Full transcript
Intro
0:00welcome to the threat modeling Workshop
0:02developing a threat modeling mindset by
0:04Robert heret like I said this is
0:06originally designed for our hackathon
0:09participants um but we decided to open
0:11it to all TMC member because it's just
0:13something too give to not to share with
0:15a Brer community so whether or not
0:17you're in the hackathon and we hope we
0:20believe that this you will find this
0:22Workshop really really helpful and this
0:24is a workshop that's been featured in
0:26many many major security conferences um
0:29incl our very own F Monon and it's get
0:32so much great feedback so you're really
0:34in for a treat um now Robert is offering
0:38this to all the TNC members so enjoy I'm
0:41going to introduce Robert herit with our
0:44speaker and Robert over to you all right
0:46yeah thanks and welcome everyone uh
0:48really glad to be here and to uh be able
0:51to present on developing a threat moding
0:54mindset as shoing mentioned this is a u
0:58Workshop that I've done in person at uh
1:01threat modcon uh at least a couple of
1:04them in the last two years as well as
1:06some other places uh this is really u
1:09based on a presentation I put together a
1:13few years ago where I was inspired by uh
1:17this thought of uh security folks have a
1:21certain mindset they can see things a
1:23certain way if they see a door open uh
1:26if they see uh some things that are you
1:29know ports open and so forth uh they
1:32have a particular mindset and I thought
1:34you know threat moding I think uh has a
1:37mindset as well especially as you learn
1:40about it and start to apply uh some of
1:42the process to what you're doing uh then
1:45you develop that mindset and I think
1:47anyone can and so that's really the sort
1:50of the background of uh this uh workshop
1:54and and turning into a workshop uh
1:57Beyond a presentation
Agenda
2:00so uh what are we going to be doing
2:01today we're going to be going through uh
2:03introducing the threat Ming mindset as
2:05well as walking through the threat
2:07moding process uh we do have some
2:10learning and exercises we'll have at
2:12least a couple of breakout uh
2:15opportunities uh breakout groups where
2:17we're going to be meeting uh with a
2:20number of folks who are uh volunteering
2:22their time today to help you out uh and
2:25we're we'll go through some of the
2:26exercises and then we'll come back
2:28together we'll talk about some of the
2:30things that you found and then we'll
2:32continue on uh but at least going to be
2:34doing two of those uh today and then at
2:38the end of course we'll have some
2:39questions and answers uh and and
2:41hopefully uh we could answer all the
2:43questions you have today all right so
2:46who am I um I am a principal application
2:48security architect as well as TR Ming
2:50lead at Aquia uh at least for right now
2:53um until the end of the month I'm
2:55actually looking at some other work here
2:57soon uh but other things I'm doing I'm a
3:00co-host with Chris Romeo of the
3:02application security podcast we're now
3:04over eight years uh going into our ninth
3:07year actually of running the application
3:09security podcast I'm also a co-author of
3:11the threat Ming Manifesto uh threat Ming
3:13capabilities and a co-founder of the
3:15threat Ming connect and as I mentioned
3:17I've had opportunity to present uh this
3:20workshop at a couple of the um hack or
3:23sorry the threat mod cons as well as a
3:26PhD student um focused on Space cyber
3:29security uh the next
3:31Frontier uh previously I uh started and
3:34led the threat Ming program at Bank of
3:36America where uh we were able to put
3:39together uh almost 1500 threat models
3:41over three years working with lots and
3:43lots of teams lots of developers um at
3:45one time we did put some uh training
3:47together for 45,000 developers uh at
3:50Bank of America required uh learning
3:52about threat modeling so it was a really
3:54uh fun time and a lot of what I learned
3:56there and in other places over the years
3:58whove sort of gone into this uh Workshop
4:02how to help uh folks as are beginning in
4:05threat modeling how to learn uh some of
4:08the the basic uh steps and process and
4:11how they can apply it to the work that
4:12they're
4:14doing so again what are we looking to do
4:17develop a threat Ming mindset through
4:19Hands-On learning about uh the threat
4:21Ming process so just to start off with
What is a threat modeling mindset?
4:25what is a threat moding mindset well
4:28first of all I wanted to mentioned to
4:30you that you know threat modeling is
4:32something we're already doing in our
4:33personal lives and first and foremost I
4:36want to mention that a threat model or
4:38threat modeling activity itself is a
4:40thinking activity there are a lot of
4:43great tools that you can use for
4:46analyzing systems uh but a threat model
4:49uh building a threat model is really a
4:51thinking activity and so with that in
4:54mind it again it's something we're
4:56already doing in our personal lives for
4:59example when we lock our doors to our
5:01house or the windows uh we lock the
5:03doors to our car or even when we look
5:06around across the street we're thinking
5:09about what could happen what could go
5:12wrong uh if I look around when I'm
5:15crossing the street what am I looking
5:17for uh you know just in case a car is
5:19coming down the road I need to make sure
5:21I'm safe I need to make sure my own
5:23personal Safety and Security is insured
5:26and so I look around or or maybe there's
5:28um a crosswalk uh light that tells me
5:31it's ready to go or time to go I look
5:33for those kinds of things why because
5:35again I am concerned about Safety and
5:37Security and what do I need to do uh to
5:40handle those
5:41situations and so essentially when we're
5:43thinking ahead and remember I said to
5:45thinking tool it's a thinking activity
5:48we think ahead on what could go wrong we
5:50ask what if questions we weigh risks and
5:53we act accordingly we're doing a kind of
5:56threat
5:57modeling so the first part part of the
6:00mindset is it's strategic versus
6:04reactive uh and sometimes you can also
6:06say proactive and that's ideal but the
6:09the main thing here is strategic we're
6:11thinking ahead uh versus just hoping we
6:14are safe and and just whatever happens
6:16happens uh but instead trying to think
6:18ahead and plan ahead now that personal
6:21what we do in our personal lives that's
6:23intuitive but it's something that we can
6:25also uh push into the work that we're
6:28doing the systems that we're
6:30viewing and with that in mind uh I was
6:33as I mentioned a co-author of the threat
6:35Ming Manifesto and we adopted the four
6:38question framework Adam Shack had
6:40invented these uh questions and we
6:43adopted it into the threat Ming
6:44Manifesto what are we working on what
6:48can go wrong what are we going to do
6:50about it and did we do a good enough job
6:53and you'll see in this Workshop we apply
6:55those questions uh quite often in the
6:58process it's it's really
7:00uh underlying a lot of what we are
7:02doing when we talk about a threat model
7:05typically what we are are saying is that
7:08we think about a threat model that
7:10consists of a system representation that
7:12could be a description it could be a
7:15diagram or or a combination of the two
7:17just something that helps us understand
7:20and answer that first question what are
7:22we working on the next thing is the
7:25identified threats what could go wrong
7:28what could happen
7:30and so those are those threats propose
7:32mitigations so that's really answering
7:34that question what are we going to do
7:36about it and then determining going back
7:40and reviewing is there anything else
7:42that I missed are there any other
7:44mitigations uh that can also lead into
7:47the work that needs to be done and and
7:49the risk that's associated to help us
7:51priorize that work and that back going
7:54back and reviewing answers that question
7:57uh did we do a good enough job and so
7:59the other thing to notice about those
8:01questions it's all about we uh there's a
8:05reason for that it's a team effort and
8:07we heard that from Avi if you attended
8:09the uh session earlier uh it's a team
8:12effort uh when we're looking at building
8:15a threat
8:16model so uh taking those four questions
Overview of the threat modeling process
8:19and and sort of turning them into a a
8:22process similar steps uh those those
8:25four steps this and represents those so
8:28first of all I always say assemble the
8:31team uh and this little diagram that's
8:33the defined part diagram understand your
8:36system that's where we're uh answering
8:38that question about uh what are we
8:40working on identify threats what could
8:42go wrong document so identify and
8:46mitigate that's where what are you going
8:47to do about it and then that final is do
8:49we do a good enough job uh go back and
8:52review and and potentially uh followup
8:56validate so let's talk about assembling
Step 0: Assemble the team
8:58the team ideally you include de software
9:02developers testers Architects project
9:04managers uh many other folks that are
9:07part of your team other stakeholders and
9:10for this Workshop today uh we will
9:12divide as I mentioned this larger group
9:15into breakout groups to represent
9:17different teams as we take a look at and
9:19build a threat
9:23model now getting started very very
9:26simple tools really uh for diag pring
9:29you can use a whiteboard if you have a
9:32team together uh or you could use a
9:34virtual whiteboard I've done that many
9:36times where if we're all remote we can
9:38get on uh a zoom call or something
9:41equivalent and uh and take a look at a
9:44diagram or just ask questions and and
9:46record that information and in terms of
9:48recording it's really important to
9:51document uh what you find what you think
9:53about uh questions that were asked and
9:55answers to those questions and so you
9:57can use of course word or Cel Confluence
10:00J whatever makes sense for your team uh
10:03of course for this uh hackathon you know
10:05we encourage you to to document uh some
10:08of that information in the final threat
10:10model so that uh the judges can be able
10:12to to review uh what you're thinking
10:15what your thought process and so forth
10:19was and as mentioned today for this
10:21Workshop we'll be using a mural page uh
10:24to diagram uh and record threats and
10:26mitigations as far as the diagram part
10:28we're going to look at that
10:29uh we're not actually going to break out
10:31and draw a diagram but we're stly going
10:33to review a diagram
10:36today so just to take a step back let's
10:39talk a little bit about understanding
10:41bugs versus flaws in 2015 the itle
10:45computer Society Center for secure
10:47design uh put out this paper on avoiding
10:51the top 10 software security design
10:54flaws and for me it's just been a a
10:57really good resource to go back too
10:59there are a lot of uh great uh things
11:01listed there about for example uh don't
11:04get authentication and authorization
11:06confused always remember to authorize
11:10after you authenticate don't roll your
11:11own cryptography and so forth but the
11:14main key uh things to take away from the
11:17paper is the difference between a bug
11:20and a flaw a bug and implementation
11:23level software problem we have lots of
11:25tools that can find bugs n plus1 issues
11:28and so on
11:30a flaw on the other hand a design flaw
11:32is a deeper level problem it's the
11:34result of a mistake or oversight at the
11:37design level and much of what we're
11:39doing in threat modeling is we're really
11:41focused on the flaws we're trying to
11:43identify design flaws to improve secure
11:47design we're trying to understand
11:49underneath what were the decisions made
11:52and or going to make if we're building a
11:55threat model for upcoming
11:57work and so looking at the difference
12:00between those two secure security coding
12:03bugs you know coding errors requires
12:05developer understanding the secure
12:06coding um can be automated to find those
12:10and patching is less costly in
12:12production on the other hand security
12:14design flaws represent errors in design
12:18security requirements architecture
12:20typically need contextual knowledge and
12:23very difficult to automate Define these
12:26design flaws and also very cost L to
12:29change in production I've seen that many
12:31times for example if you didn't start
12:34with thinking how you wanted to do
12:36authorization how you wanted to do
12:38access checks it can be very costly to
12:41go back and retrofit so those are things
12:44that we're talking about those design
12:46decisions and related to security
12:49requirements to think about ahead of
12:51time if you can and again what threat
12:53mauling is really great uh to help you
12:55to
12:56do the other thing I'll mention about
12:59any typical threat moding session and it
13:01doesn't have to be so formal um it can
13:04be just simply a few minutes to take a
13:06look at a story and understand what's
13:08going on but these are some typical
13:11things that I I like to see or or think
13:13are are good recommendations first of
13:15all you know domain knowledge and that's
13:17where the team comes into play do they
13:20understand the system do we do we have
13:22that um understanding of what we're
13:24trying to build uh again it's a team
13:26effort also understand your business and
13:29Technical goals you know when you're
13:31thinking about security and design um
13:35we're always in relation to some of the
13:37business and Technical goals as well the
13:39other thing I'll mention is it's focused
13:42um we don't spend hours and days and
13:45days on threat models instead be focused
13:48because it's going to help you um get
13:51some of the main things you're looking
13:52for the other thing is you can also
13:55unfortunately if you spend too much time
13:57you can uh hit one of the is we found in
13:59the or talked about in the threat mly
14:02Manifesto analysis paralysis so be
14:05focused on the work that you're doing
14:07set aside maybe an hour or something
14:09like that to help you the other thing
14:12I'll mention uh be honest leave ego at
14:14the door and no blaming especially when
14:16you're looking at an existing system is
14:19these things can really help because you
14:21might uncover things and didn't realize
14:23assumptions you didn't uh you had before
14:26that now need to be questioned so let's
14:30do the discovery let's understand and uh
14:33it'll really help us in in building a
14:35good threat
14:37model next of course diagramming
Step 1: Be strategic as in 'understanding your system and data flows'
14:40understanding your system and data
14:41flows so in terms of diagramming and
14:45understanding the system as well as data
14:46flows we want to document elements of
14:48the system and properties affected at
14:51minimum document some of the basic
14:53elements of how the system works
14:55security concerns of any properties and
14:58as uh those of you who are going through
15:00the hackathon there's uh a description
15:04of the system take a look at it uh ask
15:07some questions about it understand what
15:09it's saying now there's some things that
15:11may be there they're not there and so
15:13forth but note those as well so that'll
15:16help you to understand that
15:19system in terms of a data flow diagram
15:21you can certainly start with a network
15:23diagram or an architecture diagram um
15:26the value of a data flow diagram and
15:28threat moding is uh one you're trying to
15:32understand uh one of the most important
15:35assets to a system which is typically
15:37the data and how that data um is used in
15:41the system you know accessed and where
15:43is the data stored and who has um access
15:46to that data uh and so on and so with
15:49that in mind typically when you're
15:50drawing a a data flow diagram or any
15:53diagram you're you're trying to
15:55understand some of the basic components
15:58here in terms of the DFD we look at
16:01external entity to start with uh that
16:03represents entities that we just don't
16:06have direct control over so that could
16:08be uh users of our system they're
16:11external to our system but they're
16:13interacting with our system or other
16:15systems maybe other apis that we're
16:17calling um browsers that users are using
16:20to connect to our web application for
16:22example all of those can be represented
16:24as external entities a process on the
16:27other hand uh represented by by that
16:29circle is something that we do have
16:32direct control over maybe it's a
16:33component we wrote maybe it's um a piece
16:37of software that we're configuring but
16:39we again we have some direct control
16:40over and so we want to distinguish that
16:44from the
16:45entities data stores represent data
16:49where is that data uh being stored and
16:52in particular it could be files so
16:54something you may not always see in an
16:56architecture diagram config files log
16:58files files other kinds of files uh
17:00database tables registry cache cookies
17:03anywhere that data may be stored within
17:05the
17:06system data flows help us understand how
17:10data is flowing through the system so
17:13going from perhaps an external entity to
17:16a process or the process in turn storing
17:19it into the data store how is that data
17:23flowing and one thing I'd recommend when
17:25you draw data flows first of all show
17:27the direction but also
17:29label it so that we understand what it's
17:31doing as well as perhaps uh the protocol
17:34use for example is it HTTP https and so
17:38on and that'll help especially as we
17:40start to identify threats what uh are
17:44some of these rather
17:45unencrypted uh what kind of data is
17:47traveling is that sensitive data that
17:49needs to be encrypted and so on and then
17:52finally the the last concept here is
17:55trust boundaries trust boundaries help
17:57us understand and uh where trust may
18:01change as those data flows go through
18:04the system connecting from an entity to
18:07a process or process to a data
18:09store the main thing about a trust
18:11boundary is as it mentions inside you
18:13trust the processes and data stores
18:16outside you don't another thing I like
18:19to think about is that as you cross that
18:21boundary with the data flow is that a
18:24place where you more than likely need to
18:27check trust for example authentication
18:30authorization validation and so that can
18:33also help you where this is an area that
18:35we need uh trust and and recognize that
18:39you know as data flows through we need
18:41to check that for trust uh when that
18:44call comes
18:47through and um you know in terms of the
18:50hackathon you can use the drawing tool
18:51of choice um however we recommend uh
18:55typically for if you're if you're
18:56building a data flow diagram and there
18:57are other things you can do as well
18:58we'll show you that in a moment uh try
19:00to stay with the basic shapes and
19:01meanings for
19:04consistency so again drawing a data flow
19:07diagram ideally The Logical and
19:09component architecture communication
19:12flows and how data is um moved and
19:15stored within the system so here's just
19:18a basic example users and admin those
19:21are your entities external entities
19:24either server or web app uh is your
19:26process and then again data flows
19:29um label them uh just so that we know
19:31what they are what they're doing uh
19:34sometimes you can just use one uh data
19:36flow for example that represents both a
19:37request and response uh that's up to you
19:40how you want to to show that and then of
19:42course uh the trust boundary that helps
19:44us understand that as that data moves to
19:48the the web server the web application
19:50um more than likely there needs to be
19:52some kind of trust check could be
19:54authentication authorization and so on
19:56and that's going to help us as we start
19:58to look at uh the threats a little bit
20:00later using the
20:02diagram here's an example this is the
20:04OAS threat Dragon 2.0 uh where you know
20:07that tool you can draw a data flow
20:09diagram in particular but just shows you
20:11again some of the uh the basic shapes uh
20:15for a data flow diagram representing
20:17processes and data flows data stores uh
20:20and Trust boundaries as
20:23well okay so um this is actually a time
20:26when we normally would uh just draw a
20:28data flow diagram if we were in uh
20:31inperson uh Workshop today uh in the
20:34interest of time we're going to actually
20:35review a data flow diagram uh that it's
20:38represented by um what's what's shown
20:40here but we've got uh some actors
20:43service staff and a user we've got an
20:46authentication provider we have for data
20:49stores logs a database uh processes a
20:52web application web services and so
20:55on so here's a diagram and again we're
