
Geoff Hill -- Rapid Threat Model Prototyping Process
Om avsnittet
What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about inconsistent diagrams, trust boundaries, and developer judgment. They also explore automation using diagram metadata and threat libraries. The result is a detailed look at making threat modeling fast enough to support a real design conversation while retaining the context needed to identify meaningful risks.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Geoff Hill:
→ Geoff Hill on LinkedIn
→ Rapid Threat Model Prototyping slides
Mentioned in this episode:
→ Rapid Threat Model Prototyping documentation
→ Microsoft Security Development Lifecycle
→ MITRE CAPEC
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Rapid threat model prototyping with Geoff Hill
05:06 The scaling problem behind the approach
08:45 STRIDE, DREAD, and traditional diagrams
11:19 When threat modeling falls behind the sprint
15:15 The just-in-time, 80/20 philosophy
16:54 Using the team’s existing design
19:03 Handling inconsistent and incomplete diagrams
22:50 Prioritizing access control and system boundaries
26:17 Ranking components by criticality
29:28 Rules for authorization and privilege boundaries
33:10 Using the developers’ knowledge of the system
35:17 Spoofing and trust-zone rules
37:20 Tampering and repudiation
39:53 Information disclosure and denial of service
41:26 Automating analysis from diagram metadata
42:46 Adding a library of threats
44:44 Where to learn more
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.