Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Geoff Hill -- Rapid Threat Model Prototyping Process

47 min1 februari 2019

Om avsnittet

What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about inconsistent diagrams, trust boundaries, and developer judgment. They also explore automation using diagram metadata and threat libraries. The result is a detailed look at making threat modeling fast enough to support a real design conversation while retaining the context needed to identify meaningful risks.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Geoff Hill:
Geoff Hill on LinkedIn
Rapid Threat Model Prototyping slides

Mentioned in this episode:
Rapid Threat Model Prototyping documentation
Microsoft Security Development Lifecycle
MITRE CAPEC

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Rapid threat model prototyping with Geoff Hill
05:06 The scaling problem behind the approach
08:45 STRIDE, DREAD, and traditional diagrams
11:19 When threat modeling falls behind the sprint
15:15 The just-in-time, 80/20 philosophy
16:54 Using the team’s existing design
19:03 Handling inconsistent and incomplete diagrams
22:50 Prioritizing access control and system boundaries
26:17 Ranking components by criticality
29:28 Rules for authorization and privilege boundaries
33:10 Using the developers’ knowledge of the system
35:17 Spoofing and trust-zone rules
37:20 Tampering and repudiation
39:53 Information disclosure and denial of service
41:26 Automating analysis from diagram metadata
42:46 Adding a library of threats
44:44 Where to learn more

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.