20:59going to look at this in more detail as
21:01we break out uh and start to look at
21:03threats uh but again representing a web
21:06application in this case the user who's
21:09an external entity uh using that browser
21:12connecting the web application we see
21:14web services batch processes uh we also
21:17see another type of user a service staff
21:20using a client application connecting to
21:22a database and if you notice over there
21:24on the on the uh right hand side we have
21:27partner organizations authentication
21:29provider we also have third-party data
21:31and service participants so a lot of
21:33different things going on in this this
21:35simple diagram uh representative to help
21:38us understand uh some of the the types
21:41of things that we might see in a typical
21:43web application uh that we're going to
21:45be looking at today for this
Step 2: Be curious / asking questions as in 'identifying threats'
21:49Workshop so let me just check the
21:52uh the chat for a moment see if there
21:55are any questions
21:59okay I don't see any at the moment all
22:01right uh so we've drawn our data flow
22:05diagram we've asked questions about how
22:07the system works we're we're trying to
22:10uh get some answers to those questions
22:12and and that'll help us understand um
22:14the system better now let's start to
22:16identify
22:19threats when we do that um essentially
22:23and going back to our mindset uh the
22:25mindset of a threat minding mindset is
22:27first of all we mentioned strategic
22:29thinking ahead the next part of a threat
22:31Ming mindset is asking questions what if
22:34what could go
22:36wrong uh we like to typically start with
22:38stride uh you don't have to use stride
22:41and in fact I have another slide that
22:43talks about many other methods as well
22:45but stride is a good place I think to
22:47start just to understand some of the
22:49most basic security issues uh that you
22:51might see within uh many software
22:54systems so stride is a nemonic
22:58representing uh spoofing tampering
23:00repudiation information disclosure
23:02denial service and elevation of
23:05privilege if you notice uh to the right
23:08the are of the threat property violated
23:11uh these are some of the most basic
23:12security issues that you see within
23:15systems uh for example we have CIA
23:19confidentiality integrity and
23:21availability uh we also have uh
23:24essentially The Three A's authentication
23:26authorization and sometimes
23:27non-repudiation
23:29is called
23:30auditability but looking at each of
23:32these spoofing pretending to be
23:34something or someone other than yourself
23:36you're looking for um ways to identify
23:39or the lack of identification do I
23:42really know who this person is or this
23:44service that's calling uh my services
23:47have I identified them tampering
23:50modifying something on disk Network
23:52memory or elsewhere what we want there
23:55as I mentioned is data Integrity so
23:57we're looking look for ways that an
24:01attacker might change the data that we
24:04rely on and uh has that been protected
24:08against and so that's the Potential
24:09Threat there
24:11repudiation is really about uh claiming
24:15you didn't do something or not having a
24:18proof of that happening and
24:20non-repudiation is the proof uh so for
24:24example in a system logging or the lack
24:27of logging
24:29could be an example of repudiation and
24:31non-repudiation the logs themselves the
24:34audit Trail uh that's an example of
24:37non-repudiation within a system and so
24:39many times when you look at a system are
24:42we monitoring are we logging and and
24:44have sufficient information to
24:46understand what's happening information
24:48disclosure providing information to
24:50someone not authorized to see it what we
24:53want again is confidentiality and many
24:55times that's where encryption comes into
24:57play no notice it says to someone not
25:00authorized to access it how would they
25:02be able to see it well if it's encrypted
25:05then they might need a key and so those
25:07who have the key provided the key then
25:09they would be able to see that
25:11information um that's a really important
25:13one uh a threat in particular
25:16information disclosure we see that quite
25:18often in data
25:20breaches who has access have we uh
25:24limited access to that data denal
25:27service uh exhausting resources needed
25:30to provide service so you might think of
25:32attacks where an attacker is trying to
25:35call a lot of pages and try to try to
25:38get the system uh to respond to Long
25:41running uh queries and so on but it's
25:44also the lack of availability as it
25:46mentions here related to services that
25:49we depend on for example apis that we
25:52call what happens if they're not
25:54available databases uh down for some
25:57reason and we're not able ble to do our
25:59work and so those are some other
26:01examples of denial of service as you
26:03look at a system and finally the most
26:05severe of all these threats elevation of
26:08privilege relating to allowing someone
26:10to do something they're not authorized
26:12to do and what we want is authorization
26:16or in enforcing some kind of lease
26:19privilege so that uh a system or a
26:23person within a particular role can only
26:25do certain things that they should be
26:27allowed to do and no more a regular user
26:29should not be able to elevate their
26:33privilege which is what the threat is to
26:35act as an administrator for example and
26:38so are there um situations when you're
26:41looking at a a a system and are there
26:44places where we haven't done proper
26:49authorization so applying all of that to
26:52a data flow diagram uh there a couple of
26:55options you can use each part of stride
26:58uh to apply to a specific element or
27:01interactions so for example the web
27:04application are there situations there
27:06for spoofing uh tampering and so on the
27:10other is you can just look at Stride per
27:12interaction uh reason being is that
27:16typically if let's say a file is never
27:19accessed uh only that action of
27:22accessing that file allows a threat
27:25maybe to be realized and so if you just
27:28look at the interactions that can help
27:29you uh to start where stride uh and
27:33apply stride to determine some potential
27:35threats of an act actual uh actor or
27:39attacker being able to get access to log
27:42files databases and so on so couple
27:45different ways to look at it applying
27:47stride to anything you see or just
27:50starting with the interactions and apply
27:52stride
27:53there so some examples spoofing user
27:57could spoofed by an
27:59attacker uh tampering requests from the
28:01user to web app may be
28:04modified repudiation how would we know
28:06actions are performed by the web app
28:08information disclosure setting and
28:10getting credentials could be exposed in
28:12transit um especially if it's if it's uh
28:16not encrypted deny service what happens
28:19if the authentication Service or
28:21provider up there the top right is not
28:24available and elevation of privilege
28:26does audit data have access control for
28:29reading uh so very important as well so
28:32those are again are some examples um as
28:34we get into our exercise we're going to
28:37have an opportunity to look at that data
28:39flow diagram and apply uh or think about
28:42some threats specifically as I mentioned
28:45many many different ways to identify
28:47threats and especially in this hackathon
28:49you don't have to use stride you're not
28:51uh you know you're not locked down to
28:53using stride you can use uh many others
28:56as uh as you uh understand or seems to
29:01apply so lenden for example is privacy
29:04focused it's another pneumonic that
29:06helps you identify privacy related
29:08threats attack trees uh asset or
29:11attacker Centric thinking about how do I
29:13get from where I am as an attacker to my
29:17goal and what are the steps to get there
29:19and and outline that and that can help
29:20you then determine the mitigations at
29:23each point at each node that you may
29:25need to apply uh to prevent the attack
29:28are getting to the goal uh pasta which
29:30is a a risk Centric threat modeling uh
29:34process has a number of steps that you
29:36can take a look at miter attack or
29:39defend uh and there's some others as
29:41well depending on the system uh all of
29:43those are intrusion Centric knowledge
29:45bases they give you uh very specific
29:48examples of how an attacker and for
29:52example with attack may use to get from
29:56uh point a to to final uh goal and
30:00various steps along the way so you can
30:02certainly take a look at that as well uh
30:04card games can help you use case abuse
30:06cases can help you lots of different
30:08ways to identify threats and so and you
30:11know building a threat model or even in
30:13this hackathon you have uh some options
30:17uh to consider and in uh building out
30:19your threat
30:21model okay so using stride to identify
30:25threats here is uh what we call a uh
30:29threat table it helps us to uh do what
30:33we talked about at the very beginning uh
30:35threat model consists of that system
30:38description the identified threats
30:42mitigations and uh what are we going to
30:44do about it as well as um you know
30:48reviewing and followup and so on and
30:50that's what this table is going to help
30:52you do so here in this case we have a
30:55threat partner organization
30:56communication to web services may be
30:58compromised uh logs for a web
31:00application may be tampered with
31:03sometimes it may map directly to stride
31:05or or whatever
31:07uh method you're using to identify
31:09threats it's just optional uh it doesn't
31:12have you don't have to say what it is
31:14maybe you determine a threat uh that
31:16doesn't fit nicely and neatly uh into uh
31:19whatever uh categorization that you're
31:21using and that's okay uh the key is that
31:25the idea behind that is just how did you
31:27arrive at that threat where did that
31:28come from it's just to help us uh to uh
31:31in your thinking of looking for those
31:34threats all
31:36right uh some other things I'll mention
31:40when you're identifying threats and
31:41asking questions is who's interested in
31:44the apps Andor data those threat agents
31:48uh what are their goals so what assets
31:50are do you think they're looking for uh
31:53what are the attack methods how what do
31:55you think uh are some ways that they
31:58might try to attack the system are there
32:00any attack surfaces trust boundaries for
32:02example exposed and are there any input
32:06output data flows missing i' see one
32:08common one is uh file uploads you know I
32:12rely on a file an XML file Json file or
32:15something like that well that's input
32:18you know how is that uh checked how's
32:21that validated and so on so uh those are
32:24important as well as you're as you're
32:26thinking about uh input and then the
32:28data flows also that uh come into your
32:32system all right so we're in our first
32:36exercise and uh this is going to be uh
32:38new for me to to try to do this in uh at
32:41least for in Zoom uh but we're going to
32:44have some breakout groups and um we're
32:46going to spend about 1015 minutes uh and
32:50uh work with each of our volunteers and
32:52then we'll back and view for a few
32:54minutes and then continue on so I'll
32:57turn to with you sh I think you're in uh
32:59in charge of that okay so how was that
33:01for everybody uh were there some
33:03interesting threats that you
33:05noted in looking at this particular
33:08diagram anybody like to share for do a
33:12couple minutes of
33:14that either on chat or in chat or you
33:18can come off mute it's
33:19fine uh yeah uh this is hi this is Ali
33:23uh can I speak yes please okay um
33:26actually uh we had a healthy discussion
33:28in our room so the first is basically
33:30regarding considering the threat the
33:32trust boundaries from the external
33:34browser to the internal um Network I
33:37should say so the user request can be
33:41spoofed um uh and it will compromise the
33:45um I should say the the spoofing of the
33:48stride model and the mitigation could be
33:51the uh multiactor authentication uh as
33:54well the next one could be also be the
33:56inbut validation
33:58for example uh if the sqli is allowed by
34:01our server site so this could lead to
34:05the uh authentication first thing it
34:08could be elevation of privileges as well
34:10uh this is the next point from the
34:13services staff if they are related to
34:15our internal uh employees and they're
34:20directly accessing the client
34:21application The Insider threat could be
34:24um a threat uh the uh uh the the
34:27mitigation for this one can be the
34:30multifactor authentication and the need
34:32to know basis and the relevant category
34:36for those application could be elevation
34:38of privileges this is the first thing
34:40and the authorization if access review
34:42were not done comprehensively and next
34:44one is from from the web application
34:46sorry interrupt me if I am speaking too
34:49much no that's okay uh and and
34:51appreciate it actually you're jumping
34:52ahead a little bit to the next part
34:54we're going to be looking at mitigations
34:55here in a moment but excellent threats
34:58and uh yeah we're going to be joining
34:59back in our our breakout groups to take
35:01a look at some mitigations of the
35:02threats we identified uh but appreciate
35:05some of the ones that you uh you
35:06identified there and shared with us uh
35:08thank you anybody else another threat
35:11that we haven't already talked about
35:12that just jumped out for your
35:15team so Robert one of my group which I
35:18was facilitating uh they also mentioned
35:21about the third party um you know supply
35:24chain risk they did call out that even
35:28though there's a t boundary um we we
35:31need to be specific we need to note it
35:34down yes great great call out all right
35:38fantastic one of my team member talk
35:41about the partner organization they are
35:43using FTP and they can AR they can
35:46modify the data uh in the database
35:49directly because there's no
35:50authentication right right yeah and and
35:55go ahead sorry so there was one more
35:57like three there's a lack of the trust
35:58boundary in the logs right so anybody
36:01can who is having an access to the web
36:03application they can access the logs
36:06directly they might be able to yeah it's
36:09not clear but yeah this a good that's a
36:12good point can anybody access it doesn't
36:15really specify it doesn't really let you
36:17know how that happens and those are
36:19things that uh and great point you may
36:22need to go back and ask questions again
36:25and you know there's some things that
36:27are missing here there's some things
36:28that you know in terms of
36:30underlying how does this work how does
36:32that work and so forth and and so great
36:35points to continue to ask questions when
36:38you look at a diagram or or you're
36:40thinking about a system or or trying to
36:43understand a system rather ask good
36:45questions like those to to clarify okay
36:48well who has access to those logs and
36:50how do they get access to those logs so
36:52great great uh call outs do we take the
36:55perspective of no assumptions or do we
36:59you know CU I mean obviously there's not
37:02enough data here really to do anything I
37:04mean you can call out everything in the
37:05sun based upon this threat model of
37:07course there's there's very little data
37:10in terms of how the application works
37:12what the exercises are going to be like
37:15uh really and the the purpose is just to
37:17find what just a few that you can you're
37:19not going to find all and and like you
37:20said there's lots here because we just
37:22don't know everything so that's that's
37:24the purpose is just exercising being
37:27able to identify some
37:30threats great all right well thank you
37:33everyone so getting back to the threat
Step 3: Be prepared / focused defense as in 'documenting threats'
37:36muling mindset uh this is a quote from
37:39Adam Shack's book uh threat muling
37:40designing for security threat Ming is a
37:43use of abstractions to Aid in thinking
37:45about
37:46risks threat modeling is the key to a
37:48focused defense without threat models
37:50you can never stop playing whack-a-mole
37:53and so key there is threat muling is
37:56focused defense and so another part of
37:58the threat modeling mindset is to be
38:01prepared that focused defense and so
38:03that's where we're getting into
38:05mitigations or that third question what
38:07are you going to do about
38:10it always recommend you document what
38:12you
38:13find these are some uh typical examples
38:17very common examples to address issues
38:20with stride so you know you want
38:23identity Assurance authentication uh
38:25this was already mentioned as potential
38:27mitigations two-factor multiactor
38:29authentication for example for spoofing
38:32uh if you look at availability Den all
38:34Service uh issues there you want rate
38:37limiting or throttling you want
38:38real-time monitoring uh things like that
38:41lease privilege you want uh system that
38:44has an Central authorization engine
38:46that's always ideal authorization
38:49controls uh system limits and system
38:52uses roles accounts permissions and so
38:55forth to help manage access lots of
38:58different good Solutions there and so
39:00again just some example controls that
39:02are pretty typical if you're thinking
39:04about stride uh but the key is
39:07understand the threat and what are some
39:09ways to get to what we need we need
39:12confidentiality we need availability we
39:15need data Integrity how do you ensure
39:18that so that's the key thing about what
39:20are we going to do about it now there
39:23are some mitigation options for example
39:26you can leave as is you determine
39:28there's a threat but there's no good way
39:31to fix it perhaps and or maybe uh the
39:35threat is we just note it but it um it's
39:39it's the possibility of it is extremely
39:42low and so you just simply leave the
39:44system as it is uh if you find a
39:47particular uh part of the system that is
39:50prone to threats and you you haven't got
39:52a good countermeasure in place yet you
39:54can just simply remove that feature from
39:56the product until you fix it or remedy
40:00it with a technology countermeasure you
40:02know set up a story around it and add
40:05that better mitigation or countermeasure
40:08in place uh the other one is warn user I
40:11see that quite often for example if I go
40:13to a coffee shop and it says free Wi-Fi
40:17anybody can connect and but the warning
40:20is uh realize it's completely open
40:23anybody is connecting anybody can see
40:26potentially your traff traffic if
40:27certainly if you're not using https or
40:30other means to uh encrypt your own uh
40:32traffic and so warn user that's another
40:36one uh that you can do as well with the
40:37mitigation option um we I like to
40:40recommend that you make the mitigations
40:42and counter measures part of your
40:43security acceptance criteria that helps
40:46you understand uh what's a threat did I
40:49have a way do I have a good way of
40:51countering
40:52that now some other things about uh that
40:56continues on with uh thinking about what
40:59we going to do about it is determining
41:01risk uh what's a risk associated with
41:04the vulnerability and the threat
41:05identified if we don't fix it what is
41:08the risk of this happening now uh we're
41:11not going to go into all the details
41:13about risk but it's Essence typically
41:17risk is uh what we consider as two
41:20factors ease of
41:22exploitation and the business impact if
41:24that risk or that threat was realized uh
41:27in terms of risk management you know
41:29certainly as I mentioned there's some
41:30others you can do for example Fair uh
41:33which is um a particular
41:35analysis uh tool that you can use or
41:38just at as very simplest risk rating
41:40high medium low based on ease of
41:44exploitation if it's if it's easy to
41:47exploit that's high the business impact
41:50if it's a Major Impact to our system
41:52that's also High and the combination of
41:54those two maybe the risk rating is high
41:57or or critical and so uh you can put
42:00those two together and try to figure out
42:02you know what your risk rating is some
42:03of that of course is sub subjective but
42:06it's it's a way of trying to help you
42:08determine um what are my priorities once
42:11I determine certain things are critical
42:13I probably need to fix those first um
42:16maybe uh uh Beyond some of the others
42:18that I need to fix as well
42:20later and so mapping that out uh here
42:24going back to our threat table we had
42:27some threats we identified now we also
42:29have some mitigations so Implement
42:32encryption and we consider that uh
