EPISODE · Feb 1, 2019 · 47 MIN
Geoff Hill -- Rapid Threat Model Prototyping Process
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about inconsistent diagrams, trust boundaries, and developer judgment. They also explore automation using diagram metadata and threat libraries. The result is a detailed look at making threat modeling fast enough to support a real design conversation while retaining the context needed to identify meaningful risks.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Geoff Hill:→ Geoff Hill on LinkedIn→ Rapid Threat Model Prototyping slidesMentioned in this episode:→ Rapid Threat Model Prototyping documentation→ Microsoft Security Development Lifecycle→ MITRE CAPECFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Rapid threat model prototyping with Geoff Hill05:06 The scaling problem behind the approach08:45 STRIDE, DREAD, and traditional diagrams11:19 When threat modeling falls behind the sprint15:15 The just-in-time, 80/20 philosophy16:54 Using the team’s existing design19:03 Handling inconsistent and incomplete diagrams22:50 Prioritizing access control and system boundaries26:17 Ranking components by criticality29:28 Rules for authorization and privilege boundaries33:10 Using the developers’ knowledge of the system35:17 Spoofing and trust-zone rules37:20 Tampering and repudiation39:53 Information disclosure and denial of service41:26 Automating analysis from diagram metadata42:46 Adding a library of threats44:44 Where to learn more
Embed this episode
What this episode covers
What happens when a threat model takes days to produce but the development team has already moved on? Geoff Hill describes the scaling problems that led him to Rapid Threat Model Prototyping, an approach that starts with the team’s existing design instead of a separate diagram built for security. He explains its just-in-time philosophy, how to rank components by criticality, and how simple rules reveal likely access-control and STRIDE issues. Chris challenges the approach with questions about...
Ready to play
Geoff Hill -- Rapid Threat Model Prototyping Process
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.