
Robert Hurlbut -- Threat Modeling
Om avsnittet
How do you find security problems in a design before they become expensive changes to running software? In this recorded conference presentation, Robert Hurlbut explains threat modeling as a collaborative way to understand a system, identify threats, choose mitigations, and follow through on the results. He distinguishes threats from vulnerabilities, connects security work to business goals, and shows why developers, testers, architects, and stakeholders all belong in the conversation. Robert covers data flow diagrams, trust boundaries, attack trees, threat libraries, and card games that help teams ask better questions. A configuration-file example makes the process concrete. The talk closes with risk decisions, documenting requirements and defects, and revisiting the model as the application changes.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Robert Hurlbut:
→ Robert Hurlbut
→ Robert’s threat modeling resources
Mentioned in this episode:
→ CAPEC
→ OWASP ASVS
→ OWASP Proactive Controls
→ Elevation of Privilege
→ Attack Trees (Schneier)
→ Microsoft Threat Modeling Tool
→ OWASP Cornucopia
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Threat modeling for secure software design
00:50 Why secure design matters
06:51 Design flaws and the connected-car example
09:47 Threats, business goals, and collaborative modeling
21:00 Diagrams, trust boundaries, and identifying threats
33:22 Threat modeling games and practical questions
37:00 The configuration-file trust problem
38:28 Choosing mitigations and evaluating risk
42:15 Documenting findings and following through
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.