42:35communication certainly from the outside
42:37as being a high risk uh the apply access
42:42control on logs for the uh threat around
42:45logs uh we consider that to be medium
42:48and uh risk in that case and then also
42:51action items and questions so should we
42:54limit to TLS
42:551.3 uh review the best validation of
42:58messages review access control options
43:01and so on and so those are some things
43:03to to consider when you're you're doing
43:06uh or putting together rather some
43:07action items to follow up on those
43:09mitigations that you
43:11identified at a minimum uh what I like
43:14to recommend is that uh the thread
43:17itself document that the stride mapping
43:19if it's relevant it doesn't have you
43:21don't have to but sometimes it helps uh
43:24and it might uncover some other
43:25potential threats as a result
43:27mitigations that you currently are
43:30implementing or maybe none and uh
43:33optionally maybe a risk rating and then
43:36also action items so mitigations that
43:39are to be implemented uh those few items
43:42if you could document that that'll be
43:44really helpful and that'll help you in
43:45terms of follow up with uh Jura tickets
43:48and user stories and other kinds of
43:51things that you may need to do as a
43:53result of threats you've identified that
43:55are not mitigated
43:58currently okay so now we're into our
44:02second breakout session where we're
44:04going to uh follow up with investigating
44:07mitigations for some of the threats we
44:09identified the the first time uh so if
44:12we could uh jump into our next um um
44:15breakout group okay how was that uh
44:20exercise were you able to figure out
44:22some good mitigations for the threats
44:24you had identified the first time
44:27yeah it was nice it was fun good good
44:31any good uh mitigations that you
44:33determined if any any team like to
44:37share maybe I I'll I'll share one of the
44:41uh so we had identified one threat for
44:44the uh web application which is uh which
44:47we considered as the internet facing
44:49application so so there could be a
44:52possibility where there could be a Dos
44:55attack Okay so service yeah yeah to the
44:59end that could be the unavailability of
45:01the service so to mitigate that we we
45:05kind of introduce u a web application
45:09firewall uh in front of the uh internet
45:13facing application along with uh the
45:16load balancer capability as well for
45:18high availability of the application
45:21great Al limitation against Brute Force
45:25attacks
45:28great great anyone else any other
45:32observations or yes please uh Ricardo um
45:36from our group we had identified that
45:39there was a a spoofing threat on the
45:41client
45:42application
45:44um and basically to counter that as a
45:46mitigation
45:48we uh decided to add
45:50the sorry um certificate certificates
45:54certificates and so that we could um you
45:57know kind of uh show that the
46:00application is trusted to uh to a person
46:04who is not being D but yeah great great
46:10fantastic anybody else hey Robert this
46:12is John the team talked about on on the
46:15Dos not just the um the WAP but dos
46:19protection you know appliances but also
46:22putting things behind the CDN so like as
46:24example have like front door there's a
46:27lot of different CDN options out there
46:29and they also mentioned two which I
46:30thought was really interesting was
46:31around autoscaling which is around
46:34resiliency which in some ways does apply
46:36a lot from a security threat perspective
46:39AB ability right so yeah AB that was a
46:42real interesting one I I hope the team
46:44doesn't mind that I brought that up but
46:47nonetheless hopefully that uh that was
46:50something that was really unique I
46:51thought in terms of what you guys
46:52brought up so very cool um within our
46:55team we we talked a little bit about
46:57logs and about potential sensitive data
47:00in the logs and with that we talked
47:02about um you know and this goes back to
47:04what we talked about earlier about
47:06understanding your domain understanding
47:08the
47:09business understanding the technical and
47:12and goals for each of those and we
47:14talked about you know what kind of data
47:16is in the in those logs is there any pii
47:19any Phi so personal information personal
47:23health information uh is if you're in
47:25the finance industry
47:27what about um any financial information
47:30and how you're handling that kind of
47:32data in the database as well and so on
47:34and and so it's also important to
47:37understand again your domain understand
47:39some specific um policies and compliance
47:44can come in here as well with mitigation
47:46and that can can apply to your building
47:49out your threat models and thinking
47:50about uh not this in a vacuum but
47:53instead we're in a business we're in you
47:55know a particular domain and the and the
47:57kinds of things that we need to think
47:59about in terms of secure access and
48:02secure data so all those kinds of things
48:04came up in in our discussion as well and
48:06so uh good call outs on on that
48:09information that you need to be aware of
48:11and and and so
48:14on great all right uh well thanks
48:17everyone for for going through that
48:19exercise uh really appreciate
48:21it so just to sort of uh wrap up here uh
48:26in the last parts so we already talked
48:29about uh you know documenting elements
48:31of the system properties affected the
48:32threat threats mitigations and risks and
48:35action items action items of course
48:37important that not just that we have
48:40gone through the exercise but we do
48:42something about it um we don't just talk
48:44about it but we do something about it
48:46and so that's where in that last part
Step 4: Be active as in 'review & follow-through'
48:48did we do a good enough job you go back
48:51and
48:52review document the findings and
48:54decisions file bugs or new requirements
48:58uh verify that those are fixed
49:01implemented and then about reviewing and
49:03just did we do a good enough job do we
49:06have a a good confidence in the threat
49:08model or is there something else missing
49:10so do we miss anything review again is
49:12there anything new review again now
49:15we've said this before no threat model
49:17is going to be perfect you're not going
49:19to find everything especially as you
49:21start uh one thing you'll find you might
49:24get into that analysis paralysis where
49:26you find find everything and some people
49:29do that like oh everything is bad I
49:30don't know you know try to be a little
49:32bit more specific if you can um and and
49:36be okay with not finding everything
49:39because as you continue to build those
49:41skills that mindset you'll see things a
49:45little differently the next time or you
49:47notice something you didn't before and
49:49that'll help to continue to improve your
49:52threat model as you go
49:54along and so again to to wrap up here
49:57with our table that review followup
