Threat Modeling, Concepts, Methodologies Flashcards
1
Q
Threat Focus
A
Focused on assets
Focused on attackers
Focuses on software
2
Q
STRIDE
A
Spoofing Tampering Repudiation Information disclosure Denial of Service (DoS) Elevation of privilege
3
Q
PASTA - Process for Attack Simulation and Threat Analysis (7 Stages)
A
- Definition of the Objectives (for analysis of risk)
- Definition of Technical Scope
- Application Decomposition and analysis
- Threat analysis
- Weakness and vulnerability analysis
- Attack Modeling & Simulation
- Risk analysis & Management
4
Q
Trike
A
risk based approach instead of depending upon aggregated threat model use in STRIDE and DREAD; performing security audit in reliable + repeatable way
5
Q
DREAD stands for:
A
Disaster, Reproducibility, Exploitability, Affected Users, Discoverability
6
Q
VAST stands for:
A
Visual, Agile and Simple Threat;
Based on agile project management and programming;
scalable