EPISODE · Oct 16, 2018 · 30 MIN
Tony UV -- Threat Libraries in the Cloud
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A list of weaknesses is not the same thing as an understanding of the threats facing a business. Tony UV returns to explain how a threat library can connect industry intelligence with evidence from an organization’s own systems. He distinguishes threats, attacks, and vulnerabilities, then describes how cloud logs and configuration signals can add context to a threat model. The conversation examines the feedback loop between modeling, detection, and real incidents, with examples involving sabotage, data loss, and extortion. Tony recommends starting with a manageable set of business concerns, substantiating them with evidence, and mapping the relevant attack paths and technologies. His approach gives teams a way to make threat modeling reflect what could actually harm the operation they support.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tony UcedaVelez:→ Tony UV on LinkedIn→ VerSpriteMentioned in this episode:→ MITRE CAPEC→ MITRE ATT&CK→ AWS CloudTrail→ FS-ISACFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat libraries in the cloud with Tony UV01:16 Continuing the threat modeling conversation02:30 External intelligence and internal evidence05:25 Validating threats in business context08:12 How the library supports a threat model12:09 Cloud platforms as sources of threat context18:13 The feedback loop between models and incidents18:55 Connecting business threats to attack patterns22:23 Starting with a manageable threat library23:14 Beyond STRIDE: evidence, extortion, and business impact
Embed this episode
What this episode covers
A list of weaknesses is not the same thing as an understanding of the threats facing a business. Tony UV returns to explain how a threat library can connect industry intelligence with evidence from an organization’s own systems. He distinguishes threats, attacks, and vulnerabilities, then describes how cloud logs and configuration signals can add context to a threat model. The conversation examines the feedback loop between modeling, detection, and real incidents, with examples involving sabo...
Ready to play
Tony UV -- Threat Libraries in the Cloud
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.