Skip to content
AppSec PodcastThe Application Security Podcast — home
2 min

Adam Shostack – Threat Modeling – 5 Minute AppSec

With Adam Shostack

Threat Modeling

Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 4 chapters
  1. 00:00Why threat model?Audio
  2. 00:10Structured, systematic, and comprehensive securityAudio
  3. 01:07The promised full interviewAudio
  4. 01:33A candid recording outtakeAudio

About this episode

Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the results to guide the rest of the security program. Skip that step, Adam warns, and you are shooting in the dark. Stay through the end for a candid recording outtake.

Connect with Adam Shostack:
Adam Shostack on LinkedIn
Shostack + Associates

Resources
Adam Shostack
Attack Trees (Schneier)
Cyber Kill Chain (Lockheed Martin)

Actionable

From this conversation

  1. Define the system you are protecting

    By asking, what are we working on? You can make sure that the things that you're working on are getting considered.

    0:22
  2. Use structured methods to identify threats

    By using a structured approach to asking what can go wrong, like STRIDE or attack trees or a kill chain, you can systematically go through each of the elements of your system to make sure that you've thought about security. And that can inform the entire remainder of your AppSec program and activities.

    0:32
  3. Threat-model before choosing security work

    If you don't threat model, you're shooting in the dark and hoping to hit the right things.

    1:01
Transcript · 2 min conversation

0:00Chris RomeoIf you've done anything with threat modeling, you've heard of Adam Shostack. And on this 5 Minute AppSec, we asked Adam a very simple question: why would anybody ever threat model?

0:10Adam ShostackYou know, it's a great question. Threat modeling is fundamentally the best way to make sure that your security activities are structured, systematic and comprehensive.

0:22Adam ShostackBy asking, what are we working on? You can make sure that the things that you're working on are getting considered.

0:32Adam ShostackBy using a structured approach to asking what can go wrong, like STRIDE or attack trees or a kill chain, you can systematically go through each of the elements of your system to make sure that you've thought about security. And that can inform the entire remainder of your AppSec program and activities.

1:01Adam ShostackIf you don't threat model, you're shooting in the dark and hoping to hit the right things.

1:07Chris RomeoStay tuned for our next episode where you'll hear the full interview we did with Adam on the topic of threat modeling layer 8, or looking at threat modeling from the human problem perspective. And if you ever wonder what happens behind the scenes here at the Application Security Podcast, continue listening for our first attempt at recording this 5 Minute AppSec. So Adam, why do we need threat modeling?

1:33You know, I don't even know. Sorry, I just had to give you that. You want to do it again?

1:45Chris RomeoYeah, I'm putting that— it's going to be the shortest 5 Minute AppSec of all time. It's gonna be like one sentence. And I was like, nah, I don't really know why.

269 words · transcript by assemblyai

More on Threat Modeling

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.