Free YouTube Transcribe

Video transcript

Developing a 'threat modeling mindset' following four steps of the threat modeling process

Threat Modeling Connect · 9,385 words · 43 min read

Want to search this transcript, jump the video from any line, or download it as TXT, SRT, or VTT?

Open in the transcript tool

Full transcript

Intro

0:00welcome to the threat modeling Workshop

0:02developing a threat modeling mindset by

0:04Robert heret like I said this is

0:06originally designed for our hackathon

0:09participants um but we decided to open

0:11it to all TMC member because it's just

0:13something too give to not to share with

0:15a Brer community so whether or not

0:17you're in the hackathon and we hope we

0:20believe that this you will find this

0:22Workshop really really helpful and this

0:24is a workshop that's been featured in

0:26many many major security conferences um

0:29incl our very own F Monon and it's get

0:32so much great feedback so you're really

0:34in for a treat um now Robert is offering

0:38this to all the TNC members so enjoy I'm

0:41going to introduce Robert herit with our

0:44speaker and Robert over to you all right

0:46yeah thanks and welcome everyone uh

0:48really glad to be here and to uh be able

0:51to present on developing a threat moding

0:54mindset as shoing mentioned this is a u

0:58Workshop that I've done in person at uh

1:01threat modcon uh at least a couple of

1:04them in the last two years as well as

1:06some other places uh this is really u

1:09based on a presentation I put together a

1:13few years ago where I was inspired by uh

1:17this thought of uh security folks have a

1:21certain mindset they can see things a

1:23certain way if they see a door open uh

1:26if they see uh some things that are you

1:29know ports open and so forth uh they

1:32have a particular mindset and I thought

1:34you know threat moding I think uh has a

1:37mindset as well especially as you learn

1:40about it and start to apply uh some of

1:42the process to what you're doing uh then

1:45you develop that mindset and I think

1:47anyone can and so that's really the sort

1:50of the background of uh this uh workshop

1:54and and turning into a workshop uh

1:57Beyond a presentation

Agenda

2:00so uh what are we going to be doing

2:01today we're going to be going through uh

2:03introducing the threat Ming mindset as

2:05well as walking through the threat

2:07moding process uh we do have some

2:10learning and exercises we'll have at

2:12least a couple of breakout uh

2:15opportunities uh breakout groups where

2:17we're going to be meeting uh with a

2:20number of folks who are uh volunteering

2:22their time today to help you out uh and

2:25we're we'll go through some of the

2:26exercises and then we'll come back

2:28together we'll talk about some of the

2:30things that you found and then we'll

2:32continue on uh but at least going to be

2:34doing two of those uh today and then at

2:38the end of course we'll have some

2:39questions and answers uh and and

2:41hopefully uh we could answer all the

2:43questions you have today all right so

2:46who am I um I am a principal application

2:48security architect as well as TR Ming

2:50lead at Aquia uh at least for right now

2:53um until the end of the month I'm

2:55actually looking at some other work here

2:57soon uh but other things I'm doing I'm a

3:00co-host with Chris Romeo of the

3:02application security podcast we're now

3:04over eight years uh going into our ninth

3:07year actually of running the application

3:09security podcast I'm also a co-author of

3:11the threat Ming Manifesto uh threat Ming

3:13capabilities and a co-founder of the

3:15threat Ming connect and as I mentioned

3:17I've had opportunity to present uh this

3:20workshop at a couple of the um hack or

3:23sorry the threat mod cons as well as a

3:26PhD student um focused on Space cyber

3:29security uh the next

3:31Frontier uh previously I uh started and

3:34led the threat Ming program at Bank of

3:36America where uh we were able to put

3:39together uh almost 1500 threat models

3:41over three years working with lots and

3:43lots of teams lots of developers um at

3:45one time we did put some uh training

3:47together for 45,000 developers uh at

3:50Bank of America required uh learning

3:52about threat modeling so it was a really

3:54uh fun time and a lot of what I learned

3:56there and in other places over the years

3:58whove sort of gone into this uh Workshop

4:02how to help uh folks as are beginning in

4:05threat modeling how to learn uh some of

4:08the the basic uh steps and process and

4:11how they can apply it to the work that

4:12they're

4:14doing so again what are we looking to do

4:17develop a threat Ming mindset through

4:19Hands-On learning about uh the threat

4:21Ming process so just to start off with

What is a threat modeling mindset?

4:25what is a threat moding mindset well

4:28first of all I wanted to mentioned to

4:30you that you know threat modeling is

4:32something we're already doing in our

4:33personal lives and first and foremost I

4:36want to mention that a threat model or

4:38threat modeling activity itself is a

4:40thinking activity there are a lot of

4:43great tools that you can use for

4:46analyzing systems uh but a threat model

4:49uh building a threat model is really a

4:51thinking activity and so with that in

4:54mind it again it's something we're

4:56already doing in our personal lives for

4:59example when we lock our doors to our

5:01house or the windows uh we lock the

5:03doors to our car or even when we look

5:06around across the street we're thinking

5:09about what could happen what could go

5:12wrong uh if I look around when I'm

5:15crossing the street what am I looking

5:17for uh you know just in case a car is

5:19coming down the road I need to make sure

5:21I'm safe I need to make sure my own

5:23personal Safety and Security is insured

5:26and so I look around or or maybe there's

5:28um a crosswalk uh light that tells me

5:31it's ready to go or time to go I look

5:33for those kinds of things why because

5:35again I am concerned about Safety and

5:37Security and what do I need to do uh to

5:40handle those

5:41situations and so essentially when we're

5:43thinking ahead and remember I said to

5:45thinking tool it's a thinking activity

5:48we think ahead on what could go wrong we

5:50ask what if questions we weigh risks and

5:53we act accordingly we're doing a kind of

5:56threat

5:57modeling so the first part part of the

6:00mindset is it's strategic versus

6:04reactive uh and sometimes you can also

6:06say proactive and that's ideal but the

6:09the main thing here is strategic we're

6:11thinking ahead uh versus just hoping we

6:14are safe and and just whatever happens

6:16happens uh but instead trying to think

6:18ahead and plan ahead now that personal

6:21what we do in our personal lives that's

6:23intuitive but it's something that we can

6:25also uh push into the work that we're

6:28doing the systems that we're

6:30viewing and with that in mind uh I was

6:33as I mentioned a co-author of the threat

6:35Ming Manifesto and we adopted the four

6:38question framework Adam Shack had

6:40invented these uh questions and we

6:43adopted it into the threat Ming

6:44Manifesto what are we working on what

6:48can go wrong what are we going to do

6:50about it and did we do a good enough job

6:53and you'll see in this Workshop we apply

6:55those questions uh quite often in the

6:58process it's it's really

7:00uh underlying a lot of what we are

7:02doing when we talk about a threat model

7:05typically what we are are saying is that

7:08we think about a threat model that

7:10consists of a system representation that

7:12could be a description it could be a

7:15diagram or or a combination of the two

7:17just something that helps us understand

7:20and answer that first question what are

7:22we working on the next thing is the

7:25identified threats what could go wrong

7:28what could happen

7:30and so those are those threats propose

7:32mitigations so that's really answering

7:34that question what are we going to do

7:36about it and then determining going back

7:40and reviewing is there anything else

7:42that I missed are there any other

7:44mitigations uh that can also lead into

7:47the work that needs to be done and and

7:49the risk that's associated to help us

7:51priorize that work and that back going

7:54back and reviewing answers that question

7:57uh did we do a good enough job and so

7:59the other thing to notice about those

8:01questions it's all about we uh there's a

8:05reason for that it's a team effort and

8:07we heard that from Avi if you attended

8:09the uh session earlier uh it's a team

8:12effort uh when we're looking at building

8:15a threat

8:16model so uh taking those four questions

Overview of the threat modeling process

8:19and and sort of turning them into a a

8:22process similar steps uh those those

8:25four steps this and represents those so

8:28first of all I always say assemble the

8:31team uh and this little diagram that's

8:33the defined part diagram understand your

8:36system that's where we're uh answering

8:38that question about uh what are we

8:40working on identify threats what could

8:42go wrong document so identify and

8:46mitigate that's where what are you going

8:47to do about it and then that final is do

8:49we do a good enough job uh go back and

8:52review and and potentially uh followup

8:56validate so let's talk about assembling

Step 0: Assemble the team

8:58the team ideally you include de software

9:02developers testers Architects project

9:04managers uh many other folks that are

9:07part of your team other stakeholders and

9:10for this Workshop today uh we will

9:12divide as I mentioned this larger group

9:15into breakout groups to represent

9:17different teams as we take a look at and

9:19build a threat

9:23model now getting started very very

9:26simple tools really uh for diag pring

9:29you can use a whiteboard if you have a

9:32team together uh or you could use a

9:34virtual whiteboard I've done that many

9:36times where if we're all remote we can

9:38get on uh a zoom call or something

9:41equivalent and uh and take a look at a

9:44diagram or just ask questions and and

9:46record that information and in terms of

9:48recording it's really important to

9:51document uh what you find what you think

9:53about uh questions that were asked and

9:55answers to those questions and so you

9:57can use of course word or Cel Confluence

10:00J whatever makes sense for your team uh

10:03of course for this uh hackathon you know

10:05we encourage you to to document uh some

10:08of that information in the final threat

10:10model so that uh the judges can be able

10:12to to review uh what you're thinking

10:15what your thought process and so forth

10:19was and as mentioned today for this

10:21Workshop we'll be using a mural page uh

10:24to diagram uh and record threats and

10:26mitigations as far as the diagram part

10:28we're going to look at that

10:29uh we're not actually going to break out

10:31and draw a diagram but we're stly going

10:33to review a diagram

10:36today so just to take a step back let's

10:39talk a little bit about understanding

10:41bugs versus flaws in 2015 the itle

10:45computer Society Center for secure

10:47design uh put out this paper on avoiding

10:51the top 10 software security design

10:54flaws and for me it's just been a a

10:57really good resource to go back too

10:59there are a lot of uh great uh things

11:01listed there about for example uh don't

11:04get authentication and authorization

11:06confused always remember to authorize

11:10after you authenticate don't roll your

11:11own cryptography and so forth but the

11:14main key uh things to take away from the

11:17paper is the difference between a bug

11:20and a flaw a bug and implementation

11:23level software problem we have lots of

11:25tools that can find bugs n plus1 issues

11:28and so on

11:30a flaw on the other hand a design flaw

11:32is a deeper level problem it's the

11:34result of a mistake or oversight at the

11:37design level and much of what we're

11:39doing in threat modeling is we're really

11:41focused on the flaws we're trying to

11:43identify design flaws to improve secure

11:47design we're trying to understand

11:49underneath what were the decisions made

11:52and or going to make if we're building a

11:55threat model for upcoming

11:57work and so looking at the difference

12:00between those two secure security coding

12:03bugs you know coding errors requires

12:05developer understanding the secure

12:06coding um can be automated to find those

12:10and patching is less costly in

12:12production on the other hand security

12:14design flaws represent errors in design

12:18security requirements architecture

12:20typically need contextual knowledge and

12:23very difficult to automate Define these

12:26design flaws and also very cost L to

12:29change in production I've seen that many

12:31times for example if you didn't start

12:34with thinking how you wanted to do

12:36authorization how you wanted to do

12:38access checks it can be very costly to

12:41go back and retrofit so those are things

12:44that we're talking about those design

12:46decisions and related to security

12:49requirements to think about ahead of

12:51time if you can and again what threat

12:53mauling is really great uh to help you

12:55to

12:56do the other thing I'll mention about

12:59any typical threat moding session and it

13:01doesn't have to be so formal um it can

13:04be just simply a few minutes to take a

13:06look at a story and understand what's

13:08going on but these are some typical

13:11things that I I like to see or or think

13:13are are good recommendations first of

13:15all you know domain knowledge and that's

13:17where the team comes into play do they

13:20understand the system do we do we have

13:22that um understanding of what we're

13:24trying to build uh again it's a team

13:26effort also understand your business and

13:29Technical goals you know when you're

13:31thinking about security and design um

13:35we're always in relation to some of the

13:37business and Technical goals as well the

13:39other thing I'll mention is it's focused

13:42um we don't spend hours and days and

13:45days on threat models instead be focused

13:48because it's going to help you um get

13:51some of the main things you're looking

13:52for the other thing is you can also

13:55unfortunately if you spend too much time

13:57you can uh hit one of the is we found in

13:59the or talked about in the threat mly

14:02Manifesto analysis paralysis so be

14:05focused on the work that you're doing

14:07set aside maybe an hour or something

14:09like that to help you the other thing

14:12I'll mention uh be honest leave ego at

14:14the door and no blaming especially when

14:16you're looking at an existing system is

14:19these things can really help because you

14:21might uncover things and didn't realize

14:23assumptions you didn't uh you had before

14:26that now need to be questioned so let's

14:30do the discovery let's understand and uh

14:33it'll really help us in in building a

14:35good threat

14:37model next of course diagramming

Step 1: Be strategic as in 'understanding your system and data flows'

14:40understanding your system and data

14:41flows so in terms of diagramming and

14:45understanding the system as well as data

14:46flows we want to document elements of

14:48the system and properties affected at

14:51minimum document some of the basic

14:53elements of how the system works

14:55security concerns of any properties and

14:58as uh those of you who are going through

15:00the hackathon there's uh a description

15:04of the system take a look at it uh ask

15:07some questions about it understand what

15:09it's saying now there's some things that

15:11may be there they're not there and so

15:13forth but note those as well so that'll

15:16help you to understand that

15:19system in terms of a data flow diagram

15:21you can certainly start with a network

15:23diagram or an architecture diagram um

15:26the value of a data flow diagram and

15:28threat moding is uh one you're trying to

15:32understand uh one of the most important

15:35assets to a system which is typically

15:37the data and how that data um is used in

15:41the system you know accessed and where

15:43is the data stored and who has um access

15:46to that data uh and so on and so with

15:49that in mind typically when you're

15:50drawing a a data flow diagram or any

15:53diagram you're you're trying to

15:55understand some of the basic components

15:58here in terms of the DFD we look at

16:01external entity to start with uh that

16:03represents entities that we just don't

16:06have direct control over so that could

16:08be uh users of our system they're

16:11external to our system but they're

16:13interacting with our system or other

16:15systems maybe other apis that we're

16:17calling um browsers that users are using

16:20to connect to our web application for

16:22example all of those can be represented

16:24as external entities a process on the

16:27other hand uh represented by by that

16:29circle is something that we do have

16:32direct control over maybe it's a

16:33component we wrote maybe it's um a piece

16:37of software that we're configuring but

16:39we again we have some direct control

16:40over and so we want to distinguish that

16:44from the

16:45entities data stores represent data

16:49where is that data uh being stored and

16:52in particular it could be files so

16:54something you may not always see in an

16:56architecture diagram config files log

16:58files files other kinds of files uh

17:00database tables registry cache cookies

17:03anywhere that data may be stored within

17:05the

17:06system data flows help us understand how

17:10data is flowing through the system so

17:13going from perhaps an external entity to

17:16a process or the process in turn storing

17:19it into the data store how is that data

17:23flowing and one thing I'd recommend when

17:25you draw data flows first of all show

17:27the direction but also

17:29label it so that we understand what it's

17:31doing as well as perhaps uh the protocol

17:34use for example is it HTTP https and so

17:38on and that'll help especially as we

17:40start to identify threats what uh are

17:44some of these rather

17:45unencrypted uh what kind of data is

17:47traveling is that sensitive data that

17:49needs to be encrypted and so on and then

17:52finally the the last concept here is

17:55trust boundaries trust boundaries help

17:57us understand and uh where trust may

18:01change as those data flows go through

18:04the system connecting from an entity to

18:07a process or process to a data

18:09store the main thing about a trust

18:11boundary is as it mentions inside you

18:13trust the processes and data stores

18:16outside you don't another thing I like

18:19to think about is that as you cross that

18:21boundary with the data flow is that a

18:24place where you more than likely need to

18:27check trust for example authentication

18:30authorization validation and so that can

18:33also help you where this is an area that

18:35we need uh trust and and recognize that

18:39you know as data flows through we need

18:41to check that for trust uh when that

18:44call comes

18:47through and um you know in terms of the

18:50hackathon you can use the drawing tool

18:51of choice um however we recommend uh

18:55typically for if you're if you're

18:56building a data flow diagram and there

18:57are other things you can do as well

18:58we'll show you that in a moment uh try

19:00to stay with the basic shapes and

19:01meanings for

19:04consistency so again drawing a data flow

19:07diagram ideally The Logical and

19:09component architecture communication

19:12flows and how data is um moved and

19:15stored within the system so here's just

19:18a basic example users and admin those

19:21are your entities external entities

19:24either server or web app uh is your

19:26process and then again data flows

19:29um label them uh just so that we know

19:31what they are what they're doing uh

19:34sometimes you can just use one uh data

19:36flow for example that represents both a

19:37request and response uh that's up to you

19:40how you want to to show that and then of

19:42course uh the trust boundary that helps

19:44us understand that as that data moves to

19:48the the web server the web application

19:50um more than likely there needs to be

19:52some kind of trust check could be

19:54authentication authorization and so on

19:56and that's going to help us as we start

19:58to look at uh the threats a little bit

20:00later using the

20:02diagram here's an example this is the

20:04OAS threat Dragon 2.0 uh where you know

20:07that tool you can draw a data flow

20:09diagram in particular but just shows you

20:11again some of the uh the basic shapes uh

20:15for a data flow diagram representing

20:17processes and data flows data stores uh

20:20and Trust boundaries as

20:23well okay so um this is actually a time

20:26when we normally would uh just draw a

20:28data flow diagram if we were in uh

20:31inperson uh Workshop today uh in the

20:34interest of time we're going to actually

20:35review a data flow diagram uh that it's

20:38represented by um what's what's shown

20:40here but we've got uh some actors

20:43service staff and a user we've got an

20:46authentication provider we have for data

20:49stores logs a database uh processes a

20:52web application web services and so

20:55on so here's a diagram and again we're

20:59going to look at this in more detail as

21:01we break out uh and start to look at

21:03threats uh but again representing a web

21:06application in this case the user who's

21:09an external entity uh using that browser

21:12connecting the web application we see

21:14web services batch processes uh we also

21:17see another type of user a service staff

21:20using a client application connecting to

21:22a database and if you notice over there

21:24on the on the uh right hand side we have

21:27partner organizations authentication

21:29provider we also have third-party data

21:31and service participants so a lot of

21:33different things going on in this this

21:35simple diagram uh representative to help

21:38us understand uh some of the the types

21:41of things that we might see in a typical

21:43web application uh that we're going to

21:45be looking at today for this

Step 2: Be curious / asking questions as in 'identifying threats'

21:49Workshop so let me just check the

21:52uh the chat for a moment see if there

21:55are any questions

21:59okay I don't see any at the moment all

22:01right uh so we've drawn our data flow

22:05diagram we've asked questions about how

22:07the system works we're we're trying to

22:10uh get some answers to those questions

22:12and and that'll help us understand um

22:14the system better now let's start to

22:16identify

22:19threats when we do that um essentially

22:23and going back to our mindset uh the

22:25mindset of a threat minding mindset is

22:27first of all we mentioned strategic

22:29thinking ahead the next part of a threat

22:31Ming mindset is asking questions what if

22:34what could go

22:36wrong uh we like to typically start with

22:38stride uh you don't have to use stride

22:41and in fact I have another slide that

22:43talks about many other methods as well

22:45but stride is a good place I think to

22:47start just to understand some of the

22:49most basic security issues uh that you

22:51might see within uh many software

22:54systems so stride is a nemonic

22:58representing uh spoofing tampering

23:00repudiation information disclosure

23:02denial service and elevation of

23:05privilege if you notice uh to the right

23:08the are of the threat property violated

23:11uh these are some of the most basic

23:12security issues that you see within

23:15systems uh for example we have CIA

23:19confidentiality integrity and

23:21availability uh we also have uh

23:24essentially The Three A's authentication

23:26authorization and sometimes

23:27non-repudiation

23:29is called

23:30auditability but looking at each of

23:32these spoofing pretending to be

23:34something or someone other than yourself

23:36you're looking for um ways to identify

23:39or the lack of identification do I

23:42really know who this person is or this

23:44service that's calling uh my services

23:47have I identified them tampering

23:50modifying something on disk Network

23:52memory or elsewhere what we want there

23:55as I mentioned is data Integrity so

23:57we're looking look for ways that an

24:01attacker might change the data that we

24:04rely on and uh has that been protected

24:08against and so that's the Potential

24:09Threat there

24:11repudiation is really about uh claiming

24:15you didn't do something or not having a

24:18proof of that happening and

24:20non-repudiation is the proof uh so for

24:24example in a system logging or the lack

24:27of logging

24:29could be an example of repudiation and

24:31non-repudiation the logs themselves the

24:34audit Trail uh that's an example of

24:37non-repudiation within a system and so

24:39many times when you look at a system are

24:42we monitoring are we logging and and

24:44have sufficient information to

24:46understand what's happening information

24:48disclosure providing information to

24:50someone not authorized to see it what we

24:53want again is confidentiality and many

24:55times that's where encryption comes into

24:57play no notice it says to someone not

25:00authorized to access it how would they

25:02be able to see it well if it's encrypted

25:05then they might need a key and so those

25:07who have the key provided the key then

25:09they would be able to see that

25:11information um that's a really important

25:13one uh a threat in particular

25:16information disclosure we see that quite

25:18often in data

25:20breaches who has access have we uh

25:24limited access to that data denal

25:27service uh exhausting resources needed

25:30to provide service so you might think of

25:32attacks where an attacker is trying to

25:35call a lot of pages and try to try to

25:38get the system uh to respond to Long

25:41running uh queries and so on but it's

25:44also the lack of availability as it

25:46mentions here related to services that

25:49we depend on for example apis that we

25:52call what happens if they're not

25:54available databases uh down for some

25:57reason and we're not able ble to do our

25:59work and so those are some other

26:01examples of denial of service as you

26:03look at a system and finally the most

26:05severe of all these threats elevation of

26:08privilege relating to allowing someone

26:10to do something they're not authorized

26:12to do and what we want is authorization

26:16or in enforcing some kind of lease

26:19privilege so that uh a system or a

26:23person within a particular role can only

26:25do certain things that they should be

26:27allowed to do and no more a regular user

26:29should not be able to elevate their

26:33privilege which is what the threat is to

26:35act as an administrator for example and

26:38so are there um situations when you're

26:41looking at a a a system and are there

26:44places where we haven't done proper

26:49authorization so applying all of that to

26:52a data flow diagram uh there a couple of

26:55options you can use each part of stride

26:58uh to apply to a specific element or

27:01interactions so for example the web

27:04application are there situations there

27:06for spoofing uh tampering and so on the

27:10other is you can just look at Stride per

27:12interaction uh reason being is that

27:16typically if let's say a file is never

27:19accessed uh only that action of

27:22accessing that file allows a threat

27:25maybe to be realized and so if you just

27:28look at the interactions that can help

27:29you uh to start where stride uh and

27:33apply stride to determine some potential

27:35threats of an act actual uh actor or

27:39attacker being able to get access to log

27:42files databases and so on so couple

27:45different ways to look at it applying

27:47stride to anything you see or just

27:50starting with the interactions and apply

27:52stride

27:53there so some examples spoofing user

27:57could spoofed by an

27:59attacker uh tampering requests from the

28:01user to web app may be

28:04modified repudiation how would we know

28:06actions are performed by the web app

28:08information disclosure setting and

28:10getting credentials could be exposed in

28:12transit um especially if it's if it's uh

28:16not encrypted deny service what happens

28:19if the authentication Service or

28:21provider up there the top right is not

28:24available and elevation of privilege

28:26does audit data have access control for

28:29reading uh so very important as well so

28:32those are again are some examples um as

28:34we get into our exercise we're going to

28:37have an opportunity to look at that data

28:39flow diagram and apply uh or think about

28:42some threats specifically as I mentioned

28:45many many different ways to identify

28:47threats and especially in this hackathon

28:49you don't have to use stride you're not

28:51uh you know you're not locked down to

28:53using stride you can use uh many others

28:56as uh as you uh understand or seems to

29:01apply so lenden for example is privacy

29:04focused it's another pneumonic that

29:06helps you identify privacy related

29:08threats attack trees uh asset or

29:11attacker Centric thinking about how do I

29:13get from where I am as an attacker to my

29:17goal and what are the steps to get there

29:19and and outline that and that can help

29:20you then determine the mitigations at

29:23each point at each node that you may

29:25need to apply uh to prevent the attack

29:28are getting to the goal uh pasta which

29:30is a a risk Centric threat modeling uh

29:34process has a number of steps that you

29:36can take a look at miter attack or

29:39defend uh and there's some others as

29:41well depending on the system uh all of

29:43those are intrusion Centric knowledge

29:45bases they give you uh very specific

29:48examples of how an attacker and for

