EPISODE · Sep 19, 2017 · 47 MIN
Robert Hurlbut -- Threat Modeling
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How do you find security problems in a design before they become expensive changes to running software? In this recorded conference presentation, Robert Hurlbut explains threat modeling as a collaborative way to understand a system, identify threats, choose mitigations, and follow through on the results. He distinguishes threats from vulnerabilities, connects security work to business goals, and shows why developers, testers, architects, and stakeholders all belong in the conversation. Robert covers data flow diagrams, trust boundaries, attack trees, threat libraries, and card games that help teams ask better questions. A configuration-file example makes the process concrete. The talk closes with risk decisions, documenting requirements and defects, and revisiting the model as the application changes.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Robert Hurlbut:→ Robert Hurlbut→ Robert’s threat modeling resourcesMentioned in this episode:→ CAPEC→ OWASP ASVS→ OWASP Proactive Controls→ Elevation of Privilege→ Attack Trees (Schneier)→ Microsoft Threat Modeling Tool→ OWASP CornucopiaFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling for secure software design00:50 Why secure design matters06:51 Design flaws and the connected-car example09:47 Threats, business goals, and collaborative modeling21:00 Diagrams, trust boundaries, and identifying threats33:22 Threat modeling games and practical questions37:00 The configuration-file trust problem38:28 Choosing mitigations and evaluating risk42:15 Documenting findings and following through
Embed this episode
What this episode covers
How do you find security problems in a design before they become expensive changes to running software? In this recorded conference presentation, Robert Hurlbut explains threat modeling as a collaborative way to understand a system, identify threats, choose mitigations, and follow through on the results. He distinguishes threats from vulnerabilities, connects security work to business goals, and shows why developers, testers, architects, and stakeholders all belong in the conversation. Robert...
Ready to play
Robert Hurlbut -- Threat Modeling
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.