Summary
In this chapter, we reviewed the PASTA, STRIDE, VAST, and Trike threat models as well as attack trees from both a risk- and attack-identification perspective. Throughout your career, you will use a combination of the threat models discussed, or even others, to find the best combination to fit your organization because, like most things, there is no true “one size fits all” for threat models. Threat models are also a concept that you want to be comfortable with because they are a constant task; whether it’s creating the initial models or validating them to ensure they are still accurate; threat models are constantly changing. For a quick reference on the different models, use this chart:
PASTA threat model |
STRIDE threat model |
VAST threat model |
Trike threat model |
Attack trees |
... |