Adaptive Threat Modeling

Adaptive Threat Modeling

NDC Conferences via YouTube Direct link

In order to determine risk we need to identify how often

13 of 32

13 of 32

In order to determine risk we need to identify how often

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Adaptive Threat Modeling

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Adaptive Threat Modeling
  2. 2 If there isn't a reason, stop doing it
  3. 3 It's the reason you're doing this!
  4. 4 Security should always come with purpose and intent
  5. 5 How do we understand threats?
  6. 6 Threat modeling is a procedure for optimizing network Security by identifying objectives and vulnerabilities, and then defining countermeasures to prevent, or mitigate the effects of threats to the s…
  7. 7 Drawing, documenting, prioritizing
  8. 8 We're not going to cover methodologies
  9. 9 Focus on reality
  10. 10 Clearly define the capabilities of the threat actor
  11. 11 Understand what the true business impact is
  12. 12 Threat Event Frequency
  13. 13 In order to determine risk we need to identify how often
  14. 14 We can do this with a SIEM
  15. 15 Or via custom tooling
  16. 16 Whatever you do, use the data!
  17. 17 Deliver value, focus, and prioritize
  18. 18 You have realized that things change
  19. 19 Start building threat scenarios automatically
  20. 20 Both predictable and irrational behavior can be modeled
  21. 21 Think about a series of requests as a state transition
  22. 22 You can produce Markov chains from behavioral patterns
  23. 23 Use the request information to produce intended and identifiably malicious transition matrices
  24. 24 You can take this incredibly far
  25. 25 Intent and capability are vital to risk analysis
  26. 26 Using these Markov chains, you can show both
  27. 27 Once you identify this you can build your threat models in near real time
  28. 28 This gives you apply controls to scenarios
  29. 29 Active risk registers tell everyone the story
  30. 30 It allows you to be in constant communication with the business
  31. 31 You can't do it all
  32. 32 Learn to focus on what matters

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.