Robert Hurlbut -- Threat Modeling episode artwork

EPISODE · Sep 19, 2017 · 47 MIN

Robert Hurlbut -- Threat Modeling

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you find security problems in a design before they become expensive changes to running software? In this recorded conference presentation, Robert Hurlbut explains threat modeling as a collaborative way to understand a system, identify threats, choose mitigations, and follow through on the results. He distinguishes threats from vulnerabilities, connects security work to business goals, and shows why developers, testers, architects, and stakeholders all belong in the conversation. Robert covers data flow diagrams, trust boundaries, attack trees, threat libraries, and card games that help teams ask better questions. A configuration-file example makes the process concrete. The talk closes with risk decisions, documenting requirements and defects, and revisiting the model as the application changes.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Robert Hurlbut:→ Robert Hurlbut→ Robert’s threat modeling resourcesMentioned in this episode:→ CAPEC→ OWASP ASVS→ OWASP Proactive Controls→ Elevation of Privilege→ Attack Trees (Schneier)→ Microsoft Threat Modeling Tool→ OWASP CornucopiaFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling for secure software design00:50 Why secure design matters06:51 Design flaws and the connected-car example09:47 Threats, business goals, and collaborative modeling21:00 Diagrams, trust boundaries, and identifying threats33:22 Threat modeling games and practical questions37:00 The configuration-file trust problem38:28 Choosing mitigations and evaluating risk42:15 Documenting findings and following through

Episode metadata supplied by the publisher feed · Published Sep 19, 2017

Embed this episode

How do you find security problems in a design before they become expensive changes to running software? In this recorded conference presentation, Robert Hurlbut explains threat modeling as a collaborative way to understand a system, identify threats, choose mitigations, and follow through on the results. He distinguishes threats from vulnerabilities, connects security work to business goals, and shows why developers, testers, architects, and stakeholders all belong in the conversation. Robert...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Robert Hurlbut -- Threat Modeling

0:00 47:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 47 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 19, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!