29:52example with attack may use to get from

29:56uh point a to to final uh goal and

30:00various steps along the way so you can

30:02certainly take a look at that as well uh

30:04card games can help you use case abuse

30:06cases can help you lots of different

30:08ways to identify threats and so and you

30:11know building a threat model or even in

30:13this hackathon you have uh some options

30:17uh to consider and in uh building out

30:19your threat

30:21model okay so using stride to identify

30:25threats here is uh what we call a uh

30:29threat table it helps us to uh do what

30:33we talked about at the very beginning uh

30:35threat model consists of that system

30:38description the identified threats

30:42mitigations and uh what are we going to

30:44do about it as well as um you know

30:48reviewing and followup and so on and

30:50that's what this table is going to help

30:52you do so here in this case we have a

30:55threat partner organization

30:56communication to web services may be

30:58compromised uh logs for a web

31:00application may be tampered with

31:03sometimes it may map directly to stride

31:05or or whatever

31:07uh method you're using to identify

31:09threats it's just optional uh it doesn't

31:12have you don't have to say what it is

31:14maybe you determine a threat uh that

31:16doesn't fit nicely and neatly uh into uh

31:19whatever uh categorization that you're

31:21using and that's okay uh the key is that

31:25the idea behind that is just how did you

31:27arrive at that threat where did that

31:28come from it's just to help us uh to uh

31:31in your thinking of looking for those

31:34threats all

31:36right uh some other things I'll mention

31:40when you're identifying threats and

31:41asking questions is who's interested in

31:44the apps Andor data those threat agents

31:48uh what are their goals so what assets

31:50are do you think they're looking for uh

31:53what are the attack methods how what do

31:55you think uh are some ways that they

31:58might try to attack the system are there

32:00any attack surfaces trust boundaries for

32:02example exposed and are there any input

32:06output data flows missing i' see one

32:08common one is uh file uploads you know I

32:12rely on a file an XML file Json file or

32:15something like that well that's input

32:18you know how is that uh checked how's

32:21that validated and so on so uh those are

32:24important as well as you're as you're

32:26thinking about uh input and then the

32:28data flows also that uh come into your

32:32system all right so we're in our first

32:36exercise and uh this is going to be uh

32:38new for me to to try to do this in uh at

32:41least for in Zoom uh but we're going to

32:44have some breakout groups and um we're

32:46going to spend about 1015 minutes uh and

32:50uh work with each of our volunteers and

32:52then we'll back and view for a few

32:54minutes and then continue on so I'll

32:57turn to with you sh I think you're in uh

32:59in charge of that okay so how was that

33:01for everybody uh were there some

33:03interesting threats that you

33:05noted in looking at this particular

33:08diagram anybody like to share for do a

33:12couple minutes of

33:14that either on chat or in chat or you

33:18can come off mute it's

33:19fine uh yeah uh this is hi this is Ali

33:23uh can I speak yes please okay um

33:26actually uh we had a healthy discussion

33:28in our room so the first is basically

33:30regarding considering the threat the

33:32trust boundaries from the external

33:34browser to the internal um Network I

33:37should say so the user request can be

33:41spoofed um uh and it will compromise the

33:45um I should say the the spoofing of the

33:48stride model and the mitigation could be

33:51the uh multiactor authentication uh as

33:54well the next one could be also be the

33:56inbut validation

33:58for example uh if the sqli is allowed by

34:01our server site so this could lead to

34:05the uh authentication first thing it

34:08could be elevation of privileges as well

34:10uh this is the next point from the

34:13services staff if they are related to

34:15our internal uh employees and they're

34:20directly accessing the client

34:21application The Insider threat could be

34:24um a threat uh the uh uh the the

34:27mitigation for this one can be the

34:30multifactor authentication and the need

34:32to know basis and the relevant category

34:36for those application could be elevation

34:38of privileges this is the first thing

34:40and the authorization if access review

34:42were not done comprehensively and next

34:44one is from from the web application

34:46sorry interrupt me if I am speaking too

34:49much no that's okay uh and and

34:51appreciate it actually you're jumping

34:52ahead a little bit to the next part

34:54we're going to be looking at mitigations

34:55here in a moment but excellent threats

34:58and uh yeah we're going to be joining

34:59back in our our breakout groups to take

35:01a look at some mitigations of the

35:02threats we identified uh but appreciate

35:05some of the ones that you uh you

35:06identified there and shared with us uh

35:08thank you anybody else another threat

35:11that we haven't already talked about

35:12that just jumped out for your

35:15team so Robert one of my group which I

35:18was facilitating uh they also mentioned

35:21about the third party um you know supply

35:24chain risk they did call out that even

35:28though there's a t boundary um we we

35:31need to be specific we need to note it

35:34down yes great great call out all right

35:38fantastic one of my team member talk

35:41about the partner organization they are

35:43using FTP and they can AR they can

35:46modify the data uh in the database

35:49directly because there's no

35:50authentication right right yeah and and

35:55go ahead sorry so there was one more

35:57like three there's a lack of the trust

35:58boundary in the logs right so anybody

36:01can who is having an access to the web

36:03application they can access the logs

36:06directly they might be able to yeah it's

36:09not clear but yeah this a good that's a

36:12good point can anybody access it doesn't

36:15really specify it doesn't really let you

36:17know how that happens and those are

36:19things that uh and great point you may

36:22need to go back and ask questions again

36:25and you know there's some things that

36:27are missing here there's some things

36:28that you know in terms of

36:30underlying how does this work how does

36:32that work and so forth and and so great

36:35points to continue to ask questions when

36:38you look at a diagram or or you're

36:40thinking about a system or or trying to

36:43understand a system rather ask good

36:45questions like those to to clarify okay

36:48well who has access to those logs and

36:50how do they get access to those logs so

36:52great great uh call outs do we take the

36:55perspective of no assumptions or do we

36:59you know CU I mean obviously there's not

37:02enough data here really to do anything I

37:04mean you can call out everything in the

37:05sun based upon this threat model of

37:07course there's there's very little data

37:10in terms of how the application works

37:12what the exercises are going to be like

37:15uh really and the the purpose is just to

37:17find what just a few that you can you're

37:19not going to find all and and like you

37:20said there's lots here because we just

37:22don't know everything so that's that's

37:24the purpose is just exercising being

37:27able to identify some

37:30threats great all right well thank you

37:33everyone so getting back to the threat

Step 3: Be prepared / focused defense as in 'documenting threats'

37:36muling mindset uh this is a quote from

37:39Adam Shack's book uh threat muling

37:40designing for security threat Ming is a

37:43use of abstractions to Aid in thinking

37:45about

37:46risks threat modeling is the key to a

37:48focused defense without threat models

37:50you can never stop playing whack-a-mole

37:53and so key there is threat muling is

37:56focused defense and so another part of

37:58the threat modeling mindset is to be

38:01prepared that focused defense and so

38:03that's where we're getting into

38:05mitigations or that third question what

38:07are you going to do about

38:10it always recommend you document what

38:12you

38:13find these are some uh typical examples

38:17very common examples to address issues

38:20with stride so you know you want

38:23identity Assurance authentication uh

38:25this was already mentioned as potential

38:27mitigations two-factor multiactor

38:29authentication for example for spoofing

38:32uh if you look at availability Den all

38:34Service uh issues there you want rate

38:37limiting or throttling you want

38:38real-time monitoring uh things like that

38:41lease privilege you want uh system that

38:44has an Central authorization engine

38:46that's always ideal authorization

38:49controls uh system limits and system

38:52uses roles accounts permissions and so

38:55forth to help manage access lots of

38:58different good Solutions there and so

39:00again just some example controls that

39:02are pretty typical if you're thinking

39:04about stride uh but the key is

39:07understand the threat and what are some

39:09ways to get to what we need we need

39:12confidentiality we need availability we

39:15need data Integrity how do you ensure

39:18that so that's the key thing about what

39:20are we going to do about it now there

39:23are some mitigation options for example

39:26you can leave as is you determine

39:28there's a threat but there's no good way

39:31to fix it perhaps and or maybe uh the

39:35threat is we just note it but it um it's

39:39it's the possibility of it is extremely

39:42low and so you just simply leave the

39:44system as it is uh if you find a

39:47particular uh part of the system that is

39:50prone to threats and you you haven't got

39:52a good countermeasure in place yet you

39:54can just simply remove that feature from

39:56the product until you fix it or remedy

40:00it with a technology countermeasure you

40:02know set up a story around it and add

40:05that better mitigation or countermeasure

40:08in place uh the other one is warn user I

40:11see that quite often for example if I go

40:13to a coffee shop and it says free Wi-Fi

40:17anybody can connect and but the warning

40:20is uh realize it's completely open

40:23anybody is connecting anybody can see

40:26potentially your traff traffic if

40:27certainly if you're not using https or

40:30other means to uh encrypt your own uh

40:32traffic and so warn user that's another

40:36one uh that you can do as well with the

40:37mitigation option um we I like to

40:40recommend that you make the mitigations

40:42and counter measures part of your

40:43security acceptance criteria that helps

40:46you understand uh what's a threat did I

40:49have a way do I have a good way of

40:51countering

40:52that now some other things about uh that

40:56continues on with uh thinking about what

40:59we going to do about it is determining

41:01risk uh what's a risk associated with

41:04the vulnerability and the threat

41:05identified if we don't fix it what is

41:08the risk of this happening now uh we're

41:11not going to go into all the details

41:13about risk but it's Essence typically

41:17risk is uh what we consider as two

41:20factors ease of

41:22exploitation and the business impact if

41:24that risk or that threat was realized uh

41:27in terms of risk management you know

41:29certainly as I mentioned there's some

41:30others you can do for example Fair uh

41:33which is um a particular

41:35analysis uh tool that you can use or

41:38just at as very simplest risk rating

41:40high medium low based on ease of

41:44exploitation if it's if it's easy to

41:47exploit that's high the business impact

41:50if it's a Major Impact to our system

41:52that's also High and the combination of

41:54those two maybe the risk rating is high

41:57or or critical and so uh you can put

42:00those two together and try to figure out

42:02you know what your risk rating is some

42:03of that of course is sub subjective but

42:06it's it's a way of trying to help you

42:08determine um what are my priorities once

42:11I determine certain things are critical

42:13I probably need to fix those first um

42:16maybe uh uh Beyond some of the others

42:18that I need to fix as well

42:20later and so mapping that out uh here

42:24going back to our threat table we had

42:27some threats we identified now we also

42:29have some mitigations so Implement

42:32encryption and we consider that uh

42:35communication certainly from the outside

42:37as being a high risk uh the apply access

42:42control on logs for the uh threat around

42:45logs uh we consider that to be medium

42:48and uh risk in that case and then also

42:51action items and questions so should we

42:54limit to TLS

42:551.3 uh review the best validation of

42:58messages review access control options

43:01and so on and so those are some things

43:03to to consider when you're you're doing

43:06uh or putting together rather some

43:07action items to follow up on those

43:09mitigations that you

43:11identified at a minimum uh what I like

43:14to recommend is that uh the thread

43:17itself document that the stride mapping

43:19if it's relevant it doesn't have you

43:21don't have to but sometimes it helps uh

43:24and it might uncover some other

43:25potential threats as a result

43:27mitigations that you currently are

43:30implementing or maybe none and uh

43:33optionally maybe a risk rating and then

43:36also action items so mitigations that

43:39are to be implemented uh those few items

43:42if you could document that that'll be

43:44really helpful and that'll help you in

43:45terms of follow up with uh Jura tickets

43:48and user stories and other kinds of

43:51things that you may need to do as a

43:53result of threats you've identified that

43:55are not mitigated

43:58currently okay so now we're into our

44:02second breakout session where we're

44:04going to uh follow up with investigating

44:07mitigations for some of the threats we

44:09identified the the first time uh so if

44:12we could uh jump into our next um um

44:15breakout group okay how was that uh

44:20exercise were you able to figure out

44:22some good mitigations for the threats

44:24you had identified the first time

44:27yeah it was nice it was fun good good

44:31any good uh mitigations that you

44:33determined if any any team like to

44:37share maybe I I'll I'll share one of the

44:41uh so we had identified one threat for

44:44the uh web application which is uh which

44:47we considered as the internet facing

44:49application so so there could be a

44:52possibility where there could be a Dos

44:55attack Okay so service yeah yeah to the

44:59end that could be the unavailability of

45:01the service so to mitigate that we we

45:05kind of introduce u a web application

45:09firewall uh in front of the uh internet

45:13facing application along with uh the

45:16load balancer capability as well for

45:18high availability of the application

45:21great Al limitation against Brute Force

45:25attacks

45:28great great anyone else any other

45:32observations or yes please uh Ricardo um

45:36from our group we had identified that

45:39there was a a spoofing threat on the

45:41client

45:42application

45:44um and basically to counter that as a

45:46mitigation

45:48we uh decided to add

45:50the sorry um certificate certificates

45:54certificates and so that we could um you

45:57know kind of uh show that the

46:00application is trusted to uh to a person

46:04who is not being D but yeah great great

46:10fantastic anybody else hey Robert this

46:12is John the team talked about on on the

46:15Dos not just the um the WAP but dos

46:19protection you know appliances but also

46:22putting things behind the CDN so like as

46:24example have like front door there's a

46:27lot of different CDN options out there

46:29and they also mentioned two which I

46:30thought was really interesting was

46:31around autoscaling which is around

46:34resiliency which in some ways does apply

46:36a lot from a security threat perspective

46:39AB ability right so yeah AB that was a

46:42real interesting one I I hope the team

46:44doesn't mind that I brought that up but

46:47nonetheless hopefully that uh that was

46:50something that was really unique I

46:51thought in terms of what you guys

46:52brought up so very cool um within our

46:55team we we talked a little bit about

46:57logs and about potential sensitive data

47:00in the logs and with that we talked

47:02about um you know and this goes back to

47:04what we talked about earlier about

47:06understanding your domain understanding

47:08the

47:09business understanding the technical and

47:12and goals for each of those and we

47:14talked about you know what kind of data

47:16is in the in those logs is there any pii

47:19any Phi so personal information personal

47:23health information uh is if you're in

47:25the finance industry

47:27what about um any financial information

47:30and how you're handling that kind of

47:32data in the database as well and so on

47:34and and so it's also important to

47:37understand again your domain understand

47:39some specific um policies and compliance

47:44can come in here as well with mitigation

47:46and that can can apply to your building

47:49out your threat models and thinking

47:50about uh not this in a vacuum but

47:53instead we're in a business we're in you

47:55know a particular domain and the and the

47:57kinds of things that we need to think

47:59about in terms of secure access and

48:02secure data so all those kinds of things

48:04came up in in our discussion as well and

48:06so uh good call outs on on that

48:09information that you need to be aware of

48:11and and and so

48:14on great all right uh well thanks

48:17everyone for for going through that

48:19exercise uh really appreciate

48:21it so just to sort of uh wrap up here uh

48:26in the last parts so we already talked

48:29about uh you know documenting elements

48:31of the system properties affected the

48:32threat threats mitigations and risks and

48:35action items action items of course

48:37important that not just that we have

48:40gone through the exercise but we do

48:42something about it um we don't just talk

48:44about it but we do something about it

48:46and so that's where in that last part

Step 4: Be active as in 'review & follow-through'

