Board logo

subject: What Is Threat Modeling? [print this page]


Using the principles of security design can result in the development of a sound security design that will mitigate the risk from attacks that have not been developed yet. However, the wise security designer will not rely on good design alone to thwart future attacks. A wise security designer will continually refine these principles by evaluating the threats to the security of the systems she is assigned to protect.

Threat modeling is the act of brainstorming about new threat conditions by using known lists of possible attacks. When you perform threat modeling, you ask the questions: "What type of attacks do I need to defend against?" and "What conditions might lead to a hacker successfully compromising my network?" Just evaluating and protecting against well-known threats assumes that every network is the same and that every attacker -will attempt the same types of access and has the same skill 70-270(http://www.mcse-70-270.com) Threat modeling seeks to use the security administrator's intimate knowledge of specific networks and applications and both logical and chaotic thinking to come up with potential scenarios. What, for example, could a knowledgeable insider who developed your accounting systems do with that knowledge both as an employee and after leaving the company? How about contractors to whom security management is outsourced? What practices need to be implemented to make code more secure? Not just secure from the potential implant of a back door by a malicious programmer but secure from immature coding practices that introduce vulnerabilities an attacker might exploit.

The goal of threat modeling is the same as the goal for using known preventative security disciplines: to reduce overall risk. Microsoft has adopted threat modeling as part of its product development process and has found it extremely useful. Threat modeling done during software design introduces security early in the development process and results in a more robust and secure product. In fact, testers report that 50 percent of the bugs found in code can be found by doing threat modeling simply by looking at the system design and imagining how it could be corrupted. For threat modeling to be an effective security tool 70-270 Exam(http://www.mcse-70-270.com) it must be incorporated early in the network and system design process and in the development of security policies and procedures.

See Also Michael Howard and David LeBlanc's book, Writing Secure Code (Microsoft Press, 2002) certification provider(http://www.buyitexam.com) includes additional information about threat modeling with respect to the development process. Although the book deals with writing secure code, it embodies principles and practices that can easily be applied to designing secure networks.

Using the principles of security design can result in the development of a sound security design that will mitigate the risk from attacks that have not been developed yet. However, the wise .

by: Willsimith




welcome to loan (http://www.yloan.com/) Powered by Discuz! 5.5.0