YouTube2Text

Developing a 'threat modeling mindset' following four steps of the threat modeling process — Transcript

by Threat Modeling Connect · 9,385 words · 1,352 segments · language en · Watch on YouTube

Full transcript

  1. 0:00welcome to the threat modeling Workshop
  2. 0:02developing a threat modeling mindset by
  3. 0:04Robert heret like I said this is
  4. 0:06originally designed for our hackathon
  5. 0:09participants um but we decided to open
  6. 0:11it to all TMC member because it's just
  7. 0:13something too give to not to share with
  8. 0:15a Brer community so whether or not
  9. 0:17you're in the hackathon and we hope we
  10. 0:20believe that this you will find this
  11. 0:22Workshop really really helpful and this
  12. 0:24is a workshop that's been featured in
  13. 0:26many many major security conferences um
  14. 0:29incl our very own F Monon and it's get
  15. 0:32so much great feedback so you're really
  16. 0:34in for a treat um now Robert is offering
  17. 0:38this to all the TNC members so enjoy I'm
  18. 0:41going to introduce Robert herit with our
  19. 0:44speaker and Robert over to you all right
  20. 0:46yeah thanks and welcome everyone uh
  21. 0:48really glad to be here and to uh be able
  22. 0:51to present on developing a threat moding
  23. 0:54mindset as shoing mentioned this is a u
  24. 0:58Workshop that I've done in person at uh
  25. 1:01threat modcon uh at least a couple of
  26. 1:04them in the last two years as well as
  27. 1:06some other places uh this is really u
  28. 1:09based on a presentation I put together a
  29. 1:13few years ago where I was inspired by uh
  30. 1:17this thought of uh security folks have a
  31. 1:21certain mindset they can see things a
  32. 1:23certain way if they see a door open uh
  33. 1:26if they see uh some things that are you
  34. 1:29know ports open and so forth uh they
  35. 1:32have a particular mindset and I thought
  36. 1:34you know threat moding I think uh has a
  37. 1:37mindset as well especially as you learn
  38. 1:40about it and start to apply uh some of
  39. 1:42the process to what you're doing uh then
  40. 1:45you develop that mindset and I think
  41. 1:47anyone can and so that's really the sort
  42. 1:50of the background of uh this uh workshop
  43. 1:54and and turning into a workshop uh
  44. 1:57Beyond a presentation
  45. 2:00so uh what are we going to be doing
  46. 2:01today we're going to be going through uh
  47. 2:03introducing the threat Ming mindset as
  48. 2:05well as walking through the threat
  49. 2:07moding process uh we do have some
  50. 2:10learning and exercises we'll have at
  51. 2:12least a couple of breakout uh
  52. 2:15opportunities uh breakout groups where
  53. 2:17we're going to be meeting uh with a
  54. 2:20number of folks who are uh volunteering
  55. 2:22their time today to help you out uh and
  56. 2:25we're we'll go through some of the
  57. 2:26exercises and then we'll come back
  58. 2:28together we'll talk about some of the
  59. 2:30things that you found and then we'll
  60. 2:32continue on uh but at least going to be
  61. 2:34doing two of those uh today and then at
  62. 2:38the end of course we'll have some
  63. 2:39questions and answers uh and and
  64. 2:41hopefully uh we could answer all the
  65. 2:43questions you have today all right so
  66. 2:46who am I um I am a principal application
  67. 2:48security architect as well as TR Ming
  68. 2:50lead at Aquia uh at least for right now
  69. 2:53um until the end of the month I'm
  70. 2:55actually looking at some other work here
  71. 2:57soon uh but other things I'm doing I'm a
  72. 3:00co-host with Chris Romeo of the
  73. 3:02application security podcast we're now
  74. 3:04over eight years uh going into our ninth
  75. 3:07year actually of running the application
  76. 3:09security podcast I'm also a co-author of
  77. 3:11the threat Ming Manifesto uh threat Ming
  78. 3:13capabilities and a co-founder of the
  79. 3:15threat Ming connect and as I mentioned
  80. 3:17I've had opportunity to present uh this
  81. 3:20workshop at a couple of the um hack or
  82. 3:23sorry the threat mod cons as well as a
  83. 3:26PhD student um focused on Space cyber
  84. 3:29security uh the next
  85. 3:31Frontier uh previously I uh started and
  86. 3:34led the threat Ming program at Bank of
  87. 3:36America where uh we were able to put
  88. 3:39together uh almost 1500 threat models
  89. 3:41over three years working with lots and
  90. 3:43lots of teams lots of developers um at
  91. 3:45one time we did put some uh training
  92. 3:47together for 45,000 developers uh at
  93. 3:50Bank of America required uh learning
  94. 3:52about threat modeling so it was a really
  95. 3:54uh fun time and a lot of what I learned
  96. 3:56there and in other places over the years
  97. 3:58whove sort of gone into this uh Workshop
  98. 4:02how to help uh folks as are beginning in
  99. 4:05threat modeling how to learn uh some of
  100. 4:08the the basic uh steps and process and
  101. 4:11how they can apply it to the work that
  102. 4:12they're
  103. 4:14doing so again what are we looking to do
  104. 4:17develop a threat Ming mindset through
  105. 4:19Hands-On learning about uh the threat
  106. 4:21Ming process so just to start off with
  107. 4:25what is a threat moding mindset well
  108. 4:28first of all I wanted to mentioned to
  109. 4:30you that you know threat modeling is
  110. 4:32something we're already doing in our
  111. 4:33personal lives and first and foremost I
  112. 4:36want to mention that a threat model or
  113. 4:38threat modeling activity itself is a
  114. 4:40thinking activity there are a lot of
  115. 4:43great tools that you can use for
  116. 4:46analyzing systems uh but a threat model
  117. 4:49uh building a threat model is really a
  118. 4:51thinking activity and so with that in
  119. 4:54mind it again it's something we're
  120. 4:56already doing in our personal lives for
  121. 4:59example when we lock our doors to our
  122. 5:01house or the windows uh we lock the
  123. 5:03doors to our car or even when we look
  124. 5:06around across the street we're thinking
  125. 5:09about what could happen what could go
  126. 5:12wrong uh if I look around when I'm
  127. 5:15crossing the street what am I looking
  128. 5:17for uh you know just in case a car is
  129. 5:19coming down the road I need to make sure
  130. 5:21I'm safe I need to make sure my own
  131. 5:23personal Safety and Security is insured
  132. 5:26and so I look around or or maybe there's
  133. 5:28um a crosswalk uh light that tells me
  134. 5:31it's ready to go or time to go I look
  135. 5:33for those kinds of things why because
  136. 5:35again I am concerned about Safety and
  137. 5:37Security and what do I need to do uh to
  138. 5:40handle those
  139. 5:41situations and so essentially when we're
  140. 5:43thinking ahead and remember I said to
  141. 5:45thinking tool it's a thinking activity
  142. 5:48we think ahead on what could go wrong we
  143. 5:50ask what if questions we weigh risks and
  144. 5:53we act accordingly we're doing a kind of
  145. 5:56threat
  146. 5:57modeling so the first part part of the
  147. 6:00mindset is it's strategic versus
  148. 6:04reactive uh and sometimes you can also
  149. 6:06say proactive and that's ideal but the
  150. 6:09the main thing here is strategic we're
  151. 6:11thinking ahead uh versus just hoping we
  152. 6:14are safe and and just whatever happens
  153. 6:16happens uh but instead trying to think
  154. 6:18ahead and plan ahead now that personal
  155. 6:21what we do in our personal lives that's
  156. 6:23intuitive but it's something that we can
  157. 6:25also uh push into the work that we're
  158. 6:28doing the systems that we're
  159. 6:30viewing and with that in mind uh I was
  160. 6:33as I mentioned a co-author of the threat
  161. 6:35Ming Manifesto and we adopted the four
  162. 6:38question framework Adam Shack had
  163. 6:40invented these uh questions and we
  164. 6:43adopted it into the threat Ming
  165. 6:44Manifesto what are we working on what
  166. 6:48can go wrong what are we going to do
  167. 6:50about it and did we do a good enough job
  168. 6:53and you'll see in this Workshop we apply
  169. 6:55those questions uh quite often in the
  170. 6:58process it's it's really
  171. 7:00uh underlying a lot of what we are
  172. 7:02doing when we talk about a threat model
  173. 7:05typically what we are are saying is that
  174. 7:08we think about a threat model that
  175. 7:10consists of a system representation that
  176. 7:12could be a description it could be a
  177. 7:15diagram or or a combination of the two
  178. 7:17just something that helps us understand
  179. 7:20and answer that first question what are
  180. 7:22we working on the next thing is the
  181. 7:25identified threats what could go wrong
  182. 7:28what could happen
  183. 7:30and so those are those threats propose
  184. 7:32mitigations so that's really answering
  185. 7:34that question what are we going to do
  186. 7:36about it and then determining going back
  187. 7:40and reviewing is there anything else
  188. 7:42that I missed are there any other
  189. 7:44mitigations uh that can also lead into
  190. 7:47the work that needs to be done and and
  191. 7:49the risk that's associated to help us
  192. 7:51priorize that work and that back going
  193. 7:54back and reviewing answers that question
  194. 7:57uh did we do a good enough job and so
  195. 7:59the other thing to notice about those
  196. 8:01questions it's all about we uh there's a
  197. 8:05reason for that it's a team effort and
  198. 8:07we heard that from Avi if you attended
  199. 8:09the uh session earlier uh it's a team
  200. 8:12effort uh when we're looking at building
  201. 8:15a threat
  202. 8:16model so uh taking those four questions
  203. 8:19and and sort of turning them into a a
  204. 8:22process similar steps uh those those
  205. 8:25four steps this and represents those so
  206. 8:28first of all I always say assemble the
  207. 8:31team uh and this little diagram that's
  208. 8:33the defined part diagram understand your
  209. 8:36system that's where we're uh answering
  210. 8:38that question about uh what are we
  211. 8:40working on identify threats what could
  212. 8:42go wrong document so identify and
  213. 8:46mitigate that's where what are you going
  214. 8:47to do about it and then that final is do
  215. 8:49we do a good enough job uh go back and
  216. 8:52review and and potentially uh followup
  217. 8:56validate so let's talk about assembling
  218. 8:58the team ideally you include de software
  219. 9:02developers testers Architects project
  220. 9:04managers uh many other folks that are
  221. 9:07part of your team other stakeholders and
  222. 9:10for this Workshop today uh we will
  223. 9:12divide as I mentioned this larger group
  224. 9:15into breakout groups to represent
  225. 9:17different teams as we take a look at and
  226. 9:19build a threat
  227. 9:23model now getting started very very
  228. 9:26simple tools really uh for diag pring
  229. 9:29you can use a whiteboard if you have a
  230. 9:32team together uh or you could use a
  231. 9:34virtual whiteboard I've done that many
  232. 9:36times where if we're all remote we can
  233. 9:38get on uh a zoom call or something
  234. 9:41equivalent and uh and take a look at a
  235. 9:44diagram or just ask questions and and
  236. 9:46record that information and in terms of
  237. 9:48recording it's really important to
  238. 9:51document uh what you find what you think
  239. 9:53about uh questions that were asked and
  240. 9:55answers to those questions and so you
  241. 9:57can use of course word or Cel Confluence
  242. 10:00J whatever makes sense for your team uh
  243. 10:03of course for this uh hackathon you know
  244. 10:05we encourage you to to document uh some
  245. 10:08of that information in the final threat
  246. 10:10model so that uh the judges can be able
  247. 10:12to to review uh what you're thinking
  248. 10:15what your thought process and so forth
  249. 10:19was and as mentioned today for this
  250. 10:21Workshop we'll be using a mural page uh
  251. 10:24to diagram uh and record threats and
  252. 10:26mitigations as far as the diagram part
  253. 10:28we're going to look at that
  254. 10:29uh we're not actually going to break out
  255. 10:31and draw a diagram but we're stly going
  256. 10:33to review a diagram
  257. 10:36today so just to take a step back let's
  258. 10:39talk a little bit about understanding
  259. 10:41bugs versus flaws in 2015 the itle
  260. 10:45computer Society Center for secure
  261. 10:47design uh put out this paper on avoiding
  262. 10:51the top 10 software security design
  263. 10:54flaws and for me it's just been a a
  264. 10:57really good resource to go back too
  265. 10:59there are a lot of uh great uh things
  266. 11:01listed there about for example uh don't
  267. 11:04get authentication and authorization
  268. 11:06confused always remember to authorize
  269. 11:10after you authenticate don't roll your
  270. 11:11own cryptography and so forth but the
  271. 11:14main key uh things to take away from the
  272. 11:17paper is the difference between a bug
  273. 11:20and a flaw a bug and implementation
  274. 11:23level software problem we have lots of
  275. 11:25tools that can find bugs n plus1 issues
  276. 11:28and so on
  277. 11:30a flaw on the other hand a design flaw
  278. 11:32is a deeper level problem it's the
  279. 11:34result of a mistake or oversight at the
  280. 11:37design level and much of what we're
  281. 11:39doing in threat modeling is we're really
  282. 11:41focused on the flaws we're trying to
  283. 11:43identify design flaws to improve secure
  284. 11:47design we're trying to understand
  285. 11:49underneath what were the decisions made
  286. 11:52and or going to make if we're building a
  287. 11:55threat model for upcoming
  288. 11:57work and so looking at the difference
  289. 12:00between those two secure security coding
  290. 12:03bugs you know coding errors requires
  291. 12:05developer understanding the secure
  292. 12:06coding um can be automated to find those
  293. 12:10and patching is less costly in
  294. 12:12production on the other hand security
  295. 12:14design flaws represent errors in design
  296. 12:18security requirements architecture
  297. 12:20typically need contextual knowledge and
  298. 12:23very difficult to automate Define these
  299. 12:26design flaws and also very cost L to
  300. 12:29change in production I've seen that many
  301. 12:31times for example if you didn't start
  302. 12:34with thinking how you wanted to do
  303. 12:36authorization how you wanted to do
  304. 12:38access checks it can be very costly to
  305. 12:41go back and retrofit so those are things
  306. 12:44that we're talking about those design
  307. 12:46decisions and related to security
  308. 12:49requirements to think about ahead of
  309. 12:51time if you can and again what threat
  310. 12:53mauling is really great uh to help you
  311. 12:55to
  312. 12:56do the other thing I'll mention about
  313. 12:59any typical threat moding session and it
  314. 13:01doesn't have to be so formal um it can
  315. 13:04be just simply a few minutes to take a
  316. 13:06look at a story and understand what's
  317. 13:08going on but these are some typical
  318. 13:11things that I I like to see or or think
  319. 13:13are are good recommendations first of
  320. 13:15all you know domain knowledge and that's
  321. 13:17where the team comes into play do they
  322. 13:20understand the system do we do we have
  323. 13:22that um understanding of what we're
  324. 13:24trying to build uh again it's a team
  325. 13:26effort also understand your business and
  326. 13:29Technical goals you know when you're
  327. 13:31thinking about security and design um
  328. 13:35we're always in relation to some of the
  329. 13:37business and Technical goals as well the
  330. 13:39other thing I'll mention is it's focused
  331. 13:42um we don't spend hours and days and
  332. 13:45days on threat models instead be focused
  333. 13:48because it's going to help you um get
  334. 13:51some of the main things you're looking
  335. 13:52for the other thing is you can also
  336. 13:55unfortunately if you spend too much time
  337. 13:57you can uh hit one of the is we found in
  338. 13:59the or talked about in the threat mly
  339. 14:02Manifesto analysis paralysis so be
  340. 14:05focused on the work that you're doing
  341. 14:07set aside maybe an hour or something
  342. 14:09like that to help you the other thing
  343. 14:12I'll mention uh be honest leave ego at
  344. 14:14the door and no blaming especially when
  345. 14:16you're looking at an existing system is
  346. 14:19these things can really help because you
  347. 14:21might uncover things and didn't realize
  348. 14:23assumptions you didn't uh you had before
  349. 14:26that now need to be questioned so let's
  350. 14:30do the discovery let's understand and uh
  351. 14:33it'll really help us in in building a
  352. 14:35good threat
  353. 14:37model next of course diagramming
  354. 14:40understanding your system and data
  355. 14:41flows so in terms of diagramming and
  356. 14:45understanding the system as well as data
  357. 14:46flows we want to document elements of
  358. 14:48the system and properties affected at
  359. 14:51minimum document some of the basic
  360. 14:53elements of how the system works
  361. 14:55security concerns of any properties and
  362. 14:58as uh those of you who are going through
  363. 15:00the hackathon there's uh a description
  364. 15:04of the system take a look at it uh ask
  365. 15:07some questions about it understand what
  366. 15:09it's saying now there's some things that
  367. 15:11may be there they're not there and so
  368. 15:13forth but note those as well so that'll
  369. 15:16help you to understand that
  370. 15:19system in terms of a data flow diagram
  371. 15:21you can certainly start with a network
  372. 15:23diagram or an architecture diagram um
  373. 15:26the value of a data flow diagram and
  374. 15:28threat moding is uh one you're trying to
  375. 15:32understand uh one of the most important
  376. 15:35assets to a system which is typically
  377. 15:37the data and how that data um is used in
  378. 15:41the system you know accessed and where
  379. 15:43is the data stored and who has um access
  380. 15:46to that data uh and so on and so with
  381. 15:49that in mind typically when you're
  382. 15:50drawing a a data flow diagram or any
  383. 15:53diagram you're you're trying to
  384. 15:55understand some of the basic components
  385. 15:58here in terms of the DFD we look at
  386. 16:01external entity to start with uh that
  387. 16:03represents entities that we just don't
  388. 16:06have direct control over so that could
  389. 16:08be uh users of our system they're
  390. 16:11external to our system but they're
  391. 16:13interacting with our system or other
  392. 16:15systems maybe other apis that we're
  393. 16:17calling um browsers that users are using
  394. 16:20to connect to our web application for
  395. 16:22example all of those can be represented
  396. 16:24as external entities a process on the
  397. 16:27other hand uh represented by by that
  398. 16:29circle is something that we do have
  399. 16:32direct control over maybe it's a
  400. 16:33component we wrote maybe it's um a piece
  401. 16:37of software that we're configuring but
  402. 16:39we again we have some direct control
  403. 16:40over and so we want to distinguish that
  404. 16:44from the
  405. 16:45entities data stores represent data
  406. 16:49where is that data uh being stored and
  407. 16:52in particular it could be files so
  408. 16:54something you may not always see in an
  409. 16:56architecture diagram config files log
  410. 16:58files files other kinds of files uh
  411. 17:00database tables registry cache cookies
  412. 17:03anywhere that data may be stored within
  413. 17:05the
  414. 17:06system data flows help us understand how
  415. 17:10data is flowing through the system so
  416. 17:13going from perhaps an external entity to
  417. 17:16a process or the process in turn storing
  418. 17:19it into the data store how is that data
  419. 17:23flowing and one thing I'd recommend when
  420. 17:25you draw data flows first of all show
  421. 17:27the direction but also
  422. 17:29label it so that we understand what it's
  423. 17:31doing as well as perhaps uh the protocol
  424. 17:34use for example is it HTTP https and so
  425. 17:38on and that'll help especially as we
  426. 17:40start to identify threats what uh are
  427. 17:44some of these rather
  428. 17:45unencrypted uh what kind of data is
  429. 17:47traveling is that sensitive data that
  430. 17:49needs to be encrypted and so on and then
  431. 17:52finally the the last concept here is
  432. 17:55trust boundaries trust boundaries help
  433. 17:57us understand and uh where trust may
  434. 18:01change as those data flows go through
  435. 18:04the system connecting from an entity to
  436. 18:07a process or process to a data
  437. 18:09store the main thing about a trust
  438. 18:11boundary is as it mentions inside you
  439. 18:13trust the processes and data stores
  440. 18:16outside you don't another thing I like
  441. 18:19to think about is that as you cross that
  442. 18:21boundary with the data flow is that a
  443. 18:24place where you more than likely need to
  444. 18:27check trust for example authentication
  445. 18:30authorization validation and so that can
  446. 18:33also help you where this is an area that
  447. 18:35we need uh trust and and recognize that
  448. 18:39you know as data flows through we need
  449. 18:41to check that for trust uh when that
  450. 18:44call comes
  451. 18:47through and um you know in terms of the
  452. 18:50hackathon you can use the drawing tool
  453. 18:51of choice um however we recommend uh
  454. 18:55typically for if you're if you're
  455. 18:56building a data flow diagram and there
  456. 18:57are other things you can do as well
  457. 18:58we'll show you that in a moment uh try
  458. 19:00to stay with the basic shapes and
  459. 19:01meanings for
  460. 19:04consistency so again drawing a data flow
  461. 19:07diagram ideally The Logical and
  462. 19:09component architecture communication
  463. 19:12flows and how data is um moved and
  464. 19:15stored within the system so here's just
  465. 19:18a basic example users and admin those
  466. 19:21are your entities external entities
  467. 19:24either server or web app uh is your
  468. 19:26process and then again data flows
  469. 19:29um label them uh just so that we know
  470. 19:31what they are what they're doing uh
  471. 19:34sometimes you can just use one uh data
  472. 19:36flow for example that represents both a
  473. 19:37request and response uh that's up to you
  474. 19:40how you want to to show that and then of
  475. 19:42course uh the trust boundary that helps
  476. 19:44us understand that as that data moves to
  477. 19:48the the web server the web application
  478. 19:50um more than likely there needs to be
  479. 19:52some kind of trust check could be
  480. 19:54authentication authorization and so on
  481. 19:56and that's going to help us as we start
  482. 19:58to look at uh the threats a little bit
  483. 20:00later using the
  484. 20:02diagram here's an example this is the
  485. 20:04OAS threat Dragon 2.0 uh where you know
  486. 20:07that tool you can draw a data flow
  487. 20:09diagram in particular but just shows you
  488. 20:11again some of the uh the basic shapes uh
  489. 20:15for a data flow diagram representing
  490. 20:17processes and data flows data stores uh
  491. 20:20and Trust boundaries as
  492. 20:23well okay so um this is actually a time
  493. 20:26when we normally would uh just draw a
  494. 20:28data flow diagram if we were in uh
  495. 20:31inperson uh Workshop today uh in the
  496. 20:34interest of time we're going to actually
  497. 20:35review a data flow diagram uh that it's
  498. 20:38represented by um what's what's shown
  499. 20:40here but we've got uh some actors
  500. 20:43service staff and a user we've got an
  501. 20:46authentication provider we have for data
  502. 20:49stores logs a database uh processes a
  503. 20:52web application web services and so
  504. 20:55on so here's a diagram and again we're
  505. 20:59going to look at this in more detail as
  506. 21:01we break out uh and start to look at
  507. 21:03threats uh but again representing a web
  508. 21:06application in this case the user who's
  509. 21:09an external entity uh using that browser
  510. 21:12connecting the web application we see
  511. 21:14web services batch processes uh we also
  512. 21:17see another type of user a service staff
  513. 21:20using a client application connecting to
  514. 21:22a database and if you notice over there
  515. 21:24on the on the uh right hand side we have
  516. 21:27partner organizations authentication
  517. 21:29provider we also have third-party data
  518. 21:31and service participants so a lot of
  519. 21:33different things going on in this this
  520. 21:35simple diagram uh representative to help
  521. 21:38us understand uh some of the the types
  522. 21:41of things that we might see in a typical
  523. 21:43web application uh that we're going to
  524. 21:45be looking at today for this
  525. 21:49Workshop so let me just check the
  526. 21:52uh the chat for a moment see if there
  527. 21:55are any questions
  528. 21:59okay I don't see any at the moment all
  529. 22:01right uh so we've drawn our data flow
  530. 22:05diagram we've asked questions about how
  531. 22:07the system works we're we're trying to
  532. 22:10uh get some answers to those questions
  533. 22:12and and that'll help us understand um
  534. 22:14the system better now let's start to
  535. 22:16identify
  536. 22:19threats when we do that um essentially
  537. 22:23and going back to our mindset uh the
  538. 22:25mindset of a threat minding mindset is
  539. 22:27first of all we mentioned strategic
  540. 22:29thinking ahead the next part of a threat
  541. 22:31Ming mindset is asking questions what if
  542. 22:34what could go
  543. 22:36wrong uh we like to typically start with
  544. 22:38stride uh you don't have to use stride
  545. 22:41and in fact I have another slide that
  546. 22:43talks about many other methods as well
  547. 22:45but stride is a good place I think to
  548. 22:47start just to understand some of the
  549. 22:49most basic security issues uh that you
  550. 22:51might see within uh many software
  551. 22:54systems so stride is a nemonic
  552. 22:58representing uh spoofing tampering
  553. 23:00repudiation information disclosure
  554. 23:02denial service and elevation of
  555. 23:05privilege if you notice uh to the right
  556. 23:08the are of the threat property violated
  557. 23:11uh these are some of the most basic
  558. 23:12security issues that you see within
  559. 23:15systems uh for example we have CIA
  560. 23:19confidentiality integrity and
  561. 23:21availability uh we also have uh
  562. 23:24essentially The Three A's authentication
  563. 23:26authorization and sometimes
  564. 23:27non-repudiation
  565. 23:29is called
  566. 23:30auditability but looking at each of
  567. 23:32these spoofing pretending to be
  568. 23:34something or someone other than yourself
  569. 23:36you're looking for um ways to identify
  570. 23:39or the lack of identification do I
  571. 23:42really know who this person is or this
  572. 23:44service that's calling uh my services
  573. 23:47have I identified them tampering
  574. 23:50modifying something on disk Network
  575. 23:52memory or elsewhere what we want there
  576. 23:55as I mentioned is data Integrity so
  577. 23:57we're looking look for ways that an
  578. 24:01attacker might change the data that we
  579. 24:04rely on and uh has that been protected
  580. 24:08against and so that's the Potential
  581. 24:09Threat there
  582. 24:11repudiation is really about uh claiming
  583. 24:15you didn't do something or not having a
  584. 24:18proof of that happening and
  585. 24:20non-repudiation is the proof uh so for
  586. 24:24example in a system logging or the lack
  587. 24:27of logging
  588. 24:29could be an example of repudiation and
  589. 24:31non-repudiation the logs themselves the
  590. 24:34audit Trail uh that's an example of
  591. 24:37non-repudiation within a system and so
  592. 24:39many times when you look at a system are
  593. 24:42we monitoring are we logging and and
  594. 24:44have sufficient information to
  595. 24:46understand what's happening information
  596. 24:48disclosure providing information to
  597. 24:50someone not authorized to see it what we
  598. 24:53want again is confidentiality and many
  599. 24:55times that's where encryption comes into
  600. 24:57play no notice it says to someone not
  601. 25:00authorized to access it how would they
  602. 25:02be able to see it well if it's encrypted
  603. 25:05then they might need a key and so those
  604. 25:07who have the key provided the key then
  605. 25:09they would be able to see that
  606. 25:11information um that's a really important
  607. 25:13one uh a threat in particular
  608. 25:16information disclosure we see that quite
  609. 25:18often in data
  610. 25:20breaches who has access have we uh
  611. 25:24limited access to that data denal
  612. 25:27service uh exhausting resources needed
  613. 25:30to provide service so you might think of
  614. 25:32attacks where an attacker is trying to
  615. 25:35call a lot of pages and try to try to
  616. 25:38get the system uh to respond to Long
  617. 25:41running uh queries and so on but it's
  618. 25:44also the lack of availability as it
  619. 25:46mentions here related to services that
  620. 25:49we depend on for example apis that we
  621. 25:52call what happens if they're not
  622. 25:54available databases uh down for some
  623. 25:57reason and we're not able ble to do our
  624. 25:59work and so those are some other
  625. 26:01examples of denial of service as you
  626. 26:03look at a system and finally the most
  627. 26:05severe of all these threats elevation of
  628. 26:08privilege relating to allowing someone
  629. 26:10to do something they're not authorized
  630. 26:12to do and what we want is authorization
  631. 26:16or in enforcing some kind of lease
  632. 26:19privilege so that uh a system or a
  633. 26:23person within a particular role can only
  634. 26:25do certain things that they should be
  635. 26:27allowed to do and no more a regular user
  636. 26:29should not be able to elevate their
  637. 26:33privilege which is what the threat is to
  638. 26:35act as an administrator for example and
  639. 26:38so are there um situations when you're
  640. 26:41looking at a a a system and are there
  641. 26:44places where we haven't done proper
  642. 26:49authorization so applying all of that to
  643. 26:52a data flow diagram uh there a couple of
  644. 26:55options you can use each part of stride
  645. 26:58uh to apply to a specific element or
  646. 27:01interactions so for example the web
  647. 27:04application are there situations there
  648. 27:06for spoofing uh tampering and so on the
  649. 27:10other is you can just look at Stride per
  650. 27:12interaction uh reason being is that
  651. 27:16typically if let's say a file is never
  652. 27:19accessed uh only that action of
  653. 27:22accessing that file allows a threat
  654. 27:25maybe to be realized and so if you just
  655. 27:28look at the interactions that can help
  656. 27:29you uh to start where stride uh and
  657. 27:33apply stride to determine some potential
  658. 27:35threats of an act actual uh actor or
  659. 27:39attacker being able to get access to log
  660. 27:42files databases and so on so couple
  661. 27:45different ways to look at it applying
  662. 27:47stride to anything you see or just
  663. 27:50starting with the interactions and apply
  664. 27:52stride
  665. 27:53there so some examples spoofing user
  666. 27:57could spoofed by an
  667. 27:59attacker uh tampering requests from the
  668. 28:01user to web app may be
  669. 28:04modified repudiation how would we know
  670. 28:06actions are performed by the web app
  671. 28:08information disclosure setting and
  672. 28:10getting credentials could be exposed in
  673. 28:12transit um especially if it's if it's uh
  674. 28:16not encrypted deny service what happens
  675. 28:19if the authentication Service or
  676. 28:21provider up there the top right is not
  677. 28:24available and elevation of privilege
  678. 28:26does audit data have access control for
  679. 28:29reading uh so very important as well so
  680. 28:32those are again are some examples um as
  681. 28:34we get into our exercise we're going to
  682. 28:37have an opportunity to look at that data
  683. 28:39flow diagram and apply uh or think about
  684. 28:42some threats specifically as I mentioned
  685. 28:45many many different ways to identify
  686. 28:47threats and especially in this hackathon
  687. 28:49you don't have to use stride you're not
  688. 28:51uh you know you're not locked down to
  689. 28:53using stride you can use uh many others
  690. 28:56as uh as you uh understand or seems to
  691. 29:01apply so lenden for example is privacy
  692. 29:04focused it's another pneumonic that
  693. 29:06helps you identify privacy related
  694. 29:08threats attack trees uh asset or
  695. 29:11attacker Centric thinking about how do I
  696. 29:13get from where I am as an attacker to my
  697. 29:17goal and what are the steps to get there
  698. 29:19and and outline that and that can help
  699. 29:20you then determine the mitigations at
  700. 29:23each point at each node that you may
  701. 29:25need to apply uh to prevent the attack
  702. 29:28are getting to the goal uh pasta which
  703. 29:30is a a risk Centric threat modeling uh
  704. 29:34process has a number of steps that you
  705. 29:36can take a look at miter attack or
  706. 29:39defend uh and there's some others as
  707. 29:41well depending on the system uh all of
  708. 29:43those are intrusion Centric knowledge
  709. 29:45bases they give you uh very specific
  710. 29:48examples of how an attacker and for
  711. 29:52example with attack may use to get from
  712. 29:56uh point a to to final uh goal and
  713. 30:00various steps along the way so you can
  714. 30:02certainly take a look at that as well uh
  715. 30:04card games can help you use case abuse
  716. 30:06cases can help you lots of different
  717. 30:08ways to identify threats and so and you
  718. 30:11know building a threat model or even in
  719. 30:13this hackathon you have uh some options
  720. 30:17uh to consider and in uh building out
  721. 30:19your threat
  722. 30:21model okay so using stride to identify
  723. 30:25threats here is uh what we call a uh
  724. 30:29threat table it helps us to uh do what
  725. 30:33we talked about at the very beginning uh
  726. 30:35threat model consists of that system
  727. 30:38description the identified threats
  728. 30:42mitigations and uh what are we going to
  729. 30:44do about it as well as um you know
  730. 30:48reviewing and followup and so on and
  731. 30:50that's what this table is going to help
  732. 30:52you do so here in this case we have a
  733. 30:55threat partner organization
  734. 30:56communication to web services may be
  735. 30:58compromised uh logs for a web
  736. 31:00application may be tampered with
  737. 31:03sometimes it may map directly to stride
  738. 31:05or or whatever
  739. 31:07uh method you're using to identify
  740. 31:09threats it's just optional uh it doesn't
  741. 31:12have you don't have to say what it is
  742. 31:14maybe you determine a threat uh that
  743. 31:16doesn't fit nicely and neatly uh into uh
  744. 31:19whatever uh categorization that you're
  745. 31:21using and that's okay uh the key is that
  746. 31:25the idea behind that is just how did you
  747. 31:27arrive at that threat where did that
  748. 31:28come from it's just to help us uh to uh
  749. 31:31in your thinking of looking for those
  750. 31:34threats all
  751. 31:36right uh some other things I'll mention
  752. 31:40when you're identifying threats and
  753. 31:41asking questions is who's interested in
  754. 31:44the apps Andor data those threat agents
  755. 31:48uh what are their goals so what assets
  756. 31:50are do you think they're looking for uh
  757. 31:53what are the attack methods how what do
  758. 31:55you think uh are some ways that they
  759. 31:58might try to attack the system are there
  760. 32:00any attack surfaces trust boundaries for
  761. 32:02example exposed and are there any input
  762. 32:06output data flows missing i' see one
  763. 32:08common one is uh file uploads you know I
  764. 32:12rely on a file an XML file Json file or
  765. 32:15something like that well that's input
  766. 32:18you know how is that uh checked how's
  767. 32:21that validated and so on so uh those are
  768. 32:24important as well as you're as you're
  769. 32:26thinking about uh input and then the
  770. 32:28data flows also that uh come into your
  771. 32:32system all right so we're in our first
  772. 32:36exercise and uh this is going to be uh
  773. 32:38new for me to to try to do this in uh at
  774. 32:41least for in Zoom uh but we're going to
  775. 32:44have some breakout groups and um we're
  776. 32:46going to spend about 1015 minutes uh and
  777. 32:50uh work with each of our volunteers and
  778. 32:52then we'll back and view for a few
  779. 32:54minutes and then continue on so I'll
  780. 32:57turn to with you sh I think you're in uh
  781. 32:59in charge of that okay so how was that
  782. 33:01for everybody uh were there some
  783. 33:03interesting threats that you
  784. 33:05noted in looking at this particular
  785. 33:08diagram anybody like to share for do a
  786. 33:12couple minutes of
  787. 33:14that either on chat or in chat or you
  788. 33:18can come off mute it's
  789. 33:19fine uh yeah uh this is hi this is Ali
  790. 33:23uh can I speak yes please okay um
  791. 33:26actually uh we had a healthy discussion
  792. 33:28in our room so the first is basically
  793. 33:30regarding considering the threat the
  794. 33:32trust boundaries from the external
  795. 33:34browser to the internal um Network I
  796. 33:37should say so the user request can be
  797. 33:41spoofed um uh and it will compromise the
  798. 33:45um I should say the the spoofing of the
  799. 33:48stride model and the mitigation could be
  800. 33:51the uh multiactor authentication uh as
  801. 33:54well the next one could be also be the
  802. 33:56inbut validation
  803. 33:58for example uh if the sqli is allowed by
  804. 34:01our server site so this could lead to
  805. 34:05the uh authentication first thing it
  806. 34:08could be elevation of privileges as well
  807. 34:10uh this is the next point from the
  808. 34:13services staff if they are related to
  809. 34:15our internal uh employees and they're
  810. 34:20directly accessing the client
  811. 34:21application The Insider threat could be
  812. 34:24um a threat uh the uh uh the the
  813. 34:27mitigation for this one can be the
  814. 34:30multifactor authentication and the need
  815. 34:32to know basis and the relevant category
  816. 34:36for those application could be elevation
  817. 34:38of privileges this is the first thing
  818. 34:40and the authorization if access review
  819. 34:42were not done comprehensively and next
  820. 34:44one is from from the web application
  821. 34:46sorry interrupt me if I am speaking too
  822. 34:49much no that's okay uh and and
  823. 34:51appreciate it actually you're jumping
  824. 34:52ahead a little bit to the next part
  825. 34:54we're going to be looking at mitigations
  826. 34:55here in a moment but excellent threats
  827. 34:58and uh yeah we're going to be joining
  828. 34:59back in our our breakout groups to take
  829. 35:01a look at some mitigations of the
  830. 35:02threats we identified uh but appreciate
  831. 35:05some of the ones that you uh you
  832. 35:06identified there and shared with us uh
  833. 35:08thank you anybody else another threat
  834. 35:11that we haven't already talked about
  835. 35:12that just jumped out for your
  836. 35:15team so Robert one of my group which I
  837. 35:18was facilitating uh they also mentioned
  838. 35:21about the third party um you know supply
  839. 35:24chain risk they did call out that even
  840. 35:28though there's a t boundary um we we
  841. 35:31need to be specific we need to note it
  842. 35:34down yes great great call out all right
  843. 35:38fantastic one of my team member talk
  844. 35:41about the partner organization they are
  845. 35:43using FTP and they can AR they can
  846. 35:46modify the data uh in the database
  847. 35:49directly because there's no
  848. 35:50authentication right right yeah and and
  849. 35:55go ahead sorry so there was one more
  850. 35:57like three there's a lack of the trust
  851. 35:58boundary in the logs right so anybody
  852. 36:01can who is having an access to the web
  853. 36:03application they can access the logs
  854. 36:06directly they might be able to yeah it's
  855. 36:09not clear but yeah this a good that's a
  856. 36:12good point can anybody access it doesn't
  857. 36:15really specify it doesn't really let you
  858. 36:17know how that happens and those are
  859. 36:19things that uh and great point you may
  860. 36:22need to go back and ask questions again
  861. 36:25and you know there's some things that
  862. 36:27are missing here there's some things
  863. 36:28that you know in terms of
  864. 36:30underlying how does this work how does
  865. 36:32that work and so forth and and so great
  866. 36:35points to continue to ask questions when
  867. 36:38you look at a diagram or or you're
  868. 36:40thinking about a system or or trying to
  869. 36:43understand a system rather ask good
  870. 36:45questions like those to to clarify okay
  871. 36:48well who has access to those logs and
  872. 36:50how do they get access to those logs so
  873. 36:52great great uh call outs do we take the
  874. 36:55perspective of no assumptions or do we
  875. 36:59you know CU I mean obviously there's not
  876. 37:02enough data here really to do anything I
  877. 37:04mean you can call out everything in the
  878. 37:05sun based upon this threat model of
  879. 37:07course there's there's very little data
  880. 37:10in terms of how the application works
  881. 37:12what the exercises are going to be like
  882. 37:15uh really and the the purpose is just to
  883. 37:17find what just a few that you can you're
  884. 37:19not going to find all and and like you
  885. 37:20said there's lots here because we just
  886. 37:22don't know everything so that's that's
  887. 37:24the purpose is just exercising being
  888. 37:27able to identify some
  889. 37:30threats great all right well thank you
  890. 37:33everyone so getting back to the threat
  891. 37:36muling mindset uh this is a quote from
  892. 37:39Adam Shack's book uh threat muling
  893. 37:40designing for security threat Ming is a
  894. 37:43use of abstractions to Aid in thinking
  895. 37:45about
  896. 37:46risks threat modeling is the key to a
  897. 37:48focused defense without threat models
  898. 37:50you can never stop playing whack-a-mole
  899. 37:53and so key there is threat muling is
  900. 37:56focused defense and so another part of
  901. 37:58the threat modeling mindset is to be
  902. 38:01prepared that focused defense and so
  903. 38:03that's where we're getting into
  904. 38:05mitigations or that third question what
  905. 38:07are you going to do about
  906. 38:10it always recommend you document what
  907. 38:12you
  908. 38:13find these are some uh typical examples
  909. 38:17very common examples to address issues
  910. 38:20with stride so you know you want
  911. 38:23identity Assurance authentication uh
  912. 38:25this was already mentioned as potential
  913. 38:27mitigations two-factor multiactor
  914. 38:29authentication for example for spoofing
  915. 38:32uh if you look at availability Den all
  916. 38:34Service uh issues there you want rate
  917. 38:37limiting or throttling you want
  918. 38:38real-time monitoring uh things like that
  919. 38:41lease privilege you want uh system that
  920. 38:44has an Central authorization engine
  921. 38:46that's always ideal authorization
  922. 38:49controls uh system limits and system
  923. 38:52uses roles accounts permissions and so
  924. 38:55forth to help manage access lots of
  925. 38:58different good Solutions there and so
  926. 39:00again just some example controls that
  927. 39:02are pretty typical if you're thinking
  928. 39:04about stride uh but the key is
  929. 39:07understand the threat and what are some
  930. 39:09ways to get to what we need we need
  931. 39:12confidentiality we need availability we
  932. 39:15need data Integrity how do you ensure
  933. 39:18that so that's the key thing about what
  934. 39:20are we going to do about it now there
  935. 39:23are some mitigation options for example
  936. 39:26you can leave as is you determine
  937. 39:28there's a threat but there's no good way
  938. 39:31to fix it perhaps and or maybe uh the
  939. 39:35threat is we just note it but it um it's
  940. 39:39it's the possibility of it is extremely
  941. 39:42low and so you just simply leave the
  942. 39:44system as it is uh if you find a
  943. 39:47particular uh part of the system that is
  944. 39:50prone to threats and you you haven't got
  945. 39:52a good countermeasure in place yet you
  946. 39:54can just simply remove that feature from
  947. 39:56the product until you fix it or remedy
  948. 40:00it with a technology countermeasure you
  949. 40:02know set up a story around it and add
  950. 40:05that better mitigation or countermeasure
  951. 40:08in place uh the other one is warn user I
  952. 40:11see that quite often for example if I go
  953. 40:13to a coffee shop and it says free Wi-Fi
  954. 40:17anybody can connect and but the warning
  955. 40:20is uh realize it's completely open
  956. 40:23anybody is connecting anybody can see
  957. 40:26potentially your traff traffic if
  958. 40:27certainly if you're not using https or
  959. 40:30other means to uh encrypt your own uh
  960. 40:32traffic and so warn user that's another
  961. 40:36one uh that you can do as well with the
  962. 40:37mitigation option um we I like to
  963. 40:40recommend that you make the mitigations
  964. 40:42and counter measures part of your
  965. 40:43security acceptance criteria that helps
  966. 40:46you understand uh what's a threat did I
  967. 40:49have a way do I have a good way of
  968. 40:51countering
  969. 40:52that now some other things about uh that
  970. 40:56continues on with uh thinking about what
  971. 40:59we going to do about it is determining
  972. 41:01risk uh what's a risk associated with
  973. 41:04the vulnerability and the threat
  974. 41:05identified if we don't fix it what is
  975. 41:08the risk of this happening now uh we're
  976. 41:11not going to go into all the details
  977. 41:13about risk but it's Essence typically
  978. 41:17risk is uh what we consider as two
  979. 41:20factors ease of
  980. 41:22exploitation and the business impact if
  981. 41:24that risk or that threat was realized uh
  982. 41:27in terms of risk management you know
  983. 41:29certainly as I mentioned there's some
  984. 41:30others you can do for example Fair uh
  985. 41:33which is um a particular
  986. 41:35analysis uh tool that you can use or
  987. 41:38just at as very simplest risk rating
  988. 41:40high medium low based on ease of
  989. 41:44exploitation if it's if it's easy to
  990. 41:47exploit that's high the business impact
  991. 41:50if it's a Major Impact to our system
  992. 41:52that's also High and the combination of
  993. 41:54those two maybe the risk rating is high
  994. 41:57or or critical and so uh you can put
  995. 42:00those two together and try to figure out
  996. 42:02you know what your risk rating is some
  997. 42:03of that of course is sub subjective but
  998. 42:06it's it's a way of trying to help you
  999. 42:08determine um what are my priorities once
  1000. 42:11I determine certain things are critical
  1001. 42:13I probably need to fix those first um
  1002. 42:16maybe uh uh Beyond some of the others
  1003. 42:18that I need to fix as well
  1004. 42:20later and so mapping that out uh here
  1005. 42:24going back to our threat table we had
  1006. 42:27some threats we identified now we also
  1007. 42:29have some mitigations so Implement
  1008. 42:32encryption and we consider that uh
  1009. 42:35communication certainly from the outside
  1010. 42:37as being a high risk uh the apply access
  1011. 42:42control on logs for the uh threat around
  1012. 42:45logs uh we consider that to be medium
  1013. 42:48and uh risk in that case and then also
  1014. 42:51action items and questions so should we
  1015. 42:54limit to TLS
  1016. 42:551.3 uh review the best validation of
  1017. 42:58messages review access control options
  1018. 43:01and so on and so those are some things
  1019. 43:03to to consider when you're you're doing
