World Congress 2024 • Aug 20, 2024 • Session details

Real-world Threat Modeling

Ali Yazdani

Stop treating security as an afterthought. Shift left with the STRIDE framework to catch and eliminate critical vulnerabilities before a single line of code is written.

Pause
Mute Enter Fullscreen
#1 about 2 min

Real-world consequences of missing threat modeling

Real-world examples like a costly Kubernetes API vulnerability demonstrate the need for early security measures.

#2 about 2 min

Expanding the shift left security journey

Transitioning from late-stage testing to secure pipelines shifts security earlier into the design phase.

#3 about 2 min

Defining threat modeling in secure design

Threat modeling provides a structured way to identify and mitigate risks between the design and coding phases.

#4 about 4 min

Core terminologies and relationships in threat modeling

Mapping the cascading relationship between system weaknesses, exploitable vulnerabilities, and attacks clarifies overall risk.

#5 about 2 min

Using the STRIDE threat modeling methodology

The STRIDE framework categorizes threats into spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.

#6 about 2 min

Adopting an iterative threat modeling workflow

Effective threat modeling requires a continuous loop of diagramming data flows, ranking risks, and deploying mitigations.

#7 about 2 min

Mapping STRIDE to data flow diagrams

Applying STRIDE categories directly to system processes, data stores, and external entities exposes critical security boundaries.

#8 about 3 min

Four strategies for addressing identified security threats

Handling discovered vulnerabilities involves choosing whether to mitigate, eliminate, transfer, or formally accept the business risk.

#9 about 3 min

Scoping systems with multi-level data flow diagrams

Deconstructing an application from a high-level overview down to specific components establishes clear trust boundaries.

#10 about 3 min

Implementing threat models with OWASP Threat Dragon

Visualizing diagrams with open-source tools tracks component threats and verifies the presence of appropriate mitigation controls.

#11 about 1 min

Recommended resources for continuous threat modeling education

Studying practical examples and reference implementations helps integrate threat modeling practices into everyday engineering workflows.

Matching moments

3:07 min

Introducing collaborative threat modeling workshops in engineering teams

Bruno Amaro Almeida · World Congress 2022

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · World Congress 2022

2:31 min

Addressing insecure design through early threat modeling

Christian Wenz Christian Wenz · World Congress 2026 Europe

4:07 min

Implementing a continuous threat modeling pilot program

Farshad Abasi Farshad Abasi · World Congress 2026 North America

2:35 min

Integrating security across the application development lifecycle

Niels Tanis Niels Tanis · World Congress 2022

2:00 min

Evolution of software development and threat modeling methodologies

Farshad Abasi Farshad Abasi · World Congress 2026 North America