Security Threat Modeling takes you through the four main phases of threat modeling: identifying assets, identifying threats, analyzing vulnerabilities, and creating countermeasures or safeguards. Several threat modeling frameworks are introduced and compared, including CIA, Attack Trees, OCTAVE, VAST, STRIDE, and PASTA. The course also covers LINDDUN, alongside the OWASP Threat Modeling Cheat Sheet.
In a practical lab setting, the course examines data-flow diagram (DFD) approaches and the differences between DFD elements. These include processes, data stores, external entities, data-flows, and trust boundaries. Students practice modeling applications, infrastructure, and cloud, physical, and embedded systems at the appropriate DFD depth layer. They work from the system layer down to the lower-level layer. Day one closes by comparing system-focused, asset-focused, and attacker-focused approaches to threat modeling.
Day two walks through the STRIDE framework’s six threat categories: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. Students also study the security controls that address each, using Microsoft’s Threat Modeling Tool across a multi-part lab. Attendees then learn how and when to prioritize identified issues using established priority frameworks. The course closes by revisiting non-DFD methods and tooling, including OWASP pytm, OWASP Threat Dragon, and emerging AI-assisted tools such as iriusrisk. Upon completion, attendees will have the skills and information needed to choose a threat modeling framework that suits their needs. They can then create effective threat models for their production systems.
Who Should Attend
Admins, Developers, DevOps Engineers, Solution Architects and Security Engineers
What Attendees Will Learn
Upon completing Security Threat Modeling, attendees will be able to:
- Explain the four main phases of threat modeling and compare popular threat modeling frameworks
- Build data-flow diagrams (DFDs) and apply them to real systems at the right depth
- Choose an appropriate threat modeling focus, whether system, asset, or attacker focused
- Apply the STRIDE framework to identify spoofing, tampering, repudiation, and other threat categories
- Prioritize identified issues and apply appropriate security controls
- Use tools such as Microsoft’s Threat Modeling Tool, OWASP pytm, and OWASP Threat Dragon
- Select a threat modeling framework and tooling that fits their organization’s needs
Prerequisites
Attendees should have Linux skills and basic networking skills. Prior application or infrastructure security experience is helpful but not required.