  1020. 43:06uh or putting together rather some
  1021. 43:07action items to follow up on those
  1022. 43:09mitigations that you
  1023. 43:11identified at a minimum uh what I like
  1024. 43:14to recommend is that uh the thread
  1025. 43:17itself document that the stride mapping
  1026. 43:19if it's relevant it doesn't have you
  1027. 43:21don't have to but sometimes it helps uh
  1028. 43:24and it might uncover some other
  1029. 43:25potential threats as a result
  1030. 43:27mitigations that you currently are
  1031. 43:30implementing or maybe none and uh
  1032. 43:33optionally maybe a risk rating and then
  1033. 43:36also action items so mitigations that
  1034. 43:39are to be implemented uh those few items
  1035. 43:42if you could document that that'll be
  1036. 43:44really helpful and that'll help you in
  1037. 43:45terms of follow up with uh Jura tickets
  1038. 43:48and user stories and other kinds of
  1039. 43:51things that you may need to do as a
  1040. 43:53result of threats you've identified that
  1041. 43:55are not mitigated
  1042. 43:58currently okay so now we're into our
  1043. 44:02second breakout session where we're
  1044. 44:04going to uh follow up with investigating
  1045. 44:07mitigations for some of the threats we
  1046. 44:09identified the the first time uh so if
  1047. 44:12we could uh jump into our next um um
  1048. 44:15breakout group okay how was that uh
  1049. 44:20exercise were you able to figure out
  1050. 44:22some good mitigations for the threats
  1051. 44:24you had identified the first time
  1052. 44:27yeah it was nice it was fun good good
  1053. 44:31any good uh mitigations that you
  1054. 44:33determined if any any team like to
  1055. 44:37share maybe I I'll I'll share one of the
  1056. 44:41uh so we had identified one threat for
  1057. 44:44the uh web application which is uh which
  1058. 44:47we considered as the internet facing
  1059. 44:49application so so there could be a
  1060. 44:52possibility where there could be a Dos
  1061. 44:55attack Okay so service yeah yeah to the
  1062. 44:59end that could be the unavailability of
  1063. 45:01the service so to mitigate that we we
  1064. 45:05kind of introduce u a web application
  1065. 45:09firewall uh in front of the uh internet
  1066. 45:13facing application along with uh the
  1067. 45:16load balancer capability as well for
  1068. 45:18high availability of the application
  1069. 45:21great Al limitation against Brute Force
  1070. 45:25attacks
  1071. 45:28great great anyone else any other
  1072. 45:32observations or yes please uh Ricardo um
  1073. 45:36from our group we had identified that
  1074. 45:39there was a a spoofing threat on the
  1075. 45:41client
  1076. 45:42application
  1077. 45:44um and basically to counter that as a
  1078. 45:46mitigation
  1079. 45:48we uh decided to add
  1080. 45:50the sorry um certificate certificates
  1081. 45:54certificates and so that we could um you
  1082. 45:57know kind of uh show that the
  1083. 46:00application is trusted to uh to a person
  1084. 46:04who is not being D but yeah great great
  1085. 46:10fantastic anybody else hey Robert this
  1086. 46:12is John the team talked about on on the
  1087. 46:15Dos not just the um the WAP but dos
  1088. 46:19protection you know appliances but also
  1089. 46:22putting things behind the CDN so like as
  1090. 46:24example have like front door there's a
  1091. 46:27lot of different CDN options out there
  1092. 46:29and they also mentioned two which I
  1093. 46:30thought was really interesting was
  1094. 46:31around autoscaling which is around
  1095. 46:34resiliency which in some ways does apply
  1096. 46:36a lot from a security threat perspective
  1097. 46:39AB ability right so yeah AB that was a
  1098. 46:42real interesting one I I hope the team
  1099. 46:44doesn't mind that I brought that up but
  1100. 46:47nonetheless hopefully that uh that was
  1101. 46:50something that was really unique I
  1102. 46:51thought in terms of what you guys
  1103. 46:52brought up so very cool um within our
  1104. 46:55team we we talked a little bit about
  1105. 46:57logs and about potential sensitive data
  1106. 47:00in the logs and with that we talked
  1107. 47:02about um you know and this goes back to
  1108. 47:04what we talked about earlier about
  1109. 47:06understanding your domain understanding
  1110. 47:08the
  1111. 47:09business understanding the technical and
  1112. 47:12and goals for each of those and we
  1113. 47:14talked about you know what kind of data
  1114. 47:16is in the in those logs is there any pii
  1115. 47:19any Phi so personal information personal
  1116. 47:23health information uh is if you're in
  1117. 47:25the finance industry
  1118. 47:27what about um any financial information
  1119. 47:30and how you're handling that kind of
  1120. 47:32data in the database as well and so on
  1121. 47:34and and so it's also important to
  1122. 47:37understand again your domain understand
  1123. 47:39some specific um policies and compliance
  1124. 47:44can come in here as well with mitigation
  1125. 47:46and that can can apply to your building
  1126. 47:49out your threat models and thinking
  1127. 47:50about uh not this in a vacuum but
  1128. 47:53instead we're in a business we're in you
  1129. 47:55know a particular domain and the and the
  1130. 47:57kinds of things that we need to think
  1131. 47:59about in terms of secure access and
  1132. 48:02secure data so all those kinds of things
  1133. 48:04came up in in our discussion as well and
  1134. 48:06so uh good call outs on on that
  1135. 48:09information that you need to be aware of
  1136. 48:11and and and so
  1137. 48:14on great all right uh well thanks
  1138. 48:17everyone for for going through that
  1139. 48:19exercise uh really appreciate
  1140. 48:21it so just to sort of uh wrap up here uh
  1141. 48:26in the last parts so we already talked
  1142. 48:29about uh you know documenting elements
  1143. 48:31of the system properties affected the
  1144. 48:32threat threats mitigations and risks and
  1145. 48:35action items action items of course
  1146. 48:37important that not just that we have
  1147. 48:40gone through the exercise but we do
  1148. 48:42something about it um we don't just talk
  1149. 48:44about it but we do something about it
  1150. 48:46and so that's where in that last part
  1151. 48:48did we do a good enough job you go back
  1152. 48:51and
  1153. 48:52review document the findings and
  1154. 48:54decisions file bugs or new requirements
  1155. 48:58uh verify that those are fixed
  1156. 49:01implemented and then about reviewing and
  1157. 49:03just did we do a good enough job do we
  1158. 49:06have a a good confidence in the threat
  1159. 49:08model or is there something else missing
  1160. 49:10so do we miss anything review again is
  1161. 49:12there anything new review again now
  1162. 49:15we've said this before no threat model
  1163. 49:17is going to be perfect you're not going
  1164. 49:19to find everything especially as you
  1165. 49:21start uh one thing you'll find you might
  1166. 49:24get into that analysis paralysis where
  1167. 49:26you find find everything and some people
  1168. 49:29do that like oh everything is bad I
  1169. 49:30don't know you know try to be a little
  1170. 49:32bit more specific if you can um and and
  1171. 49:36be okay with not finding everything
  1172. 49:39because as you continue to build those
  1173. 49:41skills that mindset you'll see things a
  1174. 49:45little differently the next time or you
  1175. 49:47notice something you didn't before and
  1176. 49:49that'll help to continue to improve your
  1177. 49:52threat model as you go
  1178. 49:54along and so again to to wrap up here
  1179. 49:57with our table that review followup
  1180. 49:59address issues in the next Sprint or
  1181. 50:02evaluate if we'll fix in the next Sprint
  1182. 50:03or future Sprint and sometimes you may
  1183. 50:06note it's nothing we can really fix uh
  1184. 50:08we we talked about in our group the
  1185. 50:10third party data and supply chain issues
  1186. 50:13we can certainly do some things on the
  1187. 50:14company's side but we can't do
  1188. 50:17everything on in this case it's an
  1189. 50:20external entity we can't fix everything
  1190. 50:22that they may be doing so there are
  1191. 50:24maybe some things that we need to put in
  1192. 50:25place about questions we ask ask how
  1193. 50:27does it work here how does how do they
  1194. 50:29secure this or that and and have a
  1195. 50:32little bit of understanding but there
  1196. 50:34are some things we may never be able to
  1197. 50:36to solve because it's external and
  1198. 50:39something we depend on so it's good to
  1199. 50:41be able to identify that as
  1200. 50:44well so repeat or iterate as needed
  1201. 50:47consider a baseline threat model for
  1202. 50:49your project if you've never ever
  1203. 50:51created a threat model before and then
  1204. 50:53update in or review your threat model as
  1205. 50:55you continue to add new or updated
  1206. 50:57features and I find that second part
  1207. 50:59goes a lot faster the first time may
  1208. 51:01take a little bit of time you know a few
  1209. 51:04sessions just to get a good Baseline
  1210. 51:06threat model but then after that much
  1211. 51:09faster you'll find your
  1212. 51:11stories continue to be updated or added
  1213. 51:14uh small bits of here's some new threat
  1214. 51:18we need to think about we hadn't thought
  1215. 51:19about and address it and that updates
  1216. 51:21your threat model as well and that can
  1217. 51:23go a lot faster as you uh gain those
  1218. 51:26skills continue to build those skills
  1219. 51:28and so uh again that threat maing
  1220. 51:32process assembling your team diagramming
  1221. 51:35understanding your system identify your
  1222. 51:36threats document your your threats as
  1223. 51:40well as your mitigations review and
  1224. 51:43followup and so that last of the threat
  1225. 51:46Ming mindset is it's active review
  1226. 51:50follow through uh it's not just an
  1227. 51:52exercise where we talk about this stuff
  1228. 51:53and it's all great but do something
  1229. 51:55review follow through uh and and uh
  1230. 51:59determine you know where the mitigations
  1231. 52:01fit and work on those as you can and if
  1232. 52:03you
  1233. 52:04can all right so key takeaways pursue a
  1234. 52:08threat moding mindset be strategic think
  1235. 52:12of secure design uh before you start new
  1236. 52:15features that's
  1237. 52:16ideal ask what if and what could go
  1238. 52:20wrong
  1239. 52:21questions focus on and be prepared where
  1240. 52:24defenses May Fail
  1241. 52:27actively review follow through and
  1242. 52:29repeat as needed so build that in as
  1243. 52:32well that opportunities to go back and
  1244. 52:34review your threat model and update your
  1245. 52:36threat model U as you go along
  1246. 52:38especially for those new features as you
  1247. 52:40may add
  1248. 52:42them uh some resources we mentioned this
  1249. 52:45before the threat Ming
  1250. 52:47Manifesto uh the capabilities that
  1251. 52:49really help uh if you're in your
  1252. 52:52organization trying to figure out how do
  1253. 52:54I add threat modeling is there a good um
  1254. 52:58Playbook about some of the things I
  1255. 52:59probably should consider uh the
  1256. 53:01capabilities model is is a great um U
  1257. 53:05document to help you with that and then
  1258. 53:08uh some books great books out there and
  1259. 53:11um uh these are a couple I like to point
  1260. 53:13to um for Applied threat Ming hacky
  1261. 53:16kubernetes really good book about uh
  1262. 53:19detailing for for those authors on how
  1263. 53:22they were uh protecting their kubernetes
  1264. 53:25uh instance uh applying uh stride
  1265. 53:29applying data flow diagrams but also
  1266. 53:31applying attack trees if you're
  1267. 53:32interested we didn't talk about that in
  1268. 53:34detail today uh but they also show how
  1269. 53:36they use the tack tree so very good
  1270. 53:38resource and then uh this other uh the
  1271. 53:41playbook for threat Ming medical devices
  1272. 53:43another uh interesting applied threat
  1273. 53:45modeling as well and there's some other
  1274. 53:47resources and by the way uh the resource
  1275. 53:49pack I would recommend that you check
  1276. 53:51out uh there was a link I think that was
  1277. 53:54shared in the previous session
  1278. 53:56uh but um uh you should be able to find
  1279. 53:58that for the hackathon uh the resource
  1280. 54:00pack as well as participant um list as
  1281. 54:03well of items uh you can take a look at
  1282. 54:06uh to learn more uh examples and so on
  1283. 54:10all right so we're at the basically at
  1284. 54:12the end um and yes absolutely sh slides
  1285. 54:15will be shared we are we already have uh
  1286. 54:18there's a pdf version of this already
  1287. 54:21been shared uh so that should go out I
  1288. 54:23think to to participants
  1289. 54:26any
  1290. 54:27questions got a couple minutes
  1291. 54:33left um just one um I noticed during the
  1292. 54:37exercises uh it was probably maybe an
  1293. 54:39extract on on on thread dragon and then
  1294. 54:43we also had the table that we were
  1295. 54:45populating on the side uh was just uh
  1296. 54:48something is it just good uh Cadence to
  1297. 54:51let's say I'm using a thread Dragon
  1298. 54:54normally you would put your notes in
  1299. 54:55there is it also like good um sort of
  1300. 54:59like Cadence to then do the extraction
  1301. 55:01and have like a SE separate template
  1302. 55:03like the one that we were using just to
  1303. 55:05report
  1304. 55:07differently uh and provide in terms of
  1305. 55:10information and everyone to be able to
  1306. 55:12read through that in terms of best
  1307. 55:14practice uh really is itth do I need to
  1308. 55:17capture everything on the dragon or
  1309. 55:20dragon and then have an extract of the
  1310. 55:23same data on an Excel sheet that I could
  1311. 55:26probably
  1312. 55:27circulate yeah great question um what
  1313. 55:31and I'll probably defer to uh shoing as
  1314. 55:34well but in general good idea uh there
  1315. 55:38are tools that can help you uh capture
  1316. 55:40that information the threats and so on
  1317. 55:42uh for the hackathon we're asking that
  1318. 55:44teams not use tools like that in
  1319. 55:47particular drawing tools and uh
  1320. 55:50recording of some sort uh document of
  1321. 55:52some sort uh but but not uh using those
  1322. 55:56tools but shining do you want to give
  1323. 55:58some more um comment on that yeah so we
  1324. 56:02will defer those questions to the prom
  1325. 56:04questions channels for the chief judge
  1326. 56:07Sten resp yeah okay appreciate it thank
  1327. 56:11you uh but in general it is you know
  1328. 56:14whatever tool works for you to record to
  1329. 56:16to keep track if you're you're working
  1330. 56:18on a threat model with your team um is a
  1331. 56:21good idea but in in this case yeah
  1332. 56:23absolutely check with the hackathon uh
  1333. 56:25rules uh specifically for resources to
  1334. 56:28use okay cool thanks
  1335. 56:34welcome awesome let's give Robert her
  1336. 56:38another virtual big round of applause
  1337. 56:40for such an amazing amazing Workshop
  1338. 56:43thank you Robert thank
  1339. 56:46you all of us all right thank you
  1340. 56:49everyone for joining us for this
  1341. 56:51Workshop we will email you the slides
  1342. 56:54and the recording um for this events you
  1343. 56:56know whether or not you're the hackathon
  1344. 56:58participant but you will get that by an
  1345. 56:59email later today but those hackathon
  1346. 57:01participant head back to the hackathon
  1347. 57:03slack and there all the resources will
  1348. 57:05be shared there all right so thank you
  1349. 57:07everyone for joining have a great rest
  1350. 57:08of your day thanks all thanks Robert you
  1351. 57:11thank
  1352. 57:13you byee

About this transcript

This page contains the full transcript of Developing a 'threat modeling mindset' following four steps of the threat modeling process by Threat Modeling Connect, generated from the public captions YouTube serves with the video. The transcript has 9,385 words across 1,352 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.