Home > Ask the Security Experts > Information Security Threats Questions & Answers > Can threat modeling help enterprises?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can threat modeling help enterprises?

Ed Skoudis, past SearchSecurity.com expert EXPERT RESPONSE FROM: Ed Skoudis, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 October 2007
Is threat modeling a useful defense mechanism? Is it really possible to think like an attacker?

>
Threat modeling is an incredibly useful tool for security pros today. To conduct a threat modeling exercise, follow the steps below.

First, have your team brainstorm about your organization's most valuable information assets, your important computing resources and where they are located.

Next, discuss in detail who might attack your enterprise and why. These are your threats. Would cybercriminals attack you? How about nation-states? What about the insider threat? Don't forget to consider an errant worm or bot that gets installed inside your environment. Not all of today's threats are human ones.

Third, based on your list of threats, start thinking about how they could exploit you. What are the easiest ways in? What are the most damaging attacks that someone could do to you? Get very detailed, and don't immediately rule out the various outlandish ideas that your folks may come up with. Where threat and vulnerability overlap, you have a risk.

Finally, consider the countermeasures that you have deployed to deal with these risks. Would your defenses block the attack scenarios you've formulated? If not, would you at least quickly detect a malfeasance and respond in a timely fashion?

Of course, you won't be able to come up with all of the ways that bad guys and malware could attack you. The attackers are a creative lot and are constantly innovating. To use an old cliché: you can't think like all of the bad guys all of the time, but you can think like some of them some of the time. Thus, make sure that you can at least defend against what your team considers the most common and most damaging attacks. Without doing some of this basic threat modeling, you might get hit with a very predictable and obvious attack that should have been blocked.

The team over at the Open Web Application Security Project (OWASP) has put together a great synopsis of various threat modeling approaches, inspired by Microsoft's own process. This great summary describes different ways of determining an organization's greatest threats and associated risks. Various companies are also working on automated threat modeling software, including Skybox Security.

More information:

  • Michael Cobb explains how threat modeling can improve the security of Web applications.
  • Learn other ways to define an 'acceptable' level of risk.


  • BROWSE BY TAG
    Information Security Threats,   Application and Platform Security,   Enterprise Vulnerability Management,   Vulnerability Risk Assessment,   Security Testing and Ethical Hacking,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Information Security Threats
    How to get rid of malware, botnets on a hospital IT network
    Should a national cybersecurity strategy include offensive botnets?
    How can search results lead to malware?
    How to prevent brute force webmail attacks
    How to prevent mobile phone spying
    What are today's antivirus software trends?
    How to detect input validation errors and vulnerabilities
    Can secure USB devices prevent man-in-the middle attacks
    How to prevent and build protection against online identity theft
    Is there a spy on my mobile device?

    Vulnerability Risk Assessment
    What patch management metrics does Project Quant use?
    Screencast: How to launch an OpenVAS scan
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    Newest malware threats
    Are Web application penetration tests still important?
    PCI compliance requirement 6: Systems and applications
    Cybercrime and threat management
    Vulnerability Risk Assessment Research

    Security Testing and Ethical Hacking
    H.D. Moore speaks about Metasploit Project deal, Release 3.3
    Could Metasploit popularity erode?
    Metasploit Project acquired by vulnerability management firm Rapid7
    Should management processes change based on a patch release schedule?
    Does an EULA make it truly illegal to decompile software?
    Screencast: BackTrack 4 offers an arsenal of penetration testing tools
    Security testing firm uncovers XML vulnerabilities
    Screencast: Samurai offers pen-testing nirvana
    The requirements needed to make an external penetration test legal
    McAfee to acquire Solidcore Systems for whitelisting

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    gray hat  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts