存档

文章标签 ‘Threat Modeling Web Applications’

Threat Risk Modeling

2011年8月17日 没有评论

When you start a web application design, it is essential to apply threat risk modeling; otherwise you will squander resources, time, and money on useless controls that fail to focus on the real risks.

The method used to assess risk is not nearly as important as actually performing a structured threat risk modeling. Microsoft notes that the single most important factor in their security improvement program was the corporate adoption of threat risk modeling.

阅读全文…

High-Level Threat Modelling Process

2011年8月17日 没有评论

The following is a (slightly modified) version of a document I wrote for the VSTO team way back in the day. You might find it useful as you plan threat modelling for your product(s). You should of course read the Threat Modelling book from Microsoft Press if you want to go into great details about how to do a good job of threat modelling, but this might be enough to get you started on a plan.

阅读全文…

Guerrilla Threat Modelling

2011年8月17日 没有评论

 I’m not talking about writing a threat model for a large, furry ape (although that would be fun); I’m talking about writing quick-and-dirty threat models when you don’t have time to do the real thing. If you want to do threat modelling properly, I highly recommend you read Frank and Window’s “Threat Modeling” [sic] book from Microsoft Press; but if you just need to get one done, you might not have the time or inclination for that.

阅读全文…

Create a good threat model in 10 simple steps

2011年8月16日 没有评论

 How can I get a great and secure product without killing myself? This is not just a question for how-to diet magazines; it’s a legitimate business problem. I teach the ACE Threat Modeling class (First Wednesday of every month!), and that is the question I hear most often.

阅读全文…

Threat Modeling Express

2011年8月16日 没有评论

这个是精简型的TM,不错。

阅读全文…

Introduction to Security Threat Modeling

2011年8月16日 没有评论

Security threat modeling, or threat modeling, is a process of assessing and documenting a system抯 security risks. Security threat modeling enables you to understand a system抯 threat profile by examining it through the eyes of your potential foes. With techniques such as entry point identification, privilege boundaries and threat trees, you can identify strategies to mitigate potential threats to your system. Your security threat modeling efforts also enable your team to justify security features within a system, or security practices for using the system, to protect your corporate assets.

阅读全文…

Threat Modeling I’m coming

2011年8月16日 2 条评论

Threat Modeling Web Applications

2009年8月27日 没有评论

Threat Modeling Web Applications  http://msdn.microsoft.com/en-us/library/ms978516.aspx

At a Glance: Web Application Threat Modeling http://msdn.microsoft.com/en-us/library/ms978523.aspx

How To: Create a Threat Model for a Web Application at Design Time http://msdn.microsoft.com/en-us/library/ms978527.aspx