EPISODE · Nov 8, 2016 · 38 MIN
Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A useful threat model should explain how an attacker could harm the business, not just complete a checklist. Tony UcedaVélez joins Chris and Robert to introduce PASTA, the Process for Attack Simulation and Threat Analysis, and its risk-centered approach to application security. He explains how business context, threat intelligence, and attacker motivation shape the analysis, then connects those ideas to attack trees and cloud containers. The conversation explores where to find useful threat information, whether attack models can be reused, and how resources such as MITRE CAPEC can support the work. Tony also addresses the challenge of helping developers reason about adversaries. The episode closes with practical advice for making threat modeling an evidence-based part of understanding and protecting a system.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tony UcedaVelez:→ Tony UcedaVélez on LinkedIn→ VerSpriteMentioned in this episode:→ PASTA threat modeling→ Attack Trees (Schneier)→ MITRE CAPEC→ OWASP Threat Modeling Project→ Microsoft Threat Modeling Tool→ DockerFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 PASTA threat modeling with Tony UcedaVélez01:22 Tony’s security origin story05:00 What PASTA adds to threat modeling08:48 Finding relevant threat intelligence12:32 Helping teams reason about adversaries15:07 Moving beyond security checklists18:02 Attack trees and cloud containers20:08 How attack trees describe paths to a goal24:30 Reusing and sharing attack models26:12 Connecting CAPEC and weakness information34:27 Practical steps for risk-centered threat modeling
Embed this episode
What this episode covers
A useful threat model should explain how an attacker could harm the business, not just complete a checklist. Tony UcedaVélez joins Chris and Robert to introduce PASTA, the Process for Attack Simulation and Threat Analysis, and its risk-centered approach to application security. He explains how business context, threat intelligence, and attacker motivation shape the analysis, then connects those ideas to attack trees and cloud containers. The conversation explores where to find useful threat i...
Ready to play
Tony UcedaVelez -- PASTA: Not Just for Breakfast Anymore
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.