Geoff Hill -- Rapid Threat Model Prototyping Process episode artwork

EPISODE · Feb 1, 2019 · 47 MIN

Geoff Hill -- Rapid Threat Model Prototyping Process

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about inconsistent diagrams, trust boundaries, and developer judgment. They also explore automation using diagram metadata and threat libraries. The result is a detailed look at making threat modeling fast enough to support a real design conversation while retaining the context needed to identify meaningful risks.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Geoff Hill:→ Geoff Hill on LinkedIn→ Rapid Threat Model Prototyping slidesMentioned in this episode:→ Rapid Threat Model Prototyping documentation→ Microsoft Security Development Lifecycle→ MITRE CAPECFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Rapid threat model prototyping with Geoff Hill05:06 The scaling problem behind the approach08:45 STRIDE, DREAD, and traditional diagrams11:19 When threat modeling falls behind the sprint15:15 The just-in-time, 80/20 philosophy16:54 Using the team’s existing design19:03 Handling inconsistent and incomplete diagrams22:50 Prioritizing access control and system boundaries26:17 Ranking components by criticality29:28 Rules for authorization and privilege boundaries33:10 Using the developers’ knowledge of the system35:17 Spoofing and trust-zone rules37:20 Tampering and repudiation39:53 Information disclosure and denial of service41:26 Automating analysis from diagram metadata42:46 Adding a library of threats44:44 Where to learn more

Episode metadata supplied by the publisher feed · Published Feb 1, 2019

Embed this episode

What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Geoff Hill -- Rapid Threat Model Prototyping Process

0:00 47:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 47 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 1, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!