Threat Modelling – A practical method

batman-threat-model-1200-800x535

Threat Modelling – A practical method, Goal for Threat Detection Strategy.

Framework

Core Focus

STRIDE

General Security

PASTA

Risk-Centric

LINDDUN

Privacy

OCTAVE

Organizational Risk

Trike

System Modeling

VAST

Agile Development

Threat modelling is an exercise to generate use cases/content aligned to key business risks or concerns around specific assets. Questions are no different than probing for cyber operations optimisation. Threat Modelling provide criticism and dissent, which are incredibly valuable in a improving your Incident Response.
 
Assess Enterprise Risk
Table  Top Risks
Threat Model and develop Use case based on Incident Response Plan
Identify industry specific threats
Develop Red Team and target assests
Develop Metaspolit TTPs
Simulate based on Mitre and Caldera
Update Incident Response Plan and Security Roadmap
 
 

Asset Modelling

“If you don’t know WHAt to protect, how do you know you’re PROTECTING it?” – Kurt Haase

Capture asset value align to Traffic Light Protocol and allow for heighten response for red and yellow assets.

https://www.youtube.com/watch?v=PS64b1LOVEI&feature=emb_title

ArcSight Asset Modeling - YouTube 2020-01-23 13-36-07

  • Zoom Meeting ID: 552-878-997 2020-01-24 12-15-18

     

  • Cloud Items

    AWS Well-Architected: Security Pillar 2020-01-26 18-28-43

    product-page-diagram-Amazon-GuardDuty_how-it-works.4370200b49eddc34d3a55c52c584484ceb2d532b

    0.pdf (1 page) 2020-01-31 09-51-49

    Required Teams

  •  
  • – Board, C-Level, IT, Ops, HR, General Counsel, Legal, SecOps
  • consider utilizing three-way contracts (a Master Services Agreement) between: (a) outside counsel, (b) the investigator, and (c) your company when engaging a cyber security expert to investigate and remediate a data breach.
  • Use external Outside legal counsel to Preserving the Privilege during Breach Response
    • https://www.fireeye.com/blog/executive-perspective/2019/04/maximize-privilege-and-work-product-protections-in-data-breach-investigations.html
    • https://www.slideshare.net/cisoplatform7/preserving-the-privilege-during-breach-response
    • https://www.lindabury.com/firm/insights/protecting-privilege-before-and-after-a-cyber-breach.html
    • https://www.nortonrosefulbright.com/en/knowledge/publications/f984cee7/practical-privilege-risk-assessments-and-internal-investigations
    • https://www.reedsmith.com/en/capabilities/services/litigation-and-dispute-resolution/records-and-e-discovery

Asset, Network, Physical, User, Operating and Dependency Models

Reference;

Elevation of Privilege

Table Top

Threat modeling is one of the oldest aspects of cybersecurity, as early as 1977 some form of threat models were leveraged to understand the risks against systems.

🤔 However, threat modeling is not commonly practiced because it is manual and time-intensive. But is it worth the time, effort & resources? Hell YES. The value of threat modeling continually increases as our systems become more complex.

Yes, your GenAI workloads aren’t exempted ! 🙌

🎊 GOOD NEWS -> There are abundant resources that help streamline threat modeling by automating several steps.

The Threat Composer tool from Amazon Web Services (AWS) is one of such tools.

🌩️ A recent AWS blog post, provides a recommended approach for threat modeling GenAI workloads using Threat Composer. Adam Shostack‘s four question framework is used as a guide.

👉 Check out the blog post here – https://lnkd.in/g6i4zSpN

Here is a quick summary:

1️⃣ What are we working on?
Aims to get a detailed understanding of your business context & application architecture. Example outcomes are Data Flow Diagrams, assumptions, and key design decisions.

2️⃣ What can go wrong?
Identify possible threats to your application using the context & information gathered for the previous question. Leverage info sources e.g. OWASP Top 10 For Large Language Model Applications & Generative AI, MITRE ATLAS

3️⃣ What are we going to do about it?
Consider which controls would be appropriate to mitigate the risks associated with the threats identified in the previous question. Some infro sources have sections for mitigation which could be used.

4️⃣ Did we do a good enough job?
Contrary to popular opinions, threat modeling exercises do not end after the actual activity ! Its important to verify the effectiveness of the implemented mitigations to determine if the identified risks have been addressed. Use penetration testing, adversary emulation etc to proactively evaluate the effectiveness of implemented mitigations.

Leave a comment