Tutorial

Go Back   Tutorial > Technology > Home security tips

Forum overview

Latest topics
Show:

Portalsearch

Advanced Search

Statistic
Topics: 37432
We welcome our newest user: Feelaabinmelt
New users:
12-05-2008
- Feelaabinmelt
12-05-2008
- Fubembemflumn
12-05-2008
- TabSleernezen
12-04-2008
- bedDeldMype
12-04-2008
- bedGeseejaina


Threat Model vs Attack Model


Home security tips

Sponsored Links:

Reply
 
Thread Tools Search this Thread Display Modes

  #1  
Old 06-12-2007, 09:23 PM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,895
Threat Model vs Attack Model

Sponsored Links:
This is just a brief post on terminology. Recently I've heard people discussing "threat models" and "attack models." When I reviewed Gary McGraw's excellent Software Security I said the following:

Gary is not afraid to point out the problems with other interpretations of the software security problem. I almost fell out of my chair when I read his critique on pp 140-7 and p 213 of Microsoft's improper use of terms like "threat" in their so-called "threat model." Gary is absolutely right to say Microsoft is performing "risk analysis," not "threat analysis." (I laughed when I read him describe Microsoft's "Threat Modeling" as "[t]he unfortunately titled book" on p 310.) I examine this issue deeper in my reviews of Microsoft's books.

In other words, what Microsoft calls "threat modeling" is actually a form of risk analysis. So what is a threat model?

Four years ago I wrote Threat Matrix Chart Clarifies Definition of "Threat", which showed the sorts of components one should analyze when doing threat modeling. I wrote:

It shows the five components used to judge a threat: existence, capability, history, intentions, and targeting.

That is how one models threats. It has nothing to do with the specifics of the attack. That is attack modeling.

Attack modeling concentrates on the nature of an attack, not the threats conducting them. I mentioned this in my review of Microsoft's Writing Secure Code, 2nd Ed:

[W]henever you read "threat trees," [in this misguided Microsoft book] think "attack trees" -- and remember Bruce Schneier worked hard on these but is apparently ignored by Microsoft.

That is still true -- Bruce Schneier's work on attack trees and attack modeling is correct in its terminology and its applications. Attack trees are a way to perform attack modeling. Attack modeling can be done separate from threat modeling, meaning one can develop an attack tree that any sufficient threat could execute.

This understanding also means most organizations will have more useful results performing attack modeling and not threat modeling, because most organizations (outside law enforcement and the intel community) lack any real threat knowledge. With the help of a pen testing team an organization can develop realistic attack models and therefore effective countermeasures. This is Ira Winkler's point when he says most organizations aren't equipped to deal with threats and instead they should mitigate vulnerabilities that any threat might attack.

This does not mean I am embracing vulnerability-centric security. I still believe threats are the primary security problem, but only those chartered and equipped to deter, apprehend, prosecute, and incarcerate threats should do so. The rest of us should focus our resources on what we can, but take every step to get law enforcement and the military to do the real work of threat removal.Copyright 2003-2007 Richard Bejtlich
Sponsored Links:
Reply With Quote
Reply

Sponsored Links:

Compare price

Compare products

Download software


Free Download Softwware


Tags: , ,



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Top of the Model LapTop Bikini Picture 0 05-28-2007 04:28 PM
Bikini Model LapTop Bikini Picture 1 05-18-2007 12:00 AM
Bikini Model LapTop Bikini Picture 0 05-17-2007 04:34 PM
Get a Role Model LapTop Tennis tips 0 04-29-2007 05:17 AM
RGB color model LapTop Photoshop Tutorials 0 04-29-2007 04:15 AM



All times are GMT. The time now is 01:01 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

RSS 2.0 HOME