Threat Modelling using STRIDE

Manish Soni

profile
Threat Modelling using STRIDE
profile
3,000
120 mins

As a Product Security Engineer you are expected to do Threat Modelling very often, almost in every release cycle. With Shift Left approach in SDLC, Threat Models became a prominent tool to Identify Security Threats early in the software lifecycle. An efficient threat model uncovers risks early, identify controls that need to be implemented, and will save a lot of Time, Effort and Cost of patching a security vulnerability.


This is a quick learning session for creating an effective Threat model. By end of this session, you should be able to What, Why and How to disgn a Threat Model.


The whole session is based on my decade of experiece that I have collected by doing Threat Models across multiple projects. If this session we will cover following topis :

  1. What is a Threat Model ?
  2. Why we do a Threat Model ?
  3. Baseline vs Increamental Threat Model.
  4. What are the outcomes of a Threat Model ?
  5. Who should do the Threat Model ? Who should be the stake holders ?
  6. What is STRIDE ?
  7. What are other Threat Model Framework ?
  8. Lets do a Threat Model Using STRIDE. We will discuss a reference architecture and will do a Threat Model.
  9. Stages of a Threat Model.
  10. Threat Model report and Vulnerabiltiy Reporting.
  11. How to tackle a Developer who is not accepting a Vulnerability.
  12. Many more interesting stuff !


Pre-requisites:

  1. Basing understanding of OWASP Vulnerabilities. https://owasp.org/www-project-top-ten/
  2. Product security mindset !
  3. Good to have Some Industry Experiece, but thats not a blocker.


So, If you really want to learn Threat Modelling. I am sure this session will be helpful for you in your learning journey.




Testimonials