Death Star Threat Modeling - Kevin Williams

16kbps 64kbps

In the field of Information Security, the terms vulnerability, threat, and risk have specific meanings and are often misapplied and misidentified in projects. This presentation will explain threat modeling as it applies to information and application security projects, utilizing the shared memory of the Death Star trench run as an analogy to better understand these concepts. You will learn how to define risks, threats, vulnerabilities, and countermeasures; how to integrate threat modeling into a software development lifecycle; examine example threat modeling methodologies; and hear real-world anecdotes of threat modeling successes and failures.

Also huffduffed as…

  1. Death Star Threat Modeling

    —Huffduffed by jt421 on March 22nd, 2010

Possibly related…

  1. Douglas Crockford - Ajax security

    Douglas Crockford talks about the broken security model of the browser at Web Directions South 2008.

    http://www.webdirections.org/resources/douglas-crockford-ajax-security/

    —Huffduffed by adactio 4 years ago

  2. Episode 012: “Security 2.0”

    http://devzone.zend.com/article/3364-The-ZendCon-Sessions-Episode-12-Security-2.0

    Welcome to The ZendCon Sessions. This episode of The ZendCon Sessions was recorded live at ZendCon 2007 in Burlingame, CA.

    We hope you enjoy today’s session as we listen to Chris Shiflett present "Security 2.0".

    The ZendCon Sessions are distributed under a creative commons Attribution-Noncommercial-No Derivative Works 3.0 License, Please honor this license and the rights of our authors.

    If you like the ZendCon Sessions, why not consider attending the next ZendCon? Dates, locations, speakers and just about anything else you would want to know about ZendCon can be found on our website, www.zendcon.com

    —Huffduffed by michaelfox 2 years ago

  3. Blue Box: The VoIP Security Podcast

    A periodic podcast on VoIP security news, comments and opinions from two security professionals associated with the Voice Over IP Security Alliance (VOIPSA).

    http://www.blueboxpodcast.com/

    —Huffduffed by agileone one year ago