--- title: "Steven Wierckx -- The #OWASP Threat Modeling Project" url: https://appsecpodcast.com/steven-wierckx-the-owasp-threat-modeling-project/ date: 2018-04-06 duration_seconds: 1950 guests: ["Steven Wierckx"] topics: ["Threat Modeling"] audio: https://www.buzzsprout.com/1730684/episodes/8122689-steven-wierckx-the-owasp-threat-modeling-project.mp3 transcript: true --- # Steven Wierckx -- The #OWASP Threat Modeling Project *April 6, 2018 · 33 min* with [Steven Wierckx](https://appsecpodcast.com/guests/steven-wierckx/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122689-steven-wierckx-the-owasp-threat-modeling-project.mp3) ## Show notes Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open discussion could help practitioners compare approaches and adapt them to agile development. Steven also explains the relationship between documentation and tools such as Threat Dragon. The episode closes with how working sessions and community contributions can turn shared experience into practical resources. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Steven Wierckx: → [Steven Wierckx on LinkedIn](https://www.linkedin.com/in/steven-wierckx/) Mentioned in this episode: → [OWASP Threat Modeling Project](https://owasp.org/www-project-threat-modeling/) → [OWASP Threat Dragon](https://owasp.org/www-project-threat-dragon/) → [Open Security Summit 2018 archive](https://2018.open-security-summit.org/) Chapters: 00:00 The OWASP Threat Modeling Project 01:11 Steven’s security origin story 04:04 How the summit shaped the project 07:42 What methodology-neutral threat modeling means 10:46 The four common threat modeling questions 12:30 Building a community of practitioners 15:34 Example models and the project roadmap 20:05 How documentation and Threat Dragon fit together 24:15 Planning the Open Security Summit 27:48 Turning working sessions into published resources 30:28 How to participate in threat modeling ## Transcript *4,629 words · assemblyai* **0:00 Chris Romeo:** Hey folks, welcome to season 3, episode 12 of the Application Security Podcast. On this episode, Robert and I investigate the new OWASP Threat Model Project by interviewing Steven, the new project lead. Steven explains the project, talks about his vision for the future, and also introduces us to the Open Security Summit that happens in June 2018, where a lot of work is going to occur on this project. We hope you enjoy. The Application Security Podcast. Here we go. **0:58 Robert Hurlbut:** Hello folks, and welcome to another episode of the Application Security Podcast. Chris and I are joined today by Steven Verdicts. I hope I pronounced that correctly. Welcome, Steven. **1:09 Steven Wierckx:** Thank you for having me. **1:11 Robert Hurlbut:** Absolutely. And as we get started, what we'd like to do to begin with is if you could give us your security origin story. How did you get into this? **1:22 Steven Wierckx:** Well, I finished my degree in '99, and at that time there was very little to do with security when you were studying IT-related topics. So I started off as a programmer, and after a while I migrated more to the QA side of things, so the quality assurance side of things. And I became a tester. I was writing my own test tools and things like that. And at some point, I went to OWASP, and I went to an OWASP Belgium chapter meeting. And