Tin Zaw Scott Matsumoto - Threat Modeling A Brief History and the Unified Approach at Intuit
392 views · Published 4 July 2014 · 40:10 · Indexed 26 September 2026
Channel: OWASP Foundation · 2014 · Science & Technology
From AppSecEU 2014 in Cambridge https://2014.appsec.eu/ Threat Modeling is a software design analysis method that looks for security weaknesses by juxtaposing software design views against a set of attackers. Software engineers and security practitioners at Intuit have been practicing Threat Modeling in various ways for years. Intuit has used a Threat Model methodology based on STRIDE. The approach had many advantages, but also some drawbacks. Some of the drawbacks included amount of time required to translate the information from development (generating the Data Flow Diagrams) and difficulty in modeling different threat agents. Intuit and Cigital unified their two Threat Modeling methodologies to produce an approach that satisfies various stakeholders at Intuit. The result was what is called Unified Threat Modeling, an approach that consists of identifying assets and attacker profiles, and documenting and suggesting a list of controls. It works for software architecture and system deployments (using System Threat Modeling approach) as well as for interaction between different software and system components (via Protocol Threat Modeling approach). Speakers Scott Matsumoto Principal Consultant, Cigital, Inc. Scott Matsumoto is a Principal Consultant with Cigital. At Cigital, he is responsible for the mobile security practice within the company. He consults for many of Cigital's clients on security architecture topics such as mobile security, Cloud Computing Security, as well as SOA Security and Governance. His prior experience encompasses development of component-based middleware, performance management systems, graphical UIs, language compilers, database management systems and operating system... Tin Zaw Staff Software Engineer, Intuit Tin Zaw is a Staff Software Engineer at Intuit making secure products that help simplify financial lives of consumers and small businesses. He has over 18 years of experience in software development and information security at various capacities. He holds an MS in Computer Science and an MBA from University of Southern California. He is a former president of OWASP Los Angeles chapter. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
35:56
HTML5 JS Security - maty siman
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
2:26:27
OWASP AppSecUSA 2014 - Breakers Track - Friday
-
53:26
OWASP AppSecUSA 2014 - Keynote: OWASP Global Board
-
49:40
Building Your Application Security Data Hub: The Imperative for Structured Vulnerability Information
-
48:32
Blended Web and Database Attacks on Real-time, In-Memory Platforms - OWASP AppSecUSA 2014
-
45:23
OWASP A9: A Year Later - Are you still using components with known vulnerabilities? - AppSecUSA 2014
-
46:55
AppSec EU15 - Joshua Corman - Continuous Acceleration: Why Continuous Everything Requires A Suppl...