Threat Modeling and Understanding Inherent Threats – Adam Shostack – ESW #359
This is a great interview with Adam Shostack on all things threat modeling. He's often the first name that pops into people's heads when threat modeling comes up, and has created or been involved with much of the foundational material around the subject. Adam recently released a whitepaper that focuses on and defines inherent threats.
Resources:
- Here's the Inherent Threats Whitepaper
- Adam's book, Threat Modeling: Designing for Security
- Adam's latest book, Threats: What Every Engineer Should Learn from Star Wars
- We mention the Okta Breach - here's my writeup on it
- We mention the CSRB report on the Microsoft/Storm breach, here's Adam's blog post on it
- And finally, Adam mentions the British Library incident report, which is here, and Adam's blog post is here
Announcements
Security Weekly listeners save $100 on their RSA Conference 2024 Full Conference Pass! RSA Conference will take place May 6 to May 9 in San Francisco and on demand. To register using our discount code, please visit securityweekly.com/rsac24 and use the code 54USECWEEKLY! We hope to see you there!
Guest
Adam is the author of Threat Modeling: Designing for Security and Threats: What Every Engineer Should Learn from Star Wars. He’s a leading expert on threat modeling, a consultant, expert witness, and game designer. He has decades of experience delivering security. His experience ranges across the business world from founding startups to nearly a decade at Microsoft.
His accomplishments include:
– Helped create the CVE. Now an Emeritus member of the Advisory Board.
– Fixed Autorun for hundreds of millions of systems
– Led the design and delivery of the Microsoft SDL Threat Modeling Tool (v3)
– Created the Elevation of Privilege threat modeling game
– Co-authored The New School of Information Security
Beyond consulting and training, Shostack serves as a member of the Blackhat Review Board, an advisor to a variety of companies and academic institutions, and an Affiliate Professor at the Paul G. Allen School of Computer Science and Engineering at the University of Washington.