48:48did we do a good enough job you go back

48:51and

48:52review document the findings and

48:54decisions file bugs or new requirements

48:58uh verify that those are fixed

49:01implemented and then about reviewing and

49:03just did we do a good enough job do we

49:06have a a good confidence in the threat

49:08model or is there something else missing

49:10so do we miss anything review again is

49:12there anything new review again now

49:15we've said this before no threat model

49:17is going to be perfect you're not going

49:19to find everything especially as you

49:21start uh one thing you'll find you might

49:24get into that analysis paralysis where

49:26you find find everything and some people

49:29do that like oh everything is bad I

49:30don't know you know try to be a little

49:32bit more specific if you can um and and

49:36be okay with not finding everything

49:39because as you continue to build those

49:41skills that mindset you'll see things a

49:45little differently the next time or you

49:47notice something you didn't before and

49:49that'll help to continue to improve your

49:52threat model as you go

49:54along and so again to to wrap up here

49:57with our table that review followup

49:59address issues in the next Sprint or

50:02evaluate if we'll fix in the next Sprint

50:03or future Sprint and sometimes you may

50:06note it's nothing we can really fix uh

50:08we we talked about in our group the

50:10third party data and supply chain issues

50:13we can certainly do some things on the

50:14company's side but we can't do

50:17everything on in this case it's an

50:20external entity we can't fix everything

50:22that they may be doing so there are

50:24maybe some things that we need to put in

50:25place about questions we ask ask how

50:27does it work here how does how do they

50:29secure this or that and and have a

50:32little bit of understanding but there

50:34are some things we may never be able to

50:36to solve because it's external and

50:39something we depend on so it's good to

50:41be able to identify that as

50:44well so repeat or iterate as needed

50:47consider a baseline threat model for

50:49your project if you've never ever

50:51created a threat model before and then

50:53update in or review your threat model as

50:55you continue to add new or updated

50:57features and I find that second part

50:59goes a lot faster the first time may

51:01take a little bit of time you know a few

51:04sessions just to get a good Baseline

51:06threat model but then after that much

51:09faster you'll find your

51:11stories continue to be updated or added

51:14uh small bits of here's some new threat

51:18we need to think about we hadn't thought

51:19about and address it and that updates

51:21your threat model as well and that can

51:23go a lot faster as you uh gain those

51:26skills continue to build those skills

51:28and so uh again that threat maing

51:32process assembling your team diagramming

51:35understanding your system identify your

51:36threats document your your threats as

51:40well as your mitigations review and

51:43followup and so that last of the threat

51:46Ming mindset is it's active review

51:50follow through uh it's not just an

51:52exercise where we talk about this stuff

51:53and it's all great but do something

51:55review follow through uh and and uh

51:59determine you know where the mitigations

52:01fit and work on those as you can and if

52:03you

52:04can all right so key takeaways pursue a

Key takeaways

52:08threat moding mindset be strategic think

52:12of secure design uh before you start new

52:15features that's

52:16ideal ask what if and what could go

52:20wrong

52:21questions focus on and be prepared where

52:24defenses May Fail

52:27actively review follow through and

52:29repeat as needed so build that in as

52:32well that opportunities to go back and

52:34review your threat model and update your

52:36threat model U as you go along

52:38especially for those new features as you

52:40may add

52:42them uh some resources we mentioned this

52:45before the threat Ming

52:47Manifesto uh the capabilities that

52:49really help uh if you're in your

52:52organization trying to figure out how do

52:54I add threat modeling is there a good um

52:58Playbook about some of the things I

52:59probably should consider uh the

53:01capabilities model is is a great um U

53:05document to help you with that and then

53:08uh some books great books out there and

53:11um uh these are a couple I like to point

53:13to um for Applied threat Ming hacky

53:16kubernetes really good book about uh

53:19detailing for for those authors on how

53:22they were uh protecting their kubernetes

53:25uh instance uh applying uh stride

53:29applying data flow diagrams but also

53:31applying attack trees if you're

53:32interested we didn't talk about that in

53:34detail today uh but they also show how

53:36they use the tack tree so very good

53:38resource and then uh this other uh the

53:41playbook for threat Ming medical devices

53:43another uh interesting applied threat

53:45modeling as well and there's some other

53:47resources and by the way uh the resource

53:49pack I would recommend that you check

53:51out uh there was a link I think that was

53:54shared in the previous session

53:56uh but um uh you should be able to find

53:58that for the hackathon uh the resource

54:00pack as well as participant um list as

54:03well of items uh you can take a look at

54:06uh to learn more uh examples and so on

54:10all right so we're at the basically at

54:12the end um and yes absolutely sh slides

54:15will be shared we are we already have uh

54:18there's a pdf version of this already

54:21been shared uh so that should go out I

54:23think to to participants

54:26any

54:27questions got a couple minutes

54:33left um just one um I noticed during the

54:37exercises uh it was probably maybe an

54:39extract on on on thread dragon and then

54:43we also had the table that we were

54:45populating on the side uh was just uh

54:48something is it just good uh Cadence to

54:51let's say I'm using a thread Dragon

54:54normally you would put your notes in

54:55there is it also like good um sort of

54:59like Cadence to then do the extraction

55:01and have like a SE separate template

55:03like the one that we were using just to

55:05report

55:07differently uh and provide in terms of

55:10information and everyone to be able to

55:12read through that in terms of best

55:14practice uh really is itth do I need to

55:17capture everything on the dragon or

55:20dragon and then have an extract of the

55:23same data on an Excel sheet that I could

55:26probably

55:27circulate yeah great question um what

55:31and I'll probably defer to uh shoing as

55:34well but in general good idea uh there

55:38are tools that can help you uh capture

55:40that information the threats and so on

55:42uh for the hackathon we're asking that

55:44teams not use tools like that in

55:47particular drawing tools and uh

55:50recording of some sort uh document of

55:52some sort uh but but not uh using those

55:56tools but shining do you want to give

55:58some more um comment on that yeah so we

56:02will defer those questions to the prom

56:04questions channels for the chief judge

56:07Sten resp yeah okay appreciate it thank

56:11you uh but in general it is you know

56:14whatever tool works for you to record to

56:16to keep track if you're you're working

56:18on a threat model with your team um is a

56:21good idea but in in this case yeah

56:23absolutely check with the hackathon uh

56:25rules uh specifically for resources to

56:28use okay cool thanks

56:34welcome awesome let's give Robert her

56:38another virtual big round of applause

56:40for such an amazing amazing Workshop

56:43thank you Robert thank

56:46you all of us all right thank you

56:49everyone for joining us for this

56:51Workshop we will email you the slides

56:54and the recording um for this events you

56:56know whether or not you're the hackathon

56:58participant but you will get that by an

56:59email later today but those hackathon

57:01participant head back to the hackathon

57:03slack and there all the resources will

57:05be shared there all right so thank you

57:07everyone for joining have a great rest

57:08of your day thanks all thanks Robert you

57:11thank

57:13you byee

Recently added transcripts

Browse the whole transcript library

This transcript was generated from the captions YouTube publishes for this video. Get the transcript of any YouTube video atfreeyoutubetranscribe.com, free, unlimited, no sign-up.