World Congress 2024 Aug 20, 2024 Session details

Real-world Threat Modeling

Ali Yazdani

Stop treating security as an afterthought. Shift left with the STRIDE framework to catch and eliminate critical vulnerabilities before a single line of code is written.

Pause
Mute Enter Fullscreen
#1 about 2 min

Real-world consequences of missing threat modeling

Real-world examples like a costly Kubernetes API vulnerability demonstrate the need for early security measures.

#2 about 2 min

Expanding the shift left security journey

Transitioning from late-stage testing to secure pipelines shifts security earlier into the design phase.

#3 about 2 min

Defining threat modeling in secure design

Threat modeling provides a structured way to identify and mitigate risks between the design and coding phases.

#4 about 4 min

Core terminologies and relationships in threat modeling

Mapping the cascading relationship between system weaknesses, exploitable vulnerabilities, and attacks clarifies overall risk.

#5 about 2 min

Using the STRIDE threat modeling methodology

The STRIDE framework categorizes threats into spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.

#6 about 2 min

Adopting an iterative threat modeling workflow

Effective threat modeling requires a continuous loop of diagramming data flows, ranking risks, and deploying mitigations.

#7 about 2 min

Mapping STRIDE to data flow diagrams

Applying STRIDE categories directly to system processes, data stores, and external entities exposes critical security boundaries.

#8 about 3 min

Four strategies for addressing identified security threats

Handling discovered vulnerabilities involves choosing whether to mitigate, eliminate, transfer, or formally accept the business risk.

#9 about 3 min

Scoping systems with multi-level data flow diagrams

Deconstructing an application from a high-level overview down to specific components establishes clear trust boundaries.

#10 about 3 min

Implementing threat models with OWASP Threat Dragon

Visualizing diagrams with open-source tools tracks component threats and verifies the presence of appropriate mitigation controls.

#11 about 1 min

Recommended resources for continuous threat modeling education

Studying practical examples and reference implementations helps integrate threat modeling practices into everyday engineering workflows.

Matching moments

3:07 min

Introducing collaborative threat modeling workshops in engineering teams

Bruno Amaro Almeida · WWC 2022

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · WWC 2022

2:31 min

Addressing insecure design through early threat modeling

Christian Wenz Christian Wenz · WWC Europe 2026

2:35 min

Integrating security across the application development lifecycle

Niels Tanis Niels Tanis · WWC 2022

3:19 min

Writing secure code and utilizing threat modeling methodologies

Jasmin Azemović Jasmin Azemović · WWC 2023

3:20 min

Structuring implementation timelines and threat modeling cadence

Nazneen Rupawalla · WWC 2022

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier