Threat Modelling – A practical method, Goal for Threat Detection Strategy.
|
Framework |
Core Focus |
|
STRIDE |
General Security |
|
PASTA |
Risk-Centric |
|
LINDDUN |
Privacy |
|
OCTAVE |
Organizational Risk |
|
Trike |
System Modeling |
|
VAST |
Agile Development |
Asset Modelling
“If you don’t know WHAt to protect, how do you know you’re PROTECTING it?” – Kurt Haase
Capture asset value align to Traffic Light Protocol and allow for heighten response for red and yellow assets.
https://www.youtube.com/watch?v=PS64b1LOVEI&feature=emb_title

-

-
Cloud Items



Required Teams
- – Board, C-Level, IT, Ops, HR, General Counsel, Legal, SecOps
- consider utilizing three-way contracts (a Master Services Agreement) between: (a) outside counsel, (b) the investigator, and (c) your company when engaging a cyber security expert to investigate and remediate a data breach.
- Use external Outside legal counsel to Preserving the Privilege during Breach Response
- https://www.fireeye.com/blog/executive-perspective/2019/04/maximize-privilege-and-work-product-protections-in-data-breach-investigations.html
- https://www.slideshare.net/cisoplatform7/preserving-the-privilege-during-breach-response
- https://www.lindabury.com/firm/insights/protecting-privilege-before-and-after-a-cyber-breach.html
- https://www.nortonrosefulbright.com/en/knowledge/publications/f984cee7/practical-privilege-risk-assessments-and-internal-investigations
- https://www.reedsmith.com/en/capabilities/services/litigation-and-dispute-resolution/records-and-e-discovery
Asset, Network, Physical, User, Operating and Dependency Models
Reference;
- AWS – https://aws.amazon.com/blogs/security/how-to-approach-threat-modeling/
- Threat Modeling Example with ChatGPT – https://blog.infosec.business/how-to-use-chatgpt-to-learn-threat-modeling/
- OpenCTI – https://www.opencti.io/en/
- Visualise MISP – https://www.vanimpe.eu/2017/10/31/misp-dashboard-real-time-visualization-misp-events/
- Threat Box – https://medium.com/@andy.c.piazza/quantifying-threat-actors-with-threat-box-e6b641109b11
- https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling
- https://insights.sei.cmu.edu/sei_blog/2018/12/threat-modeling-12-available-methods.html
- https://www.pluralsight.com/courses/threat-modeling-fundamentals?aid=701j0000001heIrAAI&promo=&oid=&utm_source=non_branded&utm_medium=digital_paid_search_google&utm_campaign=APAC_Dynamic&utm_content=&gclid=EAIaIQobChMI9P_RjpqR5wIVThSPCh1xxwcjEAAYASAAEgK2ofD_BwE
- https://www.owasp.org/index.php/OWASP_NZ_Day_2019-Training-Threat_Modelling_From_None_to_Done
- https://arstechnica.com/information-technology/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/
- https://docs.microsoft.com/en-gb/azure/security/develop/threat-modeling-tool-threats
- https://www.brighttalk.com/webcast/16345/317083?utm_source=brighttalk-portal&utm_medium=web&utm_content=Threat%20Modeling%20&utm_campaign=webcasts-search-results-feed
- Elevation of Privilege (EoP) Threat Modeling Card Game – https://www.microsoft.com/en-au/download/details.aspx?id=20303
- Table Top
- Cyber Range – https://www.securityinnovation.com/training/cmd-ctrl-cyber-range-security-training/cyber-range-suite/cmdctrl-cyber-range-shadow-bank/
- STRIDE/DREAD
- MITRE
- Abuse Cases
- Attack Trees
- https://www.sans.org/reading-room/whitepapers/securecode/threat-modeling-process-ensure-application-security-1646
- https://www.sans.org/blog/threat-modeling-hybrid-approach/
- https://isc.sans.edu/forums/diary/Threat+modeling+in+the+name+of+security/17675/
- https://threatmodelingbook.com/index.html
- https://www.giac.org/paper/gicsp/1678/ics-layered-threat-modeling/166594
- https://www.exabeam.com/information-security/threat-modeling/?utm_campaign=2020_q2_twitter_awareness&utm_content=6-threat-model&utm_medium=social&utm_source=Twitter
- https://docs.microsoft.com/en-us/previous-versions/tn-archive/dd941826(v=technet.10)?redirectedfrom=MSDN
- Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis by Marco M. Morana, Tony UcedaVelez – https://learning.oreilly.com/library/view/risk-centric-threat/9780470500965/
- threat-modeling-templates – https://github.com/Microsoft/threat-modeling-templates
- TRIKE – http://www.octotrike.org/
- VAST – https://threatmodeler.com/chained-threat-models/
- Plurasight Threat Modeling – https://app.pluralsight.com/course-player?clipId=b931cf1f-6a9b-4951-82f0-9b2303d109fa
- Threat Deck – https://github.com/dxc-technology/ThreatDeck/blob/main/INSTRUCTIONS.md
- Threat Dragon
Elevation of Privilege
- https://www.microsoft.com/en-au/download/details.aspx?id=20303
- https://www.thegamecrafter.com/games/elevation-of-privilege-scorepad
- https://github.com/adamshostack/eop
- https://boardgamegeek.com/boardgame/69134/elevation-privilege-card-game
Table Top
- https://www.sikich.com/technology/cybersecurity/ransomware/sikich-ir-ai-tabletop-simulation-2023/
- https://securityblueteam.medium.com/chatgpt-for-offensive-and-defensive-cyber-f954f51aa79f
- https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
- https://www.ready.gov/business/testing/exercises
- https://uwpd.wisc.edu/content/uploads/2014/01/What_is_a_tabletop_exercise.pdf
- https://www.alertmedia.com/resources/
- https://www.fireeye.com/services/tabletop-exercise.html
- https://www.cisecurity.org/white-papers/six-tabletop-exercises-prepare-cybersecurity-team/
- https://www.cisecurity.org/wp-content/uploads/2018/10/Six-tabletop-exercises-FINAL.pdf
- https://www.mitre.org/sites/default/files/publications/pr_14-3929-cyber-exercise-playbook.pdf
- https://www.ey.com/Publication/vwLUAssets/EY_-_Cybersecurity_Incident_Simulation_Exercises/$FILE/EY-cybersecurity-incident-simulation-exercises-scored.pdf
- https://www.aon.com/cyber-solutions/solutions/cyber-threat-simulations-tabletops/
- https://redcanary.com/blog/using-tabletop-simulations-to-improve-information-security/
- https://www.preparedex.com/4-essential-cyber-security-tabletop-exercise-tips/
- https://www.redlegg.com/advisory-services/tabletop-exercise-pretty-much-everything-you-need-to-know
- https://www.amazon.com/Adam-Shostack-ebook/dp/B00IG71FAS/ref=pd_sbsd_14_5/133-3814174-9273049?_encoding=UTF8&pd_rd_i=B00IG71FAS&pd_rd_r=e9fe9a82-4a3a-4b36-906d-f7dad6b13c06&pd_rd_w=qxZR7&pd_rd_wg=J2iAQ&pf_rd_p=2c2d0d3b-b3c5-4110-93fa-2c1270309ac1&pf_rd_r=EZAEXESH1F6TMJA4ZN5H&psc=1&refRID=EZAEXESH1F6TMJA4ZN5H
- Cyber Exercise Playbook
- https://www.threatmodelingmanifesto.org/
- Threat Modelling Connect – https://www.threatmodelingconnect.com/methodology-14/a-step-by-step-guide-to-create-your-first-threat-model-template-included-110
Threat modeling is one of the oldest aspects of cybersecurity, as early as 1977 some form of threat models were leveraged to understand the risks against systems.
🤔 However, threat modeling is not commonly practiced because it is manual and time-intensive. But is it worth the time, effort & resources? Hell YES. The value of threat modeling continually increases as our systems become more complex.
Yes, your GenAI workloads aren’t exempted ! 🙌
🎊 GOOD NEWS -> There are abundant resources that help streamline threat modeling by automating several steps.
The Threat Composer tool from Amazon Web Services (AWS) is one of such tools.
🌩️ A recent AWS blog post, provides a recommended approach for threat modeling GenAI workloads using Threat Composer. Adam Shostack‘s four question framework is used as a guide.
👉 Check out the blog post here – https://lnkd.in/g6i4zSpN
Here is a quick summary:
1️⃣ What are we working on?
Aims to get a detailed understanding of your business context & application architecture. Example outcomes are Data Flow Diagrams, assumptions, and key design decisions.
2️⃣ What can go wrong?
Identify possible threats to your application using the context & information gathered for the previous question. Leverage info sources e.g. OWASP Top 10 For Large Language Model Applications & Generative AI, MITRE ATLAS
3️⃣ What are we going to do about it?
Consider which controls would be appropriate to mitigate the risks associated with the threats identified in the previous question. Some infro sources have sections for mitigation which could be used.
4️⃣ Did we do a good enough job?
Contrary to popular opinions, threat modeling exercises do not end after the actual activity ! Its important to verify the effectiveness of the implemented mitigations to determine if the identified risks have been addressed. Use penetration testing, adversary emulation etc to proactively evaluate the effectiveness of implemented mitigations.