49:59address issues in the next Sprint or
50:02evaluate if we'll fix in the next Sprint
50:03or future Sprint and sometimes you may
50:06note it's nothing we can really fix uh
50:08we we talked about in our group the
50:10third party data and supply chain issues
50:13we can certainly do some things on the
50:14company's side but we can't do
50:17everything on in this case it's an
50:20external entity we can't fix everything
50:22that they may be doing so there are
50:24maybe some things that we need to put in
50:25place about questions we ask ask how
50:27does it work here how does how do they
50:29secure this or that and and have a
50:32little bit of understanding but there
50:34are some things we may never be able to
50:36to solve because it's external and
50:39something we depend on so it's good to
50:41be able to identify that as
50:44well so repeat or iterate as needed
50:47consider a baseline threat model for
50:49your project if you've never ever
50:51created a threat model before and then
50:53update in or review your threat model as
50:55you continue to add new or updated
50:57features and I find that second part
50:59goes a lot faster the first time may
51:01take a little bit of time you know a few
51:04sessions just to get a good Baseline
51:06threat model but then after that much
51:09faster you'll find your
51:11stories continue to be updated or added
51:14uh small bits of here's some new threat
51:18we need to think about we hadn't thought
51:19about and address it and that updates
51:21your threat model as well and that can
51:23go a lot faster as you uh gain those
51:26skills continue to build those skills
51:28and so uh again that threat maing
51:32process assembling your team diagramming
51:35understanding your system identify your
51:36threats document your your threats as
51:40well as your mitigations review and
51:43followup and so that last of the threat
51:46Ming mindset is it's active review
51:50follow through uh it's not just an
51:52exercise where we talk about this stuff
51:53and it's all great but do something
51:55review follow through uh and and uh
51:59determine you know where the mitigations
52:01fit and work on those as you can and if
52:03you
52:04can all right so key takeaways pursue a
Key takeaways
52:08threat moding mindset be strategic think
52:12of secure design uh before you start new
52:15features that's
52:16ideal ask what if and what could go
52:20wrong
52:21questions focus on and be prepared where
52:24defenses May Fail
52:27actively review follow through and
52:29repeat as needed so build that in as
52:32well that opportunities to go back and
52:34review your threat model and update your
52:36threat model U as you go along
52:38especially for those new features as you
52:40may add
52:42them uh some resources we mentioned this
52:45before the threat Ming
52:47Manifesto uh the capabilities that
52:49really help uh if you're in your
52:52organization trying to figure out how do
52:54I add threat modeling is there a good um
52:58Playbook about some of the things I
52:59probably should consider uh the
53:01capabilities model is is a great um U
53:05document to help you with that and then
53:08uh some books great books out there and
53:11um uh these are a couple I like to point
53:13to um for Applied threat Ming hacky
53:16kubernetes really good book about uh
53:19detailing for for those authors on how
53:22they were uh protecting their kubernetes
53:25uh instance uh applying uh stride
53:29applying data flow diagrams but also
53:31applying attack trees if you're
53:32interested we didn't talk about that in
53:34detail today uh but they also show how
53:36they use the tack tree so very good
53:38resource and then uh this other uh the
53:41playbook for threat Ming medical devices
53:43another uh interesting applied threat
53:45modeling as well and there's some other
53:47resources and by the way uh the resource
53:49pack I would recommend that you check
53:51out uh there was a link I think that was
53:54shared in the previous session
53:56uh but um uh you should be able to find
53:58that for the hackathon uh the resource
54:00pack as well as participant um list as
54:03well of items uh you can take a look at
54:06uh to learn more uh examples and so on
54:10all right so we're at the basically at
54:12the end um and yes absolutely sh slides
54:15will be shared we are we already have uh
54:18there's a pdf version of this already
54:21been shared uh so that should go out I
54:23think to to participants
54:26any
54:27questions got a couple minutes
54:33left um just one um I noticed during the
54:37exercises uh it was probably maybe an
54:39extract on on on thread dragon and then
54:43we also had the table that we were
54:45populating on the side uh was just uh
54:48something is it just good uh Cadence to
54:51let's say I'm using a thread Dragon
54:54normally you would put your notes in
54:55there is it also like good um sort of
54:59like Cadence to then do the extraction
55:01and have like a SE separate template
55:03like the one that we were using just to
55:05report
55:07differently uh and provide in terms of
55:10information and everyone to be able to
55:12read through that in terms of best
55:14practice uh really is itth do I need to
55:17capture everything on the dragon or
55:20dragon and then have an extract of the
55:23same data on an Excel sheet that I could
55:26probably
55:27circulate yeah great question um what
55:31and I'll probably defer to uh shoing as
55:34well but in general good idea uh there
55:38are tools that can help you uh capture
55:40that information the threats and so on
55:42uh for the hackathon we're asking that
55:44teams not use tools like that in
55:47particular drawing tools and uh
55:50recording of some sort uh document of
55:52some sort uh but but not uh using those
55:56tools but shining do you want to give
55:58some more um comment on that yeah so we
56:02will defer those questions to the prom
56:04questions channels for the chief judge
56:07Sten resp yeah okay appreciate it thank
56:11you uh but in general it is you know
56:14whatever tool works for you to record to
56:16to keep track if you're you're working
56:18on a threat model with your team um is a
56:21good idea but in in this case yeah
56:23absolutely check with the hackathon uh
56:25rules uh specifically for resources to
56:28use okay cool thanks
56:34welcome awesome let's give Robert her
56:38another virtual big round of applause
56:40for such an amazing amazing Workshop
56:43thank you Robert thank
56:46you all of us all right thank you
56:49everyone for joining us for this
56:51Workshop we will email you the slides
56:54and the recording um for this events you
56:56know whether or not you're the hackathon
56:58participant but you will get that by an
56:59email later today but those hackathon
57:01participant head back to the hackathon
57:03slack and there all the resources will
57:05be shared there all right so thank you
57:07everyone for joining have a great rest
57:08of your day thanks all thanks Robert you
57:11thank
57:13you byee