Mike Goodwin -- The OWASP Threat Dragon episode artwork

EPISODE · Jun 27, 2017 · 31 MIN

Mike Goodwin -- The OWASP Threat Dragon

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Threat modeling is easier to adopt when its tools fit the way developers already work. Mike Goodwin joins Chris and Robert to introduce the early OWASP Threat Dragon project and explain why he wanted an accessible alternative to tools tied to a single operating system. They walk through creating diagrams, recording threats, and keeping models alongside application code in GitHub. Mike describes his plans for automated threat suggestions, workflow integration, and reminders that keep models from becoming stale. The discussion also considers collaboration, combining feature-level models, and what new users need to understand about STRIDE. This archive conversation documents the project’s initial ambitions and invites developers to help shape a simpler, more integrated approach to threat modeling.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mike Goodwin:→ Mike Goodwin on GitHub→ OWASP Threat DragonMentioned in this episode:→ Threat Dragon source code→ Microsoft Threat Modeling ToolFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Mike Goodwin and OWASP Threat Dragon01:19 A cloud migration sparks an interest in security02:59 What Threat Dragon is designed to do04:31 Why build another threat modeling tool?06:17 The limitations of a Windows-only workflow07:17 Creating a model in Threat Dragon12:15 Threat generation and future capabilities13:39 Keeping threat models beside code in GitHub15:50 Connecting models to developer workflows20:18 What organizations need from modeling tools21:30 Concurrent editing and combining models24:02 STRIDE and the knowledge new users need25:00 The early roadmap toward beta and version one27:18 Giving feedback and contributing

Episode metadata supplied by the publisher feed · Published Jun 27, 2017

Embed this episode

Threat modeling is easier to adopt when its tools fit the way developers already work. Mike Goodwin joins Chris and Robert to introduce the early OWASP Threat Dragon project and explain why he wanted an accessible alternative to tools tied to a single operating system. They walk through creating diagrams, recording threats, and keeping models alongside application code in GitHub. Mike describes his plans for automated threat suggestions, workflow integration, and reminders that keep models fr...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Mike Goodwin -- The OWASP Threat Dragon

0:00 31:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 31 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 27, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!