Overview
Syllabus
Intro
Why Threat Modeling?
Threat Modeling (System/Software Centric)
Attack Modeling (Attack Centric)
What To Consider When Threat Modeling
There are Five Major Threat Modeling Steps
Threat Modeling (with Common Attacks)
Threat Modeling (Attack Tree Example)
Home Alone Attack Tree (Example) - Continued
Simple Threat Model (Trojan Threat Model Example)
STRIDE Threat Categories
Cloud Security Alliance's Top Threats Working Group
Cloud Controls Matrix (CCM) 4.0 CCM
CSA Top Threats Cloud Threat Modeling
Cloud Threat Modeling Cards
TT:DD Case Study Scenario - Dow Jones 2019
Cloud Threat Modeling Asset Provenance & Pedigree
Same Elasticsearch "Product"; Different Vulnerabilities
Threat Modeling Consistency
Naming Threats
How To Apply What We Have Covered
Taught by
RSA Conference