as a whole: the Workers, data stores and security products that serve mithril.fund.
Worker System 5 DM2 System: each Cloudflare Worker is a deployed group of interacting code, bindings and routes.
データストア System 4 DM2 System: an R2 bucket or a Durable Object class is a group of storage elements that a Worker regularly interacts with.
セキュリティ製品 System 10 DM2 System: each Mithril security product (EDR, SIEM, CMDB …) is a group of engines, rules and an API that work together.
市場の製品 System 374 DM2 System: each catalogued commercial product (a scanner, an EDR suite …) is a system; the catalog records what it is, not how it performs.
製品カテゴリ SystemType 45 DM2 SystemType: "The Powertype of System." A category such as edr-xdr is a set of systems; its members are the products filed under it.
常駐ボット System 2 DM2 System: a Hermes profile is a model, tools, schedule and memory working together to act for the repository (support inbox, security watch).
クラウドエージェント System 0 DM2 System: a desktop agent backed up to /v1/agents is persona, memory and model working together. The records belong to their owners and are never published, so there are no public instances.
実行時コントロール Rule 2 DM2 Rule: "A principle or condition that governs behavior." A rate limit or the Biscuit root-key check governs what the edge admits.
標準・フレームワーク Standard 7 DM2 Standard: "A formal agreement documenting generally accepted specifications or criteria for products, processes, procedures, policies, systems, and/or personnel." ISO/IEC 27001, SOC 2, PCI DSS, NIST CSF 2.0, CIS Controls, CSA CCM, ISO/IEC 27701.
規制 Rule 9 DM2 Rule: a regulation (GDPR, HIPAA, DORA, APPI …) or a government authorization program (FedRAMP) is a prescribed guide for conduct issued by an authority, not a consensus standard.
CSF 2.0 サブカテゴリ Guidance 106 DM2 Guidance: "An authoritative statement intended to lead or steer the execution of actions." A CSF 2.0 subcategory is an outcome statement NIST publishes to steer practice; it is part of the CSF standard.
法令 Rule 4 DM2 Rule: a statute or regulation (GDPR, NIS2, APPI, PDPA) is a prescribed guide for conduct.
条約 Agreement 1 DM2 Agreement: "A consent among parties regarding the terms and conditions of activities that said parties participate in." The Budapest Convention is agreed among its parties.
法務コーパス内の標準 Standard 1 DM2 Standard: the legal corpus files NIST CSF 2.0 as a framework — a formal, generally accepted specification.
セキュリティ仕様 Standard 1 DM2 Standard: SCAP is a published family of specifications for exchanging configuration and vulnerability information.
法令・判例コーパス Information 9 DM2 Information: "the state of a something of interest that is materialized -- in any medium or form -- and communicated or received." A legislation portal or case-law database is a body of published information, not itself a rule.
制裁リスト Information 9 DM2 Information: each list is a published body of designations (a CSV, XML or web page). The prohibition it carries is the issuing authority's regulation, which the catalog does not record — so the list is Information, not Rule. Aggregators (OpenSanctions) publish lists too.
監査ログ Data 1 DM2 Data: "Representation of information in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means." A lab audit log is machine-readable records.
脅威モデル Information 1 DM2 Information: an authored threat-model scenario template is information about a situation; the catalog marks it as not evidence of an attack.
公開データセット Data 8 DM2 Data: each catalog Mithril publishes (JSON blocks, JSON-LD, datoms) is information formalized for processing by automatic means.
来歴情報 PedigreeInformation 8 DM2 PedigreeInformation: "Information describing pedigree." Each dataset's provenance — the source URLs, evidence layers, fetch dates, upstream commits and file hashes it records, and prov:wasDerivedFrom on every security-data claim — is its pedigree.
アーキテクチャ記述 ArchitecturalDescription 53 DM2 ArchitecturalDescription: "Information describing an architecture such as an OV-5 Activity Model document." Each page of this architecture surface, and the JSON-LD, describes Mithril's architecture.
DoDAF モデル ArchitecturalDescriptionType 52 DM2 ArchitecturalDescriptionType: "The Powertype of ArchitecturalDescription." Each of the 52 official models (AV-1 … DIV-3) is a kind of architectural description; the page for it is an instance.
国 Country 5 DM2 Country: "A political state or nation or its territory."
政治的領域 GeoPoliticalExtent 2 DM2 GeoPoliticalExtent: "A geospatial extent whose boundaries are by declaration or agreement by political parties." The EU and the EEA are extents by agreement, not countries.
論理的な場所 Location 1 DM2 Location: "A point or extent in space that may be referred to physically or logically." The Cloudflare global edge, the twin's worker jurisdiction, is logical, not geopolitical.

5 件の種類は、このモデルが挙げていない DM2 クラスに対応します。全体は概要の統合辞書にあります。 統合辞書 — サイトのマッピング

Mithril に実例がある概念

概念 コード 件数 例
Activity o 558
  • 契約審査ライフサイクル
  • インシデントエスカレーションライフサイクル
  • 法人設立・組織変更
  • 請求・支払ライフサイクル
  • アクセス権プロビジョニングライフサイクル
  • 入退社ライフサイクル
  • 契約書ドラフト作成
  • 法務・条項審査
  • 財務条件審査
  • CEO 契約承認
  • 契約締結
  • 契約書保管
  • ほか 546 件(すべては JSON-LD に)
Agreement o 1
  • Budapest Convention on Cybercrime (ETS 185)
ArchitecturalDescription o 53
  • Mithril architecture — DoDAF 2.02 (overview)
  • AV-1 Overview and Summary Information — Mithril
  • AV-2 Integrated Dictionary — Mithril
  • OV-1: High Level Operational Concept Graphic — Mithril
  • OV-2: Operational Connectivity Description — Mithril
  • OV-3: Operational Resource Flow Matrix — Mithril
  • OV-4: Organizational Relationships Chart — Mithril
  • OV-5a: Activity Decomposition Tree — Mithril
  • OV-5b: Activity Model — Mithril
  • OV-6a: Operational Rules Model — Mithril
  • OV-6b: State Transition Description — Mithril
  • OV-6c: Event-Trace Description — Mithril
  • ほか 41 件(すべては JSON-LD に)
ArchitecturalDescriptionType o 52
  • AV-1 Overview and Summary Information
  • AV-2 Integrated Dictionary
  • OV-1: High Level Operational Concept Graphic
  • OV-2: Operational Connectivity Description
  • OV-3: Operational Resource Flow Matrix
  • OV-4: Organizational Relationships Chart
  • OV-5a: Activity Decomposition Tree
  • OV-5b: Activity Model
  • OV-6a: Operational Rules Model
  • OV-6b: State Transition Description
  • OV-6c: Event-Trace Description
  • SV-1 Systems Interface Description
  • ほか 40 件(すべては JSON-LD に)
Capability o 31
  • continuous external attack-surface and asset inventory
  • reachable attack-path identification
  • asset context (public routes, dependencies, owner)
  • exposure events fed to the VM ledger
  • dynamic probing of running applications
  • probing with authenticated scenarios
  • runtime vulnerability detection as findings
  • static source-code analysis
  • taint / data-flow inspection
  • code findings with file and line
  • dependency-manifest inspection, emitting dependency notes
  • header verification on received mail (SPF / DKIM / DMARC alignment)
  • ほか 19 件(すべては JSON-LD に)
Country o 5
  • Australia
  • Japan
  • Ukraine
  • United Kingdom
  • United States
Data o 9
  • Arp Cache Discovery — 公開ラボ監査ログ
  • VC fund catalog
  • Compliance standards catalog
  • Sanctions watchlist catalog
  • Legal data catalog
  • Public security knowledge
  • Enterprise digital twin
  • orgbrain reference organization
  • NIST CSF 2.0 catalog
GeoPoliticalExtent df 2
  • European Economic Area
  • European Union
Guidance df 106
  • DE.AE-02 — Potentially adverse events are analyzed to better understand associated activities
  • DE.AE-03 — Information is correlated from multiple sources
  • DE.AE-04 — The estimated impact and scope of adverse events are understood
  • DE.AE-06 — Information on adverse events is provided to authorized staff and tools
  • DE.AE-07 — Cyber threat intelligence and other contextual information are integrated into the analysis
  • DE.AE-08 — Incidents are declared when adverse events meet the defined incident criteria
  • DE.CM-01 — Networks and network services are monitored to find potentially adverse events
  • DE.CM-02 — The physical environment is monitored to find potentially adverse events
  • DE.CM-03 — Personnel activity and technology usage are monitored to find potentially adverse events
  • DE.CM-06 — External service provider activities and services are monitored to find potentially adverse events
  • DE.CM-09 — Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • GV.OC-01 — The organizational mission is understood and informs cybersecurity risk management
  • ほか 94 件(すべては JSON-LD に)
Information dfo 19
  • EUR-Lex — EU 官報・連合法源ポータル
  • CourtListener / RECAP — US 連邦裁判例・ドocket コーパス
  • CanLII — カナダ判例・法源コーパス
  • AustLII — オーストラリア法情報研究所 (判例・法源コーパス)
  • Canada Justice Laws Website (カナダ連邦法令ポータル)
  • NZLII — ニュージーランド法情報研究所 (判例・法源コーパス)
  • Singapore Statutes Online — シンガポール法令公式ポータル (AGC Legislation Division 運営)
  • HUDOC — 欧州人権裁判所 (ECtHR) 判例データベース
  • Singapore Law Watch — 判例・法務ポータル (Singapore Academy of Law 運営)
  • US Treasury OFAC SDN List
  • UN Security Council Consolidated List
  • EU Financial Sanctions Database
  • ほか 7 件(すべては JSON-LD に)
Location dfo 1
  • Cloudflare global edge
Organization o 722
  • Kotoba Labs Inc.
