Threat Modeling Made Simple

No ratings

Presented at lascon 2016 by

A key part of protecting the systems we use is knowing the specific threats they face. Many of these may seem obvious, but knowing which systems are vulnerable to which threats is a key part of making sure our protection efforts are effective and efficient. None of us has enough resources to do everything, so we must focus on the defenses that protect us from the most important threats we face. The practice of threat modeling is a key part of doing this. It allows us to find the most likely and most important threats our systems face. These findings can then be ranked, so we can focus on the most important risks first. This class will help you understand what to do to find the threats and then look at the ways to properly mitigate the most important ones. Knowing the terminology and processes will provide a basis for understanding how to effectively use threat modeling. Hands-on exercises will be used throughout the class to reinforce the material and to enhance the research skills needed to find the top threats and the best ways to mitigate them with the resources we have. Class participation will be encouraged whenever possible and each of you can be as active as you wish in the learning process. Learning from peers will also be an important part of the course. Class discussions will follow many activities to give everyone a chance to draw out new insights and reinforce specific points. Topics will include: Basic concepts and how to get started. How to identify which systems need threat modeling. What needs to be known about each system. Flow diagrams and other needed system documentation. Specific ways to find threats – STRIDE and other approaches. How to evaluate threats – DREAD and other methods. Specific threats in many areas. Possible ways to mitigate or even eliminate specific threats. Threat modeling as an ongoing process. Ways to architect, design and implement systems to reduce likely threats. Ways to expand your knowledge of threats and mitigations. Some tools that can help with different parts of the process. Example systems will be provided in the class, but feel free to bring any system you want to work on if you can do so without compromising any sensitive details. The idea will be to put the concepts into practice on real-world systems or ones that look like them. Needed during the class: A laptop or tablet that can be used to make drawings and other documentation. Some type of drawing program. Anything that can draw shapes and connections. A document editing program to track results. Make sure this can output PDF format if you want to share exercise results with the class. Flow diagrams and other functional documentation for any systems you want to use for class exercises. An installed and running copy of the Windows Threat Modeling Tool if possible. (https://www.microsoft.com/en-us/download/details.aspx?id=49168) A willingness to jump in and work with others.