EPISODE · Jun 27, 2017 · 31 MIN
Mike Goodwin -- The OWASP Threat Dragon
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Threat modeling is easier to adopt when its tools fit the way developers already work. Mike Goodwin joins Chris and Robert to introduce the early OWASP Threat Dragon project and explain why he wanted an accessible alternative to tools tied to a single operating system. They walk through creating diagrams, recording threats, and keeping models alongside application code in GitHub. Mike describes his plans for automated threat suggestions, workflow integration, and reminders that keep models from becoming stale. The discussion also considers collaboration, combining feature-level models, and what new users need to understand about STRIDE. This archive conversation documents the project’s initial ambitions and invites developers to help shape a simpler, more integrated approach to threat modeling.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mike Goodwin:→ Mike Goodwin on GitHub→ OWASP Threat DragonMentioned in this episode:→ Threat Dragon source code→ Microsoft Threat Modeling ToolFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Mike Goodwin and OWASP Threat Dragon01:19 A cloud migration sparks an interest in security02:59 What Threat Dragon is designed to do04:31 Why build another threat modeling tool?06:17 The limitations of a Windows-only workflow07:17 Creating a model in Threat Dragon12:15 Threat generation and future capabilities13:39 Keeping threat models beside code in GitHub15:50 Connecting models to developer workflows20:18 What organizations need from modeling tools21:30 Concurrent editing and combining models24:02 STRIDE and the knowledge new users need25:00 The early roadmap toward beta and version one27:18 Giving feedback and contributing
Embed this episode
What this episode covers
Threat modeling is easier to adopt when its tools fit the way developers already work. Mike Goodwin joins Chris and Robert to introduce the early OWASP Threat Dragon project and explain why he wanted an accessible alternative to tools tied to a single operating system. They walk through creating diagrams, recording threats, and keeping models alongside application code in GitHub. Mike describes his plans for automated threat suggestions, workflow integration, and reminders that keep models fr...
Ready to play
Mike Goodwin -- The OWASP Threat Dragon
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.