  • cloud-kotoba (kotoba.cloud operator)
  • AWAI Network, L.L.C. (Delaware)
  • kotoba-lang (language substrate)
  • 1Password (AgileBits)
  • 42Crunch
  • ANY.RUN
  • AT&T Cybersecurity
  • AWS
  • Abnormal Security
  • Acronis
  • Akamai
  • ほか 710 件(すべては JSON-LD に)
OrganizationType o 6
  • Mithril organization account
  • VC fund
  • Portfolio company
  • ATT&CK intrusion set
  • Historical ransomware group (Ransomwatch)
  • orgbrain reference organization
PedigreeInformation dfo 8
  • Pedigree of VC fund catalog — 8 funds each with source-url (8 primary-fetched); 6 companies with sourced rounds
  • Pedigree of Compliance standards catalog — 16 of 16 frameworks with source-url
  • Pedigree of Sanctions watchlist catalog — 9 source lists with issuing authority and URL (6 declared-2026-03, 3 primary-fetched)
  • Pedigree of Legal data catalog — 52 records each with source-url (37 primary-fetched, 15 secondary-reported)
  • Pedigree of Public security knowledge — every claim carries prov:wasDerivedFrom one of 7 archived sources (CISA, MITRE, NIST, OTRF, OTRF, joshhighet/ransomwatch, Kotoba); snapshot baguqeera6fji5y3mgsvalio2cz7ca6kxlhojidwtsuqwx6klgf3wycr2gpca, 2026-09-13T23:53:34.337Z
  • Pedigree of Enterprise digital twin — every instance cites an in-repo source (2026-09-18T00:00:00+09:00)
  • Pedigree of orgbrain reference organization — kotoba-lang/kyber@055c94b00d71, 7 files pinned by sha256
  • Pedigree of NIST CSF 2.0 catalog — 106 subcategories from NIST CSWP 29 (2024-02-26, https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf)
PersonRoleType o 12
  • owner
  • admin
  • member
  • billing
  • CEO
  • CFO
  • COO
  • CTO
  • HR Manager
  • Finance Staff
  • IT Admin
  • board
Rule dfo 21
  • approve-spend
  • sign-contract
  • hire
  • fire
  • compliance
  • it-admin
  • SUPPORT_RATE_LIMIT 10/min per client address (503 by name on miss)
  • POST /v1/invoke verifies Biscuits against pinned root public key; absent key refuses every invocation by name
  • GDPR (EU 2016/679)
  • CCPA / CPRA (Cal. Civ. Code 1798)
  • FedRAMP (NIST SP 800-53 Rev.5 baseline)
  • HIPAA Security Rule (45 CFR 164 Subpart C)
  • ほか 9 件(すべては JSON-LD に)
Service o 10
  • CTEM
  • DAST
  • SAST
  • SPECT
  • VM
  • GRC
  • IR
  • DR
  • Stripe (live billing, AWAI account)
  • Cloudflare Workers / R2 / DO / custom domains
ServicePort o 3
  • POST /v1/security/govern
  • POST /v1/security/respond
  • POST /v1/security/recover
Standard df 9
  • ISO/IEC 27001:2022
  • SOC 2 (Type I / Type II)
  • PCI DSS 4.0
  • NIST Cybersecurity Framework 2.0
  • CIS Controls v8.1
  • ISO/IEC 27701:2019 (privacy extension)
  • CSA Cloud Controls Matrix v4
  • NIST Cybersecurity Framework 2.0
  • SCAP — 構成・脆弱性情報を交換する仕様群
System o 396
  • Mithril (mithril.fund)
  • kotoba-cloud-control-plane
  • kotoba-identity-authority
  • kotoba-research-authority
  • kotoba-cloud-database
  • kotobase-authn
  • R2 kotobase-graph-database-production (PUBLIC_BLOCKS)
  • R2 internal-security-nvd (NVD_BLOCKS, read-only allow-listed keys)
  • Durable Object PqKeyRegistry (SQLite, post-quantum key registry)
  • Durable Object BillingAccount (SQLite)
  • EDR / XDR
  • CMDB / 資産台帳
  • ほか 384 件(すべては JSON-LD に)
SystemType o 45
  • Vulnerability Assessment / VM
  • Attack Surface Management / EASM
  • Patch Management
  • Penetration Testing / PTaaS
  • Bug Bounty / Crowdsourced Testing
  • EDR / XDR
  • NDR / Network Detection
  • SIEM / Log Analytics
  • SOAR / Orchestration
  • Threat Intelligence
  • SBOM / VEX
  • AppSec (SAST/DAST/SCA)
  • ほか 33 件(すべては JSON-LD に)

関係

概念 コード 件数 例
WholePartType ifo 164
  • 契約審査ライフサイクル → 契約書ドラフト作成
  • 契約審査ライフサイクル → 法務・条項審査
  • 契約審査ライフサイクル → 財務条件審査
  • 契約審査ライフサイクル → CEO 契約承認
  • 契約審査ライフサイクル → 契約締結
  • 契約審査ライフサイクル → 契約書保管
  • インシデントエスカレーションライフサイクル → インシデント検知・トリアージ
  • インシデントエスカレーションライフサイクル → 指揮本部設立・指揮官任命
  • ほか 156 件(すべては JSON-LD に)
couple if 657
  • CTEM → VM (site:feedsFindingsTo)
  • DAST → VM (site:feedsFindingsTo)
  • SAST → VM (site:feedsFindingsTo)
  • SPECT → VM (site:feedsFindingsTo)
  • IR → DR (site:handsOffTo)
  • CTEM → Threat Intelligence (site:coversCategory)
  • CTEM → CSPM / CNAPP (site:coversCategory)
  • CTEM → Vulnerability Assessment / VM (site:coversCategory)
  • ほか 649 件(すべては JSON-LD に)
describedBy dfo 69
  • CTEM → CTEM — /security/services/
  • DAST → DAST — /security/services/
  • SAST → SAST — /security/services/
  • SPECT → SPECT — /security/services/
  • VM → VM — /security/services/
  • GRC → GRC — /security/services/
  • IR → IR — /security/services/
  • DR → DR — /security/services/
  • ほか 61 件(すべては JSON-LD に)
individualResourceInLocation o 3
  • Japan → cloud-kotoba (kotoba.cloud operator)
  • Delaware → AWAI Network, L.L.C. (Delaware)
  • Japan → kotoba-lang (language substrate)
servicePortDescribedBy o 3
  • POST /v1/security/govern → GRC — /security/services/
  • POST /v1/security/respond → IR — /security/services/
  • POST /v1/security/recover → DR — /security/services/
typeInstance ifo 891
  • exposure management → continuous external attack-surface and asset inventory
  • exposure management → reachable attack-path identification
  • exposure management → asset context (public routes, dependencies, owner)
  • exposure management → exposure events fed to the VM ledger
  • dynamic testing → dynamic probing of running applications
  • dynamic testing → probing with authenticated scenarios
  • dynamic testing → runtime vulnerability detection as findings
  • static analysis → static source-code analysis
  • ほか 883 件(すべては JSON-LD に)
Mithril に実例がない概念 (136)

モデルの概念コード(o・n・np・s・df・dfo・if・ifo)は DoD のワークブックに凡例が公開されていないため、そのまま表示し、意味づけはしていません。