Building a Comprehensive Threat Model:
Techniques and Best Practices
INTRODUCTION TO THREAT MODELLING
Threat modelling is a way to identify, categorize and analyse threats looking at:
Threat Modeling is a process that helps the architecture team:
INTRODUCTION TO THREAT MODELLING
Benefits include:
THREAT MODELLING PHASE(S)
2. Create an activity matrix (actor-asset-action matrix
THREAT MODELLING PHASE(S)
3. Create Trust Boundaries
4. Plan and implement your mitigation
Understand the terms “Threat” and “Risk” in
a threat modelling context
All risks and threats cannot be eliminated, Mitigation comes in during those scenarios
Mitigate
Few risks and threats have to be accepted at that point of time and later can be checked.
Accept
Threats and risks can be transferred as well
Transfer
Eliminating risk and threat through planning and implementing proper strategies
Eliminate
Overall, there are four main strategies for addressing threats:
The Approach
Identify Security Objectives
Application Overview and walkthrough
Breakdown/Decompose Application
Identify Vulnerabilities
Threat Identification
Selecting Methodology
STRIDE
PASTA
Trike
Continuous Threat
Modeling
Spoofing Tampering
Repudiation Info. Disclosure
Elevation of Privilege
Process for Attack Simulation
& Threat Analysis
Risk Centric
High levels of automation
possible from the defensive
perspective
Spoofing Tampering
Repudiation Info. Disclosure
Elevation of Privilege
ATASM
DREAD
Threat
Surging
Rapid Threat
Modeling
Architecture. Threats.
Attack Sudaces, and
Mitigations
Damage Reproducibility
Exploitability Affected Users
Discoverability
Analysis and feedback of
Threat rnodelling
results
range of processes that use lighter-weight variations
of other methodologies
When to do Threat Modelling
Requirements and Use-Cases
Architecture and Design
Test Plans
Code
Testing and Test Results
Feedback from the Field
Abuse Cases
Security Requirements
Risk Analysis
Risk-based Security Testing
Risk analysis
Penetration Testing
Security Operations
Code Review (Tools)
Defining the Scope
The most critical part of Threat Modelling
Architecture
External Entity
Actor
Data Flow
Data Rest
Boundary
Process
Understand the Attack Surface
The STRIDE per Element Approach to Threat Modeling
Diagram
Identify Threats
Mitigate
Validate
Context
Diagram - Checks
Identify Threats
Threat: Spoofing
Threat | Spoofing |
Property | Authentication |
Definition | Impersonating something or someone else |
Example | Pretending to be any of billg, microsoft.com, or ntdll.dll |
Threat: Tampering
Threat | Tampering |
Property | Integrity |
Definition | Modifying data or code |
Example | Modifying a DLL on disk or DVD, or a packet as it traverses the LAN |
Threat: Repudiation
Threat | Repudiation |
Property | Non-Repudiation |
Definition | Claiming to have not performed�an action |
Example | “I didn’t send that email,” “I didn’t modify that file,” “I certainly didn’t visit that Web site, dear!” |
Threat: Information Disclosure
Threat | Information Disclosure |
Property | Confidentiality |
Definition | Exposing information to someone not authorized to see it |
Example | Allowing someone to read the Windows source code; publishing a list of customers to a Web site |
Threat: Denial of Service
Threat | Denial of Service |
Property | Availability |
Definition | Deny or degrade service to users |
Example | Crashing Windows or a Web site, sending a packet and absorbing seconds of CPU time, or routing packets into a black hole |
Threat: Elevation of Privilege
Threat | Elevation of Privilege (EoP) |
Property | Authorization |
Definition | Gain capabilities without proper authorization |
Example | Allowing a remote Internet user to run commands is the classic example, but going from a “Limited User” to “Admin” is also EoP |
Threats Affecting Each Element Type
Threats Affecting Each Element Type
Threats and Distractions
The Process: Mitigation
Diagram
Identify Threats
Mitigate
Validate
Mitigation Is the Point of Threat Modeling
Mitigate
Standard Mitigations
Spoofing | Authentication | To authenticate principals:
To authenticate code or data:
|
Tampering | Integrity |
|
Repudiation | Non Repudiation |
|
Information Disclosure | Confidentiality |
|
Denial of Service | Availability |
|
Elevation of Privilege | Authorization |
|
The Process: Validation
Diagram
Identify Threats
Mitigate
Validate
Validating Threat Models
Validate Quality of Threats and Mitigations
Fuzzing is a test tactic, not a mitigation
Validate Information Captured
“HTTP.sys will protect us against SQL Injection”
“LPC will protect us from malformed messages”
GenRandom will give us crypto-strong randomness
Effective Threat Modeling Meetings
THANK YOU