Search / 15 posts tagged threat modeling

Subscribe
  1. No one has claimed this blog

    What do you want to know about SDL threat modeling?

    http://blogs.msdn.com/ sdl/ archive/ 2008/ 07/ 31/ what-do-you-want-to-know-abou…

    Adam Shostack here. I'm working on a paper about "Experiences Threat Modeling at Microsoft" for an academic workshop on security modeling. I have some content that I think is pretty good, but I realize that I don't know all the questions that readers might have.

  2. No one has claimed this blog

    Minimizing the Attack Surface, Part 2

    http://www.veracode.com/ blog/ ?p=113

    I’m finally getting around to finishing my post on minimizing attack surfaces. Here’s Part 1, in case you missed it. First, a quick clarification. I noticed that some of the readers who commented on that first post wanted to talk about improving security through the use of various development methodologies or coding frameworks.

  3. View all »

    Videos about threat modeling

    1. Death Star Threat Modeling - Part 1
    2. LayerOne 2008 - Adam Shostack - SDL Threat Modeling
    3. Death Star Threat Modeling - Part 2
    4. Death Star Threat Modeling - Part 3
  4. No one has claimed this blog

    Security Thoughts from TechEd 2008

    http://blogs.msdn.com/ sdl/ archive/ 2008/ 06/ 26/ security-thoughts-from-teched…

    Hi, this week is a post from Michael Howard and Laura Machado de Wright, who both attended and presented at TechEd 2008 in Orlando the week of June 2nd. First up is Laura. I have been a Security Program Manager for the last 3 years, working as a security advisor for a variety of products across Microsoft and the last seven months as a member of the SDL policy team.

  5. No one has claimed this blog

    Minimizing the Attack Surface, Part 1

    http://www.veracode.com/ blog/ ?p=111

    What was the first thing you learned about network security? There’s a good chance it had something to do with port scanning. After scanning a few boxes, you realized that modern operating systems have a lot of open ports by default, meaning a lot of services. Some had an obvious purpose, like telnet on tcp/23 or ftp fon tcp/21.

  6. No one has claimed this blog

    SDL Threat Modeling: Past, Present and Future

    http://blogs.msdn.com/ sdl/ archive/ 2008/ 06/ 17/ sdl-threat-modeling-past-pres…

    Adam Shostack here. I wanted to share my slides from the recent Layer One conference [link], where I talked about "SDL Threat Modeling: Past, Present and Future." There are a few points that I wanted to emphasize. The first is that I'm talking about threat modeling from the perspective of the SDL.

  7. No one has claimed this blog

    Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?

    http://blogs.msdn.com/ ace_team/ archive/ 2008/ 06/ 14/ application-security-dev…

    Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive approaches.

  8. Photo of dancornell

    ROOTS Conference Wrap Up

    http://denimgroup.typepad.com/ denim_group/ 2008/ 05/ more-thoughts-o.html

    By Dan Cornell I made it back to the States after the ROOTS conference and wanted to post some comments. It was a great conference with a lot of interesting folks and I was thrilled to have the opportunity to present. On Tuesday, Andre Klingsheim and Lars-Helge Netland gave a great talk on Architectural Risk Analysis.

  9. No one has claimed this blog

    ROOTS Conference Wrap Up

    http://denimgroup.typepad.com/ denim_group/ 2008/ 05/ more-thoughts-o.html

    By Dan Cornell I made it back to the States after the ROOTS conference and wanted to post some comments. It was a great conference with a lot of interesting folks and I was thrilled to have the opportunity to present. On Tuesday, Andre Klingsheim and Lars-Helge Netland gave a great talk on Architectural Risk Analysis.

    105 days ago in Denim Group, Ltd. · Authority: 5
  10. No one has claimed this blog

    Front Range web application security summit in Denver

    http://blogs.msdn.com/ ace_team/ archive/ 2008/ 05/ 04/ front-range-web-applicat…

    I will be speaking at the Front Range OWASP Conference (FROCo8) in Denver on June 10th. The focus of the conference to share the experiences that the speakers had around solving technical and management issues surrounding application security.

  11. No one has claimed this blog

    Front Range web application security summit in Denver

    http://blogs.msdn.com/ ace_team/ archive/ 2008/ 05/ 04/ front-range-web-applicat…

    I will be speaking at the Front Range OWASP Conference (FROCo8) in Denver on June 10th. The focus of the conference to share the experiences that the speakers had around solving technical and management issues surrounding application security.

Rising and falling

Technorati data powered by Truviso

Mentions by Day

Posts tagged threat modeling per day for the past 30 days.

Chart of results for threat modeling

See your posts here

To contribute to this page, include this code in your blog post: