Developing a 'threat modeling mindset' following four steps of the threat modeling process — Transcript
Full transcript
- 0:00welcome to the threat modeling Workshop
- 0:02developing a threat modeling mindset by
- 0:04Robert heret like I said this is
- 0:06originally designed for our hackathon
- 0:09participants um but we decided to open
- 0:11it to all TMC member because it's just
- 0:13something too give to not to share with
- 0:15a Brer community so whether or not
- 0:17you're in the hackathon and we hope we
- 0:20believe that this you will find this
- 0:22Workshop really really helpful and this
- 0:24is a workshop that's been featured in
- 0:26many many major security conferences um
- 0:29incl our very own F Monon and it's get
- 0:32so much great feedback so you're really
- 0:34in for a treat um now Robert is offering
- 0:38this to all the TNC members so enjoy I'm
- 0:41going to introduce Robert herit with our
- 0:44speaker and Robert over to you all right
- 0:46yeah thanks and welcome everyone uh
- 0:48really glad to be here and to uh be able
- 0:51to present on developing a threat moding
- 0:54mindset as shoing mentioned this is a u
- 0:58Workshop that I've done in person at uh
- 1:01threat modcon uh at least a couple of
- 1:04them in the last two years as well as
- 1:06some other places uh this is really u
- 1:09based on a presentation I put together a
- 1:13few years ago where I was inspired by uh
- 1:17this thought of uh security folks have a
- 1:21certain mindset they can see things a
- 1:23certain way if they see a door open uh
- 1:26if they see uh some things that are you
- 1:29know ports open and so forth uh they
- 1:32have a particular mindset and I thought
- 1:34you know threat moding I think uh has a
- 1:37mindset as well especially as you learn
- 1:40about it and start to apply uh some of
- 1:42the process to what you're doing uh then
- 1:45you develop that mindset and I think
- 1:47anyone can and so that's really the sort
- 1:50of the background of uh this uh workshop
- 1:54and and turning into a workshop uh
- 1:57Beyond a presentation
- 2:00so uh what are we going to be doing
- 2:01today we're going to be going through uh
- 2:03introducing the threat Ming mindset as
- 2:05well as walking through the threat
- 2:07moding process uh we do have some
- 2:10learning and exercises we'll have at
- 2:12least a couple of breakout uh
- 2:15opportunities uh breakout groups where
- 2:17we're going to be meeting uh with a
- 2:20number of folks who are uh volunteering
- 2:22their time today to help you out uh and
- 2:25we're we'll go through some of the
- 2:26exercises and then we'll come back
- 2:28together we'll talk about some of the
- 2:30things that you found and then we'll
- 2:32continue on uh but at least going to be
- 2:34doing two of those uh today and then at
- 2:38the end of course we'll have some
- 2:39questions and answers uh and and
- 2:41hopefully uh we could answer all the
- 2:43questions you have today all right so
- 2:46who am I um I am a principal application
- 2:48security architect as well as TR Ming
- 2:50lead at Aquia uh at least for right now
- 2:53um until the end of the month I'm
- 2:55actually looking at some other work here
- 2:57soon uh but other things I'm doing I'm a
- 3:00co-host with Chris Romeo of the
- 3:02application security podcast we're now
- 3:04over eight years uh going into our ninth
- 3:07year actually of running the application
- 3:09security podcast I'm also a co-author of
- 3:11the threat Ming Manifesto uh threat Ming
- 3:13capabilities and a co-founder of the
- 3:15threat Ming connect and as I mentioned
- 3:17I've had opportunity to present uh this
- 3:20workshop at a couple of the um hack or
- 3:23sorry the threat mod cons as well as a
- 3:26PhD student um focused on Space cyber
- 3:29security uh the next
- 3:31Frontier uh previously I uh started and
- 3:34led the threat Ming program at Bank of
- 3:36America where uh we were able to put
- 3:39together uh almost 1500 threat models
- 3:41over three years working with lots and
- 3:43lots of teams lots of developers um at
- 3:45one time we did put some uh training
- 3:47together for 45,000 developers uh at
- 3:50Bank of America required uh learning
- 3:52about threat modeling so it was a really
- 3:54uh fun time and a lot of what I learned
- 3:56there and in other places over the years
- 3:58whove sort of gone into this uh Workshop
- 4:02how to help uh folks as are beginning in
- 4:05threat modeling how to learn uh some of
- 4:08the the basic uh steps and process and
- 4:11how they can apply it to the work that
- 4:12they're
- 4:14doing so again what are we looking to do
- 4:17develop a threat Ming mindset through
- 4:19Hands-On learning about uh the threat
- 4:21Ming process so just to start off with
- 4:25what is a threat moding mindset well
- 4:28first of all I wanted to mentioned to
- 4:30you that you know threat modeling is
- 4:32something we're already doing in our
- 4:33personal lives and first and foremost I
- 4:36want to mention that a threat model or
- 4:38threat modeling activity itself is a
- 4:40thinking activity there are a lot of
- 4:43great tools that you can use for
- 4:46analyzing systems uh but a threat model
- 4:49uh building a threat model is really a
- 4:51thinking activity and so with that in
- 4:54mind it again it's something we're
- 4:56already doing in our personal lives for
- 4:59example when we lock our doors to our
- 5:01house or the windows uh we lock the
- 5:03doors to our car or even when we look
- 5:06around across the street we're thinking
- 5:09about what could happen what could go
- 5:12wrong uh if I look around when I'm
- 5:15crossing the street what am I looking
- 5:17for uh you know just in case a car is
- 5:19coming down the road I need to make sure
- 5:21I'm safe I need to make sure my own
- 5:23personal Safety and Security is insured
- 5:26and so I look around or or maybe there's
- 5:28um a crosswalk uh light that tells me
- 5:31it's ready to go or time to go I look
- 5:33for those kinds of things why because
- 5:35again I am concerned about Safety and
- 5:37Security and what do I need to do uh to
- 5:40handle those
- 5:41situations and so essentially when we're
- 5:43thinking ahead and remember I said to
- 5:45thinking tool it's a thinking activity
- 5:48we think ahead on what could go wrong we
- 5:50ask what if questions we weigh risks and
- 5:53we act accordingly we're doing a kind of
- 5:56threat
- 5:57modeling so the first part part of the
- 6:00mindset is it's strategic versus
- 6:04reactive uh and sometimes you can also
- 6:06say proactive and that's ideal but the
- 6:09the main thing here is strategic we're
- 6:11thinking ahead uh versus just hoping we
- 6:14are safe and and just whatever happens
- 6:16happens uh but instead trying to think
- 6:18ahead and plan ahead now that personal
- 6:21what we do in our personal lives that's
- 6:23intuitive but it's something that we can
- 6:25also uh push into the work that we're
- 6:28doing the systems that we're
- 6:30viewing and with that in mind uh I was
- 6:33as I mentioned a co-author of the threat
- 6:35Ming Manifesto and we adopted the four
- 6:38question framework Adam Shack had
- 6:40invented these uh questions and we
- 6:43adopted it into the threat Ming
- 6:44Manifesto what are we working on what
- 6:48can go wrong what are we going to do
- 6:50about it and did we do a good enough job
- 6:53and you'll see in this Workshop we apply
- 6:55those questions uh quite often in the
- 6:58process it's it's really
- 7:00uh underlying a lot of what we are
- 7:02doing when we talk about a threat model
- 7:05typically what we are are saying is that
- 7:08we think about a threat model that
- 7:10consists of a system representation that
- 7:12could be a description it could be a
- 7:15diagram or or a combination of the two
- 7:17just something that helps us understand
- 7:20and answer that first question what are
- 7:22we working on the next thing is the
- 7:25identified threats what could go wrong
- 7:28what could happen
- 7:30and so those are those threats propose
- 7:32mitigations so that's really answering
- 7:34that question what are we going to do
- 7:36about it and then determining going back
- 7:40and reviewing is there anything else
- 7:42that I missed are there any other
- 7:44mitigations uh that can also lead into
- 7:47the work that needs to be done and and
- 7:49the risk that's associated to help us
- 7:51priorize that work and that back going
- 7:54back and reviewing answers that question
- 7:57uh did we do a good enough job and so
- 7:59the other thing to notice about those
- 8:01questions it's all about we uh there's a
- 8:05reason for that it's a team effort and
- 8:07we heard that from Avi if you attended
- 8:09the uh session earlier uh it's a team
- 8:12effort uh when we're looking at building
- 8:15a threat
- 8:16model so uh taking those four questions
- 8:19and and sort of turning them into a a
- 8:22process similar steps uh those those
- 8:25four steps this and represents those so
- 8:28first of all I always say assemble the
- 8:31team uh and this little diagram that's
- 8:33the defined part diagram understand your
- 8:36system that's where we're uh answering
- 8:38that question about uh what are we
- 8:40working on identify threats what could
- 8:42go wrong document so identify and
- 8:46mitigate that's where what are you going
- 8:47to do about it and then that final is do
- 8:49we do a good enough job uh go back and
- 8:52review and and potentially uh followup
- 8:56validate so let's talk about assembling
- 8:58the team ideally you include de software
- 9:02developers testers Architects project
- 9:04managers uh many other folks that are
- 9:07part of your team other stakeholders and
- 9:10for this Workshop today uh we will
- 9:12divide as I mentioned this larger group
- 9:15into breakout groups to represent
- 9:17different teams as we take a look at and
- 9:19build a threat
- 9:23model now getting started very very
- 9:26simple tools really uh for diag pring
- 9:29you can use a whiteboard if you have a
- 9:32team together uh or you could use a
- 9:34virtual whiteboard I've done that many
- 9:36times where if we're all remote we can
- 9:38get on uh a zoom call or something
- 9:41equivalent and uh and take a look at a
- 9:44diagram or just ask questions and and
- 9:46record that information and in terms of
- 9:48recording it's really important to
- 9:51document uh what you find what you think
- 9:53about uh questions that were asked and
- 9:55answers to those questions and so you
- 9:57can use of course word or Cel Confluence
- 10:00J whatever makes sense for your team uh
- 10:03of course for this uh hackathon you know
- 10:05we encourage you to to document uh some
- 10:08of that information in the final threat
- 10:10model so that uh the judges can be able
- 10:12to to review uh what you're thinking
- 10:15what your thought process and so forth
- 10:19was and as mentioned today for this
- 10:21Workshop we'll be using a mural page uh
- 10:24to diagram uh and record threats and
- 10:26mitigations as far as the diagram part
- 10:28we're going to look at that
- 10:29uh we're not actually going to break out
- 10:31and draw a diagram but we're stly going
- 10:33to review a diagram
- 10:36today so just to take a step back let's
- 10:39talk a little bit about understanding
- 10:41bugs versus flaws in 2015 the itle
- 10:45computer Society Center for secure
- 10:47design uh put out this paper on avoiding
- 10:51the top 10 software security design
- 10:54flaws and for me it's just been a a
- 10:57really good resource to go back too
- 10:59there are a lot of uh great uh things
- 11:01listed there about for example uh don't
- 11:04get authentication and authorization
- 11:06confused always remember to authorize
- 11:10after you authenticate don't roll your
- 11:11own cryptography and so forth but the
- 11:14main key uh things to take away from the
- 11:17paper is the difference between a bug
- 11:20and a flaw a bug and implementation
- 11:23level software problem we have lots of
- 11:25tools that can find bugs n plus1 issues
- 11:28and so on
- 11:30a flaw on the other hand a design flaw
- 11:32is a deeper level problem it's the
- 11:34result of a mistake or oversight at the
- 11:37design level and much of what we're
- 11:39doing in threat modeling is we're really
- 11:41focused on the flaws we're trying to
- 11:43identify design flaws to improve secure
- 11:47design we're trying to understand
- 11:49underneath what were the decisions made
- 11:52and or going to make if we're building a
- 11:55threat model for upcoming
- 11:57work and so looking at the difference
- 12:00between those two secure security coding
- 12:03bugs you know coding errors requires
- 12:05developer understanding the secure
- 12:06coding um can be automated to find those
- 12:10and patching is less costly in
- 12:12production on the other hand security
- 12:14design flaws represent errors in design
- 12:18security requirements architecture
- 12:20typically need contextual knowledge and
- 12:23very difficult to automate Define these
- 12:26design flaws and also very cost L to
- 12:29change in production I've seen that many
- 12:31times for example if you didn't start
- 12:34with thinking how you wanted to do
- 12:36authorization how you wanted to do
- 12:38access checks it can be very costly to
- 12:41go back and retrofit so those are things
- 12:44that we're talking about those design
- 12:46decisions and related to security
- 12:49requirements to think about ahead of
- 12:51time if you can and again what threat
- 12:53mauling is really great uh to help you
- 12:55to
- 12:56do the other thing I'll mention about
- 12:59any typical threat moding session and it
- 13:01doesn't have to be so formal um it can
- 13:04be just simply a few minutes to take a
- 13:06look at a story and understand what's
- 13:08going on but these are some typical
- 13:11things that I I like to see or or think
- 13:13are are good recommendations first of
- 13:15all you know domain knowledge and that's
- 13:17where the team comes into play do they
- 13:20understand the system do we do we have
- 13:22that um understanding of what we're
- 13:24trying to build uh again it's a team
- 13:26effort also understand your business and
- 13:29Technical goals you know when you're
- 13:31thinking about security and design um
- 13:35we're always in relation to some of the
- 13:37business and Technical goals as well the
- 13:39other thing I'll mention is it's focused
- 13:42um we don't spend hours and days and
- 13:45days on threat models instead be focused
- 13:48because it's going to help you um get
- 13:51some of the main things you're looking
- 13:52for the other thing is you can also
- 13:55unfortunately if you spend too much time
- 13:57you can uh hit one of the is we found in
- 13:59the or talked about in the threat mly
- 14:02Manifesto analysis paralysis so be
- 14:05focused on the work that you're doing
- 14:07set aside maybe an hour or something
- 14:09like that to help you the other thing
- 14:12I'll mention uh be honest leave ego at
- 14:14the door and no blaming especially when
- 14:16you're looking at an existing system is
- 14:19these things can really help because you
- 14:21might uncover things and didn't realize
- 14:23assumptions you didn't uh you had before
- 14:26that now need to be questioned so let's
- 14:30do the discovery let's understand and uh
- 14:33it'll really help us in in building a
- 14:35good threat
- 14:37model next of course diagramming
- 14:40understanding your system and data
- 14:41flows so in terms of diagramming and
- 14:45understanding the system as well as data
- 14:46flows we want to document elements of
- 14:48the system and properties affected at
- 14:51minimum document some of the basic
- 14:53elements of how the system works
- 14:55security concerns of any properties and
- 14:58as uh those of you who are going through
- 15:00the hackathon there's uh a description
- 15:04of the system take a look at it uh ask
- 15:07some questions about it understand what
- 15:09it's saying now there's some things that
- 15:11may be there they're not there and so
- 15:13forth but note those as well so that'll
- 15:16help you to understand that
- 15:19system in terms of a data flow diagram
- 15:21you can certainly start with a network
- 15:23diagram or an architecture diagram um
- 15:26the value of a data flow diagram and
- 15:28threat moding is uh one you're trying to
- 15:32understand uh one of the most important
- 15:35assets to a system which is typically
- 15:37the data and how that data um is used in
- 15:41the system you know accessed and where
- 15:43is the data stored and who has um access
- 15:46to that data uh and so on and so with
- 15:49that in mind typically when you're
- 15:50drawing a a data flow diagram or any
- 15:53diagram you're you're trying to
- 15:55understand some of the basic components
- 15:58here in terms of the DFD we look at
- 16:01external entity to start with uh that
- 16:03represents entities that we just don't
- 16:06have direct control over so that could
- 16:08be uh users of our system they're
- 16:11external to our system but they're
- 16:13interacting with our system or other
- 16:15systems maybe other apis that we're
- 16:17calling um browsers that users are using
- 16:20to connect to our web application for
- 16:22example all of those can be represented
- 16:24as external entities a process on the
- 16:27other hand uh represented by by that
- 16:29circle is something that we do have
- 16:32direct control over maybe it's a
- 16:33component we wrote maybe it's um a piece
- 16:37of software that we're configuring but
- 16:39we again we have some direct control
- 16:40over and so we want to distinguish that
- 16:44from the
- 16:45entities data stores represent data
- 16:49where is that data uh being stored and
- 16:52in particular it could be files so
- 16:54something you may not always see in an
- 16:56architecture diagram config files log
- 16:58files files other kinds of files uh
- 17:00database tables registry cache cookies
- 17:03anywhere that data may be stored within
- 17:05the
- 17:06system data flows help us understand how
- 17:10data is flowing through the system so
- 17:13going from perhaps an external entity to
- 17:16a process or the process in turn storing
- 17:19it into the data store how is that data
- 17:23flowing and one thing I'd recommend when
- 17:25you draw data flows first of all show
- 17:27the direction but also
- 17:29label it so that we understand what it's
- 17:31doing as well as perhaps uh the protocol
- 17:34use for example is it HTTP https and so
- 17:38on and that'll help especially as we
- 17:40start to identify threats what uh are
- 17:44some of these rather
- 17:45unencrypted uh what kind of data is
- 17:47traveling is that sensitive data that
- 17:49needs to be encrypted and so on and then
- 17:52finally the the last concept here is
- 17:55trust boundaries trust boundaries help
- 17:57us understand and uh where trust may
- 18:01change as those data flows go through
- 18:04the system connecting from an entity to
- 18:07a process or process to a data
- 18:09store the main thing about a trust
- 18:11boundary is as it mentions inside you
- 18:13trust the processes and data stores
- 18:16outside you don't another thing I like
- 18:19to think about is that as you cross that
- 18:21boundary with the data flow is that a
- 18:24place where you more than likely need to
- 18:27check trust for example authentication
- 18:30authorization validation and so that can
- 18:33also help you where this is an area that
- 18:35we need uh trust and and recognize that
- 18:39you know as data flows through we need
- 18:41to check that for trust uh when that
- 18:44call comes
- 18:47through and um you know in terms of the
- 18:50hackathon you can use the drawing tool
- 18:51of choice um however we recommend uh
- 18:55typically for if you're if you're
- 18:56building a data flow diagram and there
- 18:57are other things you can do as well
- 18:58we'll show you that in a moment uh try
- 19:00to stay with the basic shapes and
- 19:01meanings for
- 19:04consistency so again drawing a data flow
- 19:07diagram ideally The Logical and
- 19:09component architecture communication
- 19:12flows and how data is um moved and
- 19:15stored within the system so here's just
- 19:18a basic example users and admin those
- 19:21are your entities external entities
- 19:24either server or web app uh is your
- 19:26process and then again data flows
- 19:29um label them uh just so that we know
- 19:31what they are what they're doing uh
- 19:34sometimes you can just use one uh data
- 19:36flow for example that represents both a
- 19:37request and response uh that's up to you
- 19:40how you want to to show that and then of
- 19:42course uh the trust boundary that helps
- 19:44us understand that as that data moves to
- 19:48the the web server the web application
- 19:50um more than likely there needs to be
- 19:52some kind of trust check could be
- 19:54authentication authorization and so on
- 19:56and that's going to help us as we start
- 19:58to look at uh the threats a little bit
- 20:00later using the
- 20:02diagram here's an example this is the
- 20:04OAS threat Dragon 2.0 uh where you know
- 20:07that tool you can draw a data flow
- 20:09diagram in particular but just shows you
- 20:11again some of the uh the basic shapes uh
- 20:15for a data flow diagram representing
- 20:17processes and data flows data stores uh
- 20:20and Trust boundaries as
- 20:23well okay so um this is actually a time
- 20:26when we normally would uh just draw a
- 20:28data flow diagram if we were in uh
- 20:31inperson uh Workshop today uh in the
- 20:34interest of time we're going to actually
- 20:35review a data flow diagram uh that it's
- 20:38represented by um what's what's shown
- 20:40here but we've got uh some actors
- 20:43service staff and a user we've got an
- 20:46authentication provider we have for data
- 20:49stores logs a database uh processes a
- 20:52web application web services and so
- 20:55on so here's a diagram and again we're
- 20:59going to look at this in more detail as
- 21:01we break out uh and start to look at
- 21:03threats uh but again representing a web
- 21:06application in this case the user who's
- 21:09an external entity uh using that browser
- 21:12connecting the web application we see
- 21:14web services batch processes uh we also
- 21:17see another type of user a service staff
- 21:20using a client application connecting to
- 21:22a database and if you notice over there
- 21:24on the on the uh right hand side we have
- 21:27partner organizations authentication
- 21:29provider we also have third-party data
- 21:31and service participants so a lot of
- 21:33different things going on in this this
- 21:35simple diagram uh representative to help
- 21:38us understand uh some of the the types
- 21:41of things that we might see in a typical
- 21:43web application uh that we're going to
- 21:45be looking at today for this
- 21:49Workshop so let me just check the
- 21:52uh the chat for a moment see if there
- 21:55are any questions
- 21:59okay I don't see any at the moment all
- 22:01right uh so we've drawn our data flow
- 22:05diagram we've asked questions about how
- 22:07the system works we're we're trying to
- 22:10uh get some answers to those questions
- 22:12and and that'll help us understand um
- 22:14the system better now let's start to
- 22:16identify
- 22:19threats when we do that um essentially
- 22:23and going back to our mindset uh the
- 22:25mindset of a threat minding mindset is
- 22:27first of all we mentioned strategic
- 22:29thinking ahead the next part of a threat
- 22:31Ming mindset is asking questions what if
- 22:34what could go
- 22:36wrong uh we like to typically start with
- 22:38stride uh you don't have to use stride
- 22:41and in fact I have another slide that
- 22:43talks about many other methods as well
- 22:45but stride is a good place I think to
- 22:47start just to understand some of the
- 22:49most basic security issues uh that you
- 22:51might see within uh many software
- 22:54systems so stride is a nemonic
- 22:58representing uh spoofing tampering
- 23:00repudiation information disclosure
- 23:02denial service and elevation of
- 23:05privilege if you notice uh to the right
- 23:08the are of the threat property violated
- 23:11uh these are some of the most basic
- 23:12security issues that you see within
- 23:15systems uh for example we have CIA
- 23:19confidentiality integrity and
- 23:21availability uh we also have uh
- 23:24essentially The Three A's authentication
- 23:26authorization and sometimes
- 23:27non-repudiation
- 23:29is called
- 23:30auditability but looking at each of
- 23:32these spoofing pretending to be
- 23:34something or someone other than yourself
- 23:36you're looking for um ways to identify
- 23:39or the lack of identification do I
- 23:42really know who this person is or this
- 23:44service that's calling uh my services
- 23:47have I identified them tampering
- 23:50modifying something on disk Network
- 23:52memory or elsewhere what we want there
- 23:55as I mentioned is data Integrity so
- 23:57we're looking look for ways that an
- 24:01attacker might change the data that we
- 24:04rely on and uh has that been protected
- 24:08against and so that's the Potential
- 24:09Threat there
- 24:11repudiation is really about uh claiming
- 24:15you didn't do something or not having a
- 24:18proof of that happening and
- 24:20non-repudiation is the proof uh so for
- 24:24example in a system logging or the lack
- 24:27of logging
- 24:29could be an example of repudiation and
- 24:31non-repudiation the logs themselves the
- 24:34audit Trail uh that's an example of
- 24:37non-repudiation within a system and so
- 24:39many times when you look at a system are
- 24:42we monitoring are we logging and and
- 24:44have sufficient information to
- 24:46understand what's happening information
- 24:48disclosure providing information to
- 24:50someone not authorized to see it what we
- 24:53want again is confidentiality and many
- 24:55times that's where encryption comes into
- 24:57play no notice it says to someone not
- 25:00authorized to access it how would they
- 25:02be able to see it well if it's encrypted
- 25:05then they might need a key and so those
- 25:07who have the key provided the key then
- 25:09they would be able to see that
- 25:11information um that's a really important
- 25:13one uh a threat in particular
- 25:16information disclosure we see that quite
- 25:18often in data
- 25:20breaches who has access have we uh
- 25:24limited access to that data denal
- 25:27service uh exhausting resources needed
- 25:30to provide service so you might think of
- 25:32attacks where an attacker is trying to
- 25:35call a lot of pages and try to try to
- 25:38get the system uh to respond to Long
- 25:41running uh queries and so on but it's
- 25:44also the lack of availability as it
- 25:46mentions here related to services that
- 25:49we depend on for example apis that we
- 25:52call what happens if they're not
- 25:54available databases uh down for some
- 25:57reason and we're not able ble to do our
- 25:59work and so those are some other
- 26:01examples of denial of service as you
- 26:03look at a system and finally the most
- 26:05severe of all these threats elevation of
- 26:08privilege relating to allowing someone
- 26:10to do something they're not authorized
- 26:12to do and what we want is authorization
- 26:16or in enforcing some kind of lease
- 26:19privilege so that uh a system or a
- 26:23person within a particular role can only
- 26:25do certain things that they should be
- 26:27allowed to do and no more a regular user
- 26:29should not be able to elevate their
- 26:33privilege which is what the threat is to
- 26:35act as an administrator for example and
- 26:38so are there um situations when you're
- 26:41looking at a a a system and are there
- 26:44places where we haven't done proper
- 26:49authorization so applying all of that to
- 26:52a data flow diagram uh there a couple of
- 26:55options you can use each part of stride
- 26:58uh to apply to a specific element or
- 27:01interactions so for example the web
- 27:04application are there situations there
- 27:06for spoofing uh tampering and so on the
- 27:10other is you can just look at Stride per
- 27:12interaction uh reason being is that
- 27:16typically if let's say a file is never
- 27:19accessed uh only that action of
- 27:22accessing that file allows a threat
- 27:25maybe to be realized and so if you just
- 27:28look at the interactions that can help
- 27:29you uh to start where stride uh and
- 27:33apply stride to determine some potential
- 27:35threats of an act actual uh actor or
- 27:39attacker being able to get access to log
- 27:42files databases and so on so couple
- 27:45different ways to look at it applying
- 27:47stride to anything you see or just
- 27:50starting with the interactions and apply
- 27:52stride
- 27:53there so some examples spoofing user
- 27:57could spoofed by an
- 27:59attacker uh tampering requests from the
- 28:01user to web app may be
- 28:04modified repudiation how would we know
- 28:06actions are performed by the web app
- 28:08information disclosure setting and
- 28:10getting credentials could be exposed in
- 28:12transit um especially if it's if it's uh
- 28:16not encrypted deny service what happens
- 28:19if the authentication Service or
- 28:21provider up there the top right is not
- 28:24available and elevation of privilege
- 28:26does audit data have access control for
- 28:29reading uh so very important as well so
- 28:32those are again are some examples um as
- 28:34we get into our exercise we're going to
- 28:37have an opportunity to look at that data
- 28:39flow diagram and apply uh or think about
- 28:42some threats specifically as I mentioned
- 28:45many many different ways to identify
- 28:47threats and especially in this hackathon
- 28:49you don't have to use stride you're not
- 28:51uh you know you're not locked down to
- 28:53using stride you can use uh many others
- 28:56as uh as you uh understand or seems to
- 29:01apply so lenden for example is privacy
- 29:04focused it's another pneumonic that
- 29:06helps you identify privacy related
- 29:08threats attack trees uh asset or
- 29:11attacker Centric thinking about how do I
- 29:13get from where I am as an attacker to my
- 29:17goal and what are the steps to get there
- 29:19and and outline that and that can help
- 29:20you then determine the mitigations at
- 29:23each point at each node that you may
- 29:25need to apply uh to prevent the attack
- 29:28are getting to the goal uh pasta which
- 29:30is a a risk Centric threat modeling uh
- 29:34process has a number of steps that you
- 29:36can take a look at miter attack or
- 29:39defend uh and there's some others as
- 29:41well depending on the system uh all of
- 29:43those are intrusion Centric knowledge
- 29:45bases they give you uh very specific
- 29:48examples of how an attacker and for
- 29:52example with attack may use to get from
- 29:56uh point a to to final uh goal and
- 30:00various steps along the way so you can
- 30:02certainly take a look at that as well uh
- 30:04card games can help you use case abuse
- 30:06cases can help you lots of different
- 30:08ways to identify threats and so and you
- 30:11know building a threat model or even in
- 30:13this hackathon you have uh some options
- 30:17uh to consider and in uh building out
- 30:19your threat
- 30:21model okay so using stride to identify
- 30:25threats here is uh what we call a uh
- 30:29threat table it helps us to uh do what
- 30:33we talked about at the very beginning uh
- 30:35threat model consists of that system
- 30:38description the identified threats
- 30:42mitigations and uh what are we going to
- 30:44do about it as well as um you know
- 30:48reviewing and followup and so on and
- 30:50that's what this table is going to help
- 30:52you do so here in this case we have a
- 30:55threat partner organization
- 30:56communication to web services may be
- 30:58compromised uh logs for a web
- 31:00application may be tampered with
- 31:03sometimes it may map directly to stride
- 31:05or or whatever
- 31:07uh method you're using to identify
- 31:09threats it's just optional uh it doesn't
- 31:12have you don't have to say what it is
- 31:14maybe you determine a threat uh that
- 31:16doesn't fit nicely and neatly uh into uh
- 31:19whatever uh categorization that you're
- 31:21using and that's okay uh the key is that
- 31:25the idea behind that is just how did you
- 31:27arrive at that threat where did that
- 31:28come from it's just to help us uh to uh
- 31:31in your thinking of looking for those
- 31:34threats all
- 31:36right uh some other things I'll mention
- 31:40when you're identifying threats and
- 31:41asking questions is who's interested in
- 31:44the apps Andor data those threat agents
- 31:48uh what are their goals so what assets
- 31:50are do you think they're looking for uh
- 31:53what are the attack methods how what do
- 31:55you think uh are some ways that they
- 31:58might try to attack the system are there
- 32:00any attack surfaces trust boundaries for
- 32:02example exposed and are there any input
- 32:06output data flows missing i' see one
- 32:08common one is uh file uploads you know I
- 32:12rely on a file an XML file Json file or
- 32:15something like that well that's input
- 32:18you know how is that uh checked how's
- 32:21that validated and so on so uh those are
- 32:24important as well as you're as you're
- 32:26thinking about uh input and then the
- 32:28data flows also that uh come into your
- 32:32system all right so we're in our first
- 32:36exercise and uh this is going to be uh
- 32:38new for me to to try to do this in uh at
- 32:41least for in Zoom uh but we're going to
- 32:44have some breakout groups and um we're
- 32:46going to spend about 1015 minutes uh and
- 32:50uh work with each of our volunteers and
- 32:52then we'll back and view for a few
- 32:54minutes and then continue on so I'll
- 32:57turn to with you sh I think you're in uh
- 32:59in charge of that okay so how was that
- 33:01for everybody uh were there some
- 33:03interesting threats that you
- 33:05noted in looking at this particular
- 33:08diagram anybody like to share for do a
- 33:12couple minutes of
- 33:14that either on chat or in chat or you
- 33:18can come off mute it's
- 33:19fine uh yeah uh this is hi this is Ali
- 33:23uh can I speak yes please okay um
- 33:26actually uh we had a healthy discussion
- 33:28in our room so the first is basically
- 33:30regarding considering the threat the
- 33:32trust boundaries from the external
- 33:34browser to the internal um Network I
- 33:37should say so the user request can be
- 33:41spoofed um uh and it will compromise the
- 33:45um I should say the the spoofing of the
- 33:48stride model and the mitigation could be
- 33:51the uh multiactor authentication uh as
- 33:54well the next one could be also be the
- 33:56inbut validation
- 33:58for example uh if the sqli is allowed by
- 34:01our server site so this could lead to
- 34:05the uh authentication first thing it
- 34:08could be elevation of privileges as well
- 34:10uh this is the next point from the
- 34:13services staff if they are related to
- 34:15our internal uh employees and they're
- 34:20directly accessing the client
- 34:21application The Insider threat could be
- 34:24um a threat uh the uh uh the the
- 34:27mitigation for this one can be the
- 34:30multifactor authentication and the need
- 34:32to know basis and the relevant category
- 34:36for those application could be elevation
- 34:38of privileges this is the first thing
- 34:40and the authorization if access review
- 34:42were not done comprehensively and next
- 34:44one is from from the web application
- 34:46sorry interrupt me if I am speaking too
- 34:49much no that's okay uh and and
- 34:51appreciate it actually you're jumping
- 34:52ahead a little bit to the next part
- 34:54we're going to be looking at mitigations
- 34:55here in a moment but excellent threats
- 34:58and uh yeah we're going to be joining
- 34:59back in our our breakout groups to take
- 35:01a look at some mitigations of the
- 35:02threats we identified uh but appreciate
- 35:05some of the ones that you uh you
- 35:06identified there and shared with us uh
- 35:08thank you anybody else another threat
- 35:11that we haven't already talked about
- 35:12that just jumped out for your
- 35:15team so Robert one of my group which I
- 35:18was facilitating uh they also mentioned
- 35:21about the third party um you know supply
- 35:24chain risk they did call out that even
- 35:28though there's a t boundary um we we
- 35:31need to be specific we need to note it
- 35:34down yes great great call out all right
- 35:38fantastic one of my team member talk
- 35:41about the partner organization they are
- 35:43using FTP and they can AR they can
- 35:46modify the data uh in the database
- 35:49directly because there's no
- 35:50authentication right right yeah and and
- 35:55go ahead sorry so there was one more
- 35:57like three there's a lack of the trust
- 35:58boundary in the logs right so anybody
- 36:01can who is having an access to the web
- 36:03application they can access the logs
- 36:06directly they might be able to yeah it's
- 36:09not clear but yeah this a good that's a
- 36:12good point can anybody access it doesn't
- 36:15really specify it doesn't really let you
- 36:17know how that happens and those are
- 36:19things that uh and great point you may
- 36:22need to go back and ask questions again
- 36:25and you know there's some things that
- 36:27are missing here there's some things
- 36:28that you know in terms of
- 36:30underlying how does this work how does
- 36:32that work and so forth and and so great
- 36:35points to continue to ask questions when
- 36:38you look at a diagram or or you're
- 36:40thinking about a system or or trying to
- 36:43understand a system rather ask good
- 36:45questions like those to to clarify okay
- 36:48well who has access to those logs and
- 36:50how do they get access to those logs so
- 36:52great great uh call outs do we take the
- 36:55perspective of no assumptions or do we
- 36:59you know CU I mean obviously there's not
- 37:02enough data here really to do anything I
- 37:04mean you can call out everything in the
- 37:05sun based upon this threat model of
- 37:07course there's there's very little data
- 37:10in terms of how the application works
- 37:12what the exercises are going to be like
- 37:15uh really and the the purpose is just to
- 37:17find what just a few that you can you're
- 37:19not going to find all and and like you
- 37:20said there's lots here because we just
- 37:22don't know everything so that's that's
- 37:24the purpose is just exercising being
- 37:27able to identify some
- 37:30threats great all right well thank you
- 37:33everyone so getting back to the threat
- 37:36muling mindset uh this is a quote from
- 37:39Adam Shack's book uh threat muling
- 37:40designing for security threat Ming is a
- 37:43use of abstractions to Aid in thinking
- 37:45about
- 37:46risks threat modeling is the key to a
- 37:48focused defense without threat models
- 37:50you can never stop playing whack-a-mole
- 37:53and so key there is threat muling is
- 37:56focused defense and so another part of
- 37:58the threat modeling mindset is to be
- 38:01prepared that focused defense and so
- 38:03that's where we're getting into
- 38:05mitigations or that third question what
- 38:07are you going to do about
- 38:10it always recommend you document what
- 38:12you
- 38:13find these are some uh typical examples
- 38:17very common examples to address issues
- 38:20with stride so you know you want
- 38:23identity Assurance authentication uh
- 38:25this was already mentioned as potential
- 38:27mitigations two-factor multiactor
- 38:29authentication for example for spoofing
- 38:32uh if you look at availability Den all
- 38:34Service uh issues there you want rate
- 38:37limiting or throttling you want
- 38:38real-time monitoring uh things like that
- 38:41lease privilege you want uh system that
- 38:44has an Central authorization engine
- 38:46that's always ideal authorization
- 38:49controls uh system limits and system
- 38:52uses roles accounts permissions and so
- 38:55forth to help manage access lots of
- 38:58different good Solutions there and so
- 39:00again just some example controls that
- 39:02are pretty typical if you're thinking
- 39:04about stride uh but the key is
- 39:07understand the threat and what are some
- 39:09ways to get to what we need we need
- 39:12confidentiality we need availability we
- 39:15need data Integrity how do you ensure
- 39:18that so that's the key thing about what
- 39:20are we going to do about it now there
- 39:23are some mitigation options for example
- 39:26you can leave as is you determine
- 39:28there's a threat but there's no good way
- 39:31to fix it perhaps and or maybe uh the
- 39:35threat is we just note it but it um it's
- 39:39it's the possibility of it is extremely
- 39:42low and so you just simply leave the
- 39:44system as it is uh if you find a
- 39:47particular uh part of the system that is
- 39:50prone to threats and you you haven't got
- 39:52a good countermeasure in place yet you
- 39:54can just simply remove that feature from
- 39:56the product until you fix it or remedy
- 40:00it with a technology countermeasure you
- 40:02know set up a story around it and add
- 40:05that better mitigation or countermeasure
- 40:08in place uh the other one is warn user I
- 40:11see that quite often for example if I go
- 40:13to a coffee shop and it says free Wi-Fi
- 40:17anybody can connect and but the warning
- 40:20is uh realize it's completely open
- 40:23anybody is connecting anybody can see
- 40:26potentially your traff traffic if
- 40:27certainly if you're not using https or
- 40:30other means to uh encrypt your own uh
- 40:32traffic and so warn user that's another
- 40:36one uh that you can do as well with the
- 40:37mitigation option um we I like to
- 40:40recommend that you make the mitigations
- 40:42and counter measures part of your
- 40:43security acceptance criteria that helps
- 40:46you understand uh what's a threat did I
- 40:49have a way do I have a good way of
- 40:51countering
- 40:52that now some other things about uh that
- 40:56continues on with uh thinking about what
- 40:59we going to do about it is determining
- 41:01risk uh what's a risk associated with
- 41:04the vulnerability and the threat
- 41:05identified if we don't fix it what is
- 41:08the risk of this happening now uh we're
- 41:11not going to go into all the details
- 41:13about risk but it's Essence typically
- 41:17risk is uh what we consider as two
- 41:20factors ease of
- 41:22exploitation and the business impact if
- 41:24that risk or that threat was realized uh
- 41:27in terms of risk management you know
- 41:29certainly as I mentioned there's some
- 41:30others you can do for example Fair uh
- 41:33which is um a particular
- 41:35analysis uh tool that you can use or
- 41:38just at as very simplest risk rating
- 41:40high medium low based on ease of
- 41:44exploitation if it's if it's easy to
- 41:47exploit that's high the business impact
- 41:50if it's a Major Impact to our system
- 41:52that's also High and the combination of
- 41:54those two maybe the risk rating is high
- 41:57or or critical and so uh you can put
- 42:00those two together and try to figure out
- 42:02you know what your risk rating is some
- 42:03of that of course is sub subjective but
- 42:06it's it's a way of trying to help you
- 42:08determine um what are my priorities once
- 42:11I determine certain things are critical
- 42:13I probably need to fix those first um
- 42:16maybe uh uh Beyond some of the others
- 42:18that I need to fix as well
- 42:20later and so mapping that out uh here
- 42:24going back to our threat table we had
- 42:27some threats we identified now we also
- 42:29have some mitigations so Implement
- 42:32encryption and we consider that uh
- 42:35communication certainly from the outside
- 42:37as being a high risk uh the apply access
- 42:42control on logs for the uh threat around
- 42:45logs uh we consider that to be medium
- 42:48and uh risk in that case and then also
- 42:51action items and questions so should we
- 42:54limit to TLS
- 42:551.3 uh review the best validation of
- 42:58messages review access control options
- 43:01and so on and so those are some things
- 43:03to to consider when you're you're doing
- 43:06uh or putting together rather some
- 43:07action items to follow up on those
- 43:09mitigations that you
- 43:11identified at a minimum uh what I like
- 43:14to recommend is that uh the thread
- 43:17itself document that the stride mapping
- 43:19if it's relevant it doesn't have you
- 43:21don't have to but sometimes it helps uh
- 43:24and it might uncover some other
- 43:25potential threats as a result
- 43:27mitigations that you currently are
- 43:30implementing or maybe none and uh
- 43:33optionally maybe a risk rating and then
- 43:36also action items so mitigations that
- 43:39are to be implemented uh those few items
- 43:42if you could document that that'll be
- 43:44really helpful and that'll help you in
- 43:45terms of follow up with uh Jura tickets
- 43:48and user stories and other kinds of
- 43:51things that you may need to do as a
- 43:53result of threats you've identified that
- 43:55are not mitigated
- 43:58currently okay so now we're into our
- 44:02second breakout session where we're
- 44:04going to uh follow up with investigating
- 44:07mitigations for some of the threats we
- 44:09identified the the first time uh so if
- 44:12we could uh jump into our next um um
- 44:15breakout group okay how was that uh
- 44:20exercise were you able to figure out
- 44:22some good mitigations for the threats
- 44:24you had identified the first time
- 44:27yeah it was nice it was fun good good
- 44:31any good uh mitigations that you
- 44:33determined if any any team like to
- 44:37share maybe I I'll I'll share one of the
- 44:41uh so we had identified one threat for
- 44:44the uh web application which is uh which
- 44:47we considered as the internet facing
- 44:49application so so there could be a
- 44:52possibility where there could be a Dos
- 44:55attack Okay so service yeah yeah to the
- 44:59end that could be the unavailability of
- 45:01the service so to mitigate that we we
- 45:05kind of introduce u a web application
- 45:09firewall uh in front of the uh internet
- 45:13facing application along with uh the
- 45:16load balancer capability as well for
- 45:18high availability of the application
- 45:21great Al limitation against Brute Force
- 45:25attacks
- 45:28great great anyone else any other
- 45:32observations or yes please uh Ricardo um
- 45:36from our group we had identified that
- 45:39there was a a spoofing threat on the
- 45:41client
- 45:42application
- 45:44um and basically to counter that as a
- 45:46mitigation
- 45:48we uh decided to add
- 45:50the sorry um certificate certificates
- 45:54certificates and so that we could um you
- 45:57know kind of uh show that the
- 46:00application is trusted to uh to a person
- 46:04who is not being D but yeah great great
- 46:10fantastic anybody else hey Robert this
- 46:12is John the team talked about on on the
- 46:15Dos not just the um the WAP but dos
- 46:19protection you know appliances but also
- 46:22putting things behind the CDN so like as
- 46:24example have like front door there's a
- 46:27lot of different CDN options out there
- 46:29and they also mentioned two which I
- 46:30thought was really interesting was
- 46:31around autoscaling which is around
- 46:34resiliency which in some ways does apply
- 46:36a lot from a security threat perspective
- 46:39AB ability right so yeah AB that was a
- 46:42real interesting one I I hope the team
- 46:44doesn't mind that I brought that up but
- 46:47nonetheless hopefully that uh that was
- 46:50something that was really unique I
- 46:51thought in terms of what you guys
- 46:52brought up so very cool um within our
- 46:55team we we talked a little bit about
- 46:57logs and about potential sensitive data
- 47:00in the logs and with that we talked
- 47:02about um you know and this goes back to
- 47:04what we talked about earlier about
- 47:06understanding your domain understanding
- 47:08the
- 47:09business understanding the technical and
- 47:12and goals for each of those and we
- 47:14talked about you know what kind of data
- 47:16is in the in those logs is there any pii
- 47:19any Phi so personal information personal
- 47:23health information uh is if you're in
- 47:25the finance industry
- 47:27what about um any financial information
- 47:30and how you're handling that kind of
- 47:32data in the database as well and so on
- 47:34and and so it's also important to
- 47:37understand again your domain understand
- 47:39some specific um policies and compliance
- 47:44can come in here as well with mitigation
- 47:46and that can can apply to your building
- 47:49out your threat models and thinking
- 47:50about uh not this in a vacuum but
- 47:53instead we're in a business we're in you
- 47:55know a particular domain and the and the
- 47:57kinds of things that we need to think
- 47:59about in terms of secure access and
- 48:02secure data so all those kinds of things
- 48:04came up in in our discussion as well and
- 48:06so uh good call outs on on that
- 48:09information that you need to be aware of
- 48:11and and and so
- 48:14on great all right uh well thanks
- 48:17everyone for for going through that
- 48:19exercise uh really appreciate
- 48:21it so just to sort of uh wrap up here uh
- 48:26in the last parts so we already talked
- 48:29about uh you know documenting elements
- 48:31of the system properties affected the
- 48:32threat threats mitigations and risks and
- 48:35action items action items of course
- 48:37important that not just that we have
- 48:40gone through the exercise but we do
- 48:42something about it um we don't just talk
- 48:44about it but we do something about it
- 48:46and so that's where in that last part
- 48:48did we do a good enough job you go back
- 48:51and
- 48:52review document the findings and
- 48:54decisions file bugs or new requirements
- 48:58uh verify that those are fixed
- 49:01implemented and then about reviewing and
- 49:03just did we do a good enough job do we
- 49:06have a a good confidence in the threat
- 49:08model or is there something else missing
- 49:10so do we miss anything review again is
- 49:12there anything new review again now
- 49:15we've said this before no threat model
- 49:17is going to be perfect you're not going
- 49:19to find everything especially as you
- 49:21start uh one thing you'll find you might
- 49:24get into that analysis paralysis where
- 49:26you find find everything and some people
- 49:29do that like oh everything is bad I
- 49:30don't know you know try to be a little
- 49:32bit more specific if you can um and and
- 49:36be okay with not finding everything
- 49:39because as you continue to build those
- 49:41skills that mindset you'll see things a
- 49:45little differently the next time or you
- 49:47notice something you didn't before and
- 49:49that'll help to continue to improve your
- 49:52threat model as you go
- 49:54along and so again to to wrap up here
- 49:57with our table that review followup
- 49:59address issues in the next Sprint or
- 50:02evaluate if we'll fix in the next Sprint
- 50:03or future Sprint and sometimes you may
- 50:06note it's nothing we can really fix uh
- 50:08we we talked about in our group the
- 50:10third party data and supply chain issues
- 50:13we can certainly do some things on the
- 50:14company's side but we can't do
- 50:17everything on in this case it's an
- 50:20external entity we can't fix everything
- 50:22that they may be doing so there are
- 50:24maybe some things that we need to put in
- 50:25place about questions we ask ask how
- 50:27does it work here how does how do they
- 50:29secure this or that and and have a
- 50:32little bit of understanding but there
- 50:34are some things we may never be able to
- 50:36to solve because it's external and
- 50:39something we depend on so it's good to
- 50:41be able to identify that as
- 50:44well so repeat or iterate as needed
- 50:47consider a baseline threat model for
- 50:49your project if you've never ever
- 50:51created a threat model before and then
- 50:53update in or review your threat model as
- 50:55you continue to add new or updated
- 50:57features and I find that second part
- 50:59goes a lot faster the first time may
- 51:01take a little bit of time you know a few
- 51:04sessions just to get a good Baseline
- 51:06threat model but then after that much
- 51:09faster you'll find your
- 51:11stories continue to be updated or added
- 51:14uh small bits of here's some new threat
- 51:18we need to think about we hadn't thought
- 51:19about and address it and that updates
- 51:21your threat model as well and that can
- 51:23go a lot faster as you uh gain those
- 51:26skills continue to build those skills
- 51:28and so uh again that threat maing
- 51:32process assembling your team diagramming
- 51:35understanding your system identify your
- 51:36threats document your your threats as
- 51:40well as your mitigations review and
- 51:43followup and so that last of the threat
- 51:46Ming mindset is it's active review
- 51:50follow through uh it's not just an
- 51:52exercise where we talk about this stuff
- 51:53and it's all great but do something
- 51:55review follow through uh and and uh
- 51:59determine you know where the mitigations
- 52:01fit and work on those as you can and if
- 52:03you
- 52:04can all right so key takeaways pursue a
- 52:08threat moding mindset be strategic think
- 52:12of secure design uh before you start new
- 52:15features that's
- 52:16ideal ask what if and what could go
- 52:20wrong
- 52:21questions focus on and be prepared where
- 52:24defenses May Fail
- 52:27actively review follow through and
- 52:29repeat as needed so build that in as
- 52:32well that opportunities to go back and
- 52:34review your threat model and update your
- 52:36threat model U as you go along
- 52:38especially for those new features as you
- 52:40may add
- 52:42them uh some resources we mentioned this
- 52:45before the threat Ming
- 52:47Manifesto uh the capabilities that
- 52:49really help uh if you're in your
- 52:52organization trying to figure out how do
- 52:54I add threat modeling is there a good um
- 52:58Playbook about some of the things I
- 52:59probably should consider uh the
- 53:01capabilities model is is a great um U
- 53:05document to help you with that and then
- 53:08uh some books great books out there and
- 53:11um uh these are a couple I like to point
- 53:13to um for Applied threat Ming hacky
- 53:16kubernetes really good book about uh
- 53:19detailing for for those authors on how
- 53:22they were uh protecting their kubernetes
- 53:25uh instance uh applying uh stride
- 53:29applying data flow diagrams but also
- 53:31applying attack trees if you're
- 53:32interested we didn't talk about that in
- 53:34detail today uh but they also show how
- 53:36they use the tack tree so very good
- 53:38resource and then uh this other uh the
- 53:41playbook for threat Ming medical devices
- 53:43another uh interesting applied threat
- 53:45modeling as well and there's some other
- 53:47resources and by the way uh the resource
- 53:49pack I would recommend that you check
- 53:51out uh there was a link I think that was
- 53:54shared in the previous session
- 53:56uh but um uh you should be able to find
- 53:58that for the hackathon uh the resource
- 54:00pack as well as participant um list as
- 54:03well of items uh you can take a look at
- 54:06uh to learn more uh examples and so on
- 54:10all right so we're at the basically at
- 54:12the end um and yes absolutely sh slides
- 54:15will be shared we are we already have uh
- 54:18there's a pdf version of this already
- 54:21been shared uh so that should go out I
- 54:23think to to participants
- 54:26any
- 54:27questions got a couple minutes
- 54:33left um just one um I noticed during the
- 54:37exercises uh it was probably maybe an
- 54:39extract on on on thread dragon and then
- 54:43we also had the table that we were
- 54:45populating on the side uh was just uh
- 54:48something is it just good uh Cadence to
- 54:51let's say I'm using a thread Dragon
- 54:54normally you would put your notes in
- 54:55there is it also like good um sort of
- 54:59like Cadence to then do the extraction
- 55:01and have like a SE separate template
- 55:03like the one that we were using just to
- 55:05report
- 55:07differently uh and provide in terms of
- 55:10information and everyone to be able to
- 55:12read through that in terms of best
- 55:14practice uh really is itth do I need to
- 55:17capture everything on the dragon or
- 55:20dragon and then have an extract of the
- 55:23same data on an Excel sheet that I could
- 55:26probably
- 55:27circulate yeah great question um what
- 55:31and I'll probably defer to uh shoing as
- 55:34well but in general good idea uh there
- 55:38are tools that can help you uh capture
- 55:40that information the threats and so on
- 55:42uh for the hackathon we're asking that
- 55:44teams not use tools like that in
- 55:47particular drawing tools and uh
- 55:50recording of some sort uh document of
- 55:52some sort uh but but not uh using those
- 55:56tools but shining do you want to give
- 55:58some more um comment on that yeah so we
- 56:02will defer those questions to the prom
- 56:04questions channels for the chief judge
- 56:07Sten resp yeah okay appreciate it thank
- 56:11you uh but in general it is you know
- 56:14whatever tool works for you to record to
- 56:16to keep track if you're you're working
- 56:18on a threat model with your team um is a
- 56:21good idea but in in this case yeah
- 56:23absolutely check with the hackathon uh
- 56:25rules uh specifically for resources to
- 56:28use okay cool thanks
- 56:34welcome awesome let's give Robert her
- 56:38another virtual big round of applause
- 56:40for such an amazing amazing Workshop
- 56:43thank you Robert thank
- 56:46you all of us all right thank you
- 56:49everyone for joining us for this
- 56:51Workshop we will email you the slides
- 56:54and the recording um for this events you
- 56:56know whether or not you're the hackathon
- 56:58participant but you will get that by an
- 56:59email later today but those hackathon
- 57:01participant head back to the hackathon
- 57:03slack and there all the resources will
- 57:05be shared there all right so thank you
- 57:07everyone for joining have a great rest
- 57:08of your day thanks all thanks Robert you
- 57:11thank
- 57:13you byee
About this transcript
This page contains the full transcript of Developing a 'threat modeling mindset' following four steps of the threat modeling process by Threat Modeling Connect, generated from the public captions YouTube serves with the video. The transcript has 9,385 words across 1,352 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.