EPISODE · May 10, 2022 · 46 MIN
Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Can machines make threat modeling faster without stripping away the judgment that makes it useful? Kristen Tan and Vaibhav Garg join Chris and Robert to discuss their analysis of open source automated threat modeling tools and what it reveals about automation, extensibility, security, and privacy. They explain why they studied the available tools, how they evaluated them, and where machine assistance can support rather than replace human reasoning. The conversation covers developer-friendly formats, privacy requirements, organizational fit, and the gap between generating threats and helping real working teams make better design decisions throughout the modern software development lifecycle in practice.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Kristen Tan and Vaibhav Garg:→ Kristen Tan on LinkedIn→ Vaibhav Garg on LinkedInMentioned in this episode:→ Analysis of open source automated threat modeling tools→ OWASP pytmFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Machine-assisted threat modeling01:44 Kristen Tan’s path to threat modeling research03:29 Vaibhav Garg’s security and privacy background06:49 Why analyze automated threat modeling tools09:18 Security and privacy as connected disciplines12:17 What motivated the research14:37 Can machines automate threat modeling?20:45 How the tools were evaluated24:24 Open source tools and extensibility28:59 Evaluation criteria and research results35:14 Choosing a tool that fits the organization37:00 YAML, developers, and usable workflows39:00 Keeping threat modeling user-centered45:00 Final takeaways
Embed this episode
What this episode covers
Can machines make threat modeling faster without stripping away the judgment that makes it useful? Kristen Tan and Vaibhav Garg join Chris and Robert to discuss their analysis of open source automated threat modeling tools and what it reveals about automation, extensibility, security, and privacy. They explain why they studied the available tools, how they evaluated them, and where machine assistance can support rather than replace human reasoning. The conversation covers developer-friendly f...
Ready to play
Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.