Search icon CANCEL
Subscription
0
Cart icon
Cart
Close icon
You have no products in your basket yet
Save more on your purchases!
Savings automatically calculated. No voucher code required
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Threat Modeling

You're reading from  Threat Modeling

Product type Book
Published in Feb 2014
Publisher Wiley
ISBN-13 9781118809990
Pages 624 pages
Edition 1st Edition
Languages
Author (1):
Adam Shostack Adam Shostack
Profile icon Adam Shostack
Toc

Table of Contents (15) Chapters close

1. Cover
2. Part I: Getting Started 3. Part II: Finding Threats 4. Part III: Managing and Addressing Threats 5. Part IV: Threat Modeling in Technologies and Tricky Areas 6. Part V: Taking It to the Next Level 7. Glossary
8. Bibliography
9. Introduction 10. End User License Agreement
Appendix A: Helpful Tools 1. Appendix B: Threat Trees 2. Appendix C: Attacker Lists 3. Appendix D: Elevation of Privilege: The Cards 4. Appendix E: Case Studies

How To Use This Book

You should start at the very beginning. It's a very good place to start, even if you already know how to threat model, because it lays out a framework that will help you understand the rest of the book.

The Four-Step Framework

This book introduces the idea that you should see threat modeling as composed of steps which accomplish subgoals, rather than as a single activity. The essential questions which you ask to accomplish those subgoals are:

  1. What are you building?
  2. What can go wrong with it once it's built?
  3. What should you do about those things that can go wrong?
  4. Did you do a decent job of analysis?

The methods you use in each step of the framework can be thought of like Lego blocks. When working with Legos, you can snap in other Lego blocks. In Chapter 1, you'll use a data flow diagram to model what you're building, STRIDE to help you think about what can go wrong and what you should do about it, and a checklist to see if you did a decent job...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime