Threat Modeling: Designing for Security
About this book
Shostack turns threat modelling into something a delivery team can do rather than something a specialist performs on their behalf. The method is built around a short sequence of questions, starting with what you are building and moving on to what can go wrong with it, what you will do about that, and whether the analysis was good enough. Most of the book addresses the second question, using STRIDE and attack trees to find the tampering, spoofing and privilege escalation problems hiding in a system diagram. Later parts cover threat modelling for privacy, for cryptographic systems and for human factors, plus how to introduce the practice into an existing development process. Long, and organised so you can read the parts relevant to your system.
Description via Product Digest.