SecurityOrb.com
  • Home
  • Sample Page
  • Masonry Blog
  • Menu Menu

Tag Archive for: you can identify strategies to mitigate potential threats to your system. Your security threat modeling efforts also enable your team to justify security features within a system

You are here: Home1 / you can identify strategies to mitigate potential threats to your system....

Posts

Introduction to Security Threat Modeling

Interesting information about Threat Modeling from AgileModeling.com

Security threat modeling, or threat modeling, is a process of assessing and documenting a system’s security risks. Security threat modeling enables you to understand a system’s threat profile by examining it through the eyes of your potential foes. With techniques such as entry point identification, privilege boundaries and threat trees, you can identify strategies to mitigate potential threats to your system. Your security threat modeling efforts also enable your team to justify security features within a system, or security practices for using the system, to protect your corporate assets.

 

There are five aspects to security threat modeling:

  1. Identify threats.  The first thing to do is to identify assets of interest, you first model the system either with data flow diagrams (DFDs) or UML deployment diagrams. From these diagrams, you can identify entry points to your system such as data sources, application programming interfaces (APIs), Web services and the user interface itself. Because an adversary gains access to your system via entry points, they are your starting points for understanding potential threats.  To help identify security threats you should add “privilege boundaries” with dotted lines onto your diagrams. Figure 1 depicts an example deployment diagram used to explain the boundaries applicable to testing a relational database.  A privilege boundary separates processes, entities, nodes and other elements that have different trust levels. Wherever aspects of your system cross a privilege boundary, security problems can arise. For example, your system’s ordering module interacts with the payment processing module.  Anybody can place an order, but only manager-level employees can credit a customer’s account when he or she returns a product. At the boundary between the two modules, someone could use functionality within the order module to obtain an illicit credit. 
  2. Understand the threat(s).  To understand the potential threats at an entry point, you must identify any security-critical activities that occur and imagine what an adversary might do to attack or misuse your system. Ask yourself questions such as “How could the adversary use an asset to modify control of the system, retrieve restricted information, manipulate information within the system, cause the system to fail or be unusable, or gain additional rights. In this way, you can determine the chances of the adversary accessing the asset without being audited, skipping any access control checks, or appearing to be another user.  To understand the threat posed by the interface between the order and payment processing modules, you would identify and then work through potential security scenarios. For example, an adversary who makes a purchase using a stolen credit card and then tries to get either a cash refund or a refund to another card when he returns the purchase.
  3. Categorize the threats.  To categorize security threats, consider the STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of Service, and Elevation of privilege) approach. Classifying a threat is the first step toward effective mitigation. For example, if you know that there is a risk that someone could order products from your company but then repudiate receiving the shipment, you should ensure that you accurately identify the purchaser and then log all critical events during the delivery process.
  4. Identify mitigation strategies.  To determine how to mitigate a threat, you can create a diagram called a threat tree. At the root of the tree is the threat itself, and its children (or leaves) are the conditions that must be true for the adversary to realize that threat. Conditions may in turn have subconditions. For example, under the condition that an adversary makes an illicit payment. The fact that the person uses a stolen credit card or a stolen debit/check card is a subcondition. For each of the leaf conditions, you must identify potential mitigation strategies; in this case, to verify the credit card using the XYZ verification package and the debit card with the issuing financial institution itself. Every path through the threat tree that does not end in a mitigation strategy is a system vulnerability.
  5. Test.  Your threat model becomes a plan for penetration testing. Penetration testing investigates threats by directly attacking a system, in an informed or uninformed manner. Informed penetration tests are effectively white-box tests that reflect knowledge of the system’s internal design , whereas uninformed tests are black box in nature. 

 

0 0 Kellep Charles Kellep Charles2012-09-21 12:48:592012-09-21 12:48:59Introduction to Security Threat Modeling

Pages

  • Masonry Blog
  • Sample Page

Categories

  • Child Safety
  • Cloud Security
  • CMMC
  • Compliance
  • Computer Forensics
  • Conference
  • CSI: Cyber Recap
  • Cyber Resilia
  • Cyber Resilience
  • Cyber Resiliency
  • Documentary
  • Education
  • Events
  • Featured
  • Frontpage Article
  • General Security
  • Hack
  • Headline
  • How-to
  • Images
  • Incident Response
  • Infographic
  • International Security
  • Internet Safety
  • Interview
  • IT Certifications
  • Linux
  • Mac OS X
  • Malware
  • Mobile Security
  • News
  • OSINT
  • Podcast
  • Privacy
  • Publications
  • RESILIA
  • Review
  • Security Advisory
  • Security Defitions
  • Security Job
  • Security Magazine
  • Security Practitioners
  • STEM
  • The SecurityOrb Show
  • Top 5
  • Training
  • Uncategorized
  • Video
  • Vulnerability
  • Vulnerability & Threat Report
  • Vulnerability Assessment
  • Web Security
  • Windows Security
  • Wireless Security

Archive

  • May 2026
  • October 2024
  • November 2023
  • September 2023
  • July 2023
  • April 2023
  • September 2022
  • March 2022
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • September 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • August 2019
  • July 2019
  • March 2019
  • February 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • June 2017
  • May 2017
  • March 2017
  • February 2017
  • January 2017
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • March 2009

Interesting links

Here are some interesting links for you! Enjoy your stay :)

Pages

  • Masonry Blog
  • Sample Page

Categories

  • Child Safety
  • Cloud Security
  • CMMC
  • Compliance
  • Computer Forensics
  • Conference
  • CSI: Cyber Recap
  • Cyber Resilia
  • Cyber Resilience
  • Cyber Resiliency
  • Documentary
  • Education
  • Events
  • Featured
  • Frontpage Article
  • General Security
  • Hack
  • Headline
  • How-to
  • Images
  • Incident Response
  • Infographic
  • International Security
  • Internet Safety
  • Interview
  • IT Certifications
  • Linux
  • Mac OS X
  • Malware
  • Mobile Security
  • News
  • OSINT
  • Podcast
  • Privacy
  • Publications
  • RESILIA
  • Review
  • Security Advisory
  • Security Defitions
  • Security Job
  • Security Magazine
  • Security Practitioners
  • STEM
  • The SecurityOrb Show
  • Top 5
  • Training
  • Uncategorized
  • Video
  • Vulnerability
  • Vulnerability & Threat Report
  • Vulnerability Assessment
  • Web Security
  • Windows Security
  • Wireless Security

Archive

  • May 2026
  • October 2024
  • November 2023
  • September 2023
  • July 2023
  • April 2023
  • September 2022
  • March 2022
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • September 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • August 2019
  • July 2019
  • March 2019
  • February 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • June 2017
  • May 2017
  • March 2017
  • February 2017
  • January 2017
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • May 2015
  • April 2015
  • March 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • March 2009
© Copyright - SecurityOrb.com - Enfold Theme by Kriesi
Scroll to top Scroll to top Scroll to top