World Congress 2024 Aug 20, 2024 Session details

Real-world Threat Modeling

Ali Yazdani

Stop treating security as an afterthought. Shift left with the STRIDE framework to catch and eliminate critical vulnerabilities before a single line of code is written.

Pause
Mute Enter Fullscreen
#1 about 2 min

Real-world consequences of missing threat modeling

Real-world examples like a costly Kubernetes API vulnerability demonstrate the need for early security measures.

#2 about 2 min

Expanding the shift left security journey

Transitioning from late-stage testing to secure pipelines shifts security earlier into the design phase.

#3 about 2 min

Defining threat modeling in secure design

Threat modeling provides a structured way to identify and mitigate risks between the design and coding phases.

#4 about 4 min

Core terminologies and relationships in threat modeling

Mapping the cascading relationship between system weaknesses, exploitable vulnerabilities, and attacks clarifies overall risk.

#5 about 2 min

Using the STRIDE threat modeling methodology

The STRIDE framework categorizes threats into spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.

#6 about 2 min

Adopting an iterative threat modeling workflow

Effective threat modeling requires a continuous loop of diagramming data flows, ranking risks, and deploying mitigations.

#7 about 2 min

Mapping STRIDE to data flow diagrams

Applying STRIDE categories directly to system processes, data stores, and external entities exposes critical security boundaries.

#8 about 3 min

Four strategies for addressing identified security threats

Handling discovered vulnerabilities involves choosing whether to mitigate, eliminate, transfer, or formally accept the business risk.

#9 about 3 min

Scoping systems with multi-level data flow diagrams

Deconstructing an application from a high-level overview down to specific components establishes clear trust boundaries.

#10 about 3 min

Implementing threat models with OWASP Threat Dragon

Visualizing diagrams with open-source tools tracks component threats and verifies the presence of appropriate mitigation controls.

#11 about 1 min

Recommended resources for continuous threat modeling education

Studying practical examples and reference implementations helps integrate threat modeling practices into everyday engineering workflows.

Matching moments

3:07 min

Introducing collaborative threat modeling workshops in engineering teams

Bruno Amaro Almeida · World Congress 2022

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · World Congress 2022

2:31 min

Addressing insecure design through early threat modeling

Christian Wenz Christian Wenz · World Congress 2026 Europe

2:35 min

Integrating security across the application development lifecycle

Niels Tanis Niels Tanis · World Congress 2022

3:19 min

Writing secure code and utilizing threat modeling methodologies

Jasmin Azemović Jasmin Azemović · World Congress 2023

3:20 min

Structuring implementation timelines and threat modeling cadence

Nazneen Rupawalla · World Congress 2022

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Stage 7

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

September 24, 2026 · 16:00–18:00

Stage 11

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 6

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen