Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore

39 min8 november 2016

Om avsnittet

A useful threat model should explain how an attacker could harm the business, not just complete a checklist. Tony UcedaVélez joins Chris and Robert to introduce PASTA, the Process for Attack Simulation and Threat Analysis, and its risk-centered approach to application security. He explains how business context, threat intelligence, and attacker motivation shape the analysis, then connects those ideas to attack trees and cloud containers. The conversation explores where to find useful threat information, whether attack models can be reused, and how resources such as MITRE CAPEC can support the work. Tony also addresses the challenge of helping developers reason about adversaries. The episode closes with practical advice for making threat modeling an evidence-based part of understanding and protecting a system.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Tony UcedaVelez:
Tony UcedaVélez on LinkedIn
VerSprite

Mentioned in this episode:
PASTA threat modeling
Attack Trees (Schneier)
MITRE CAPEC
OWASP Threat Modeling Project
Microsoft Threat Modeling Tool
Docker

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 PASTA threat modeling with Tony UcedaVélez
01:22 Tony’s security origin story
05:00 What PASTA adds to threat modeling
08:48 Finding relevant threat intelligence
12:32 Helping teams reason about adversaries
15:07 Moving beyond security checklists
18:02 Attack trees and cloud containers
20:08 How attack trees describe paths to a goal
24:30 Reusing and sharing attack models
26:12 Connecting CAPEC and weakness information
34:27 Practical steps for risk-centered threat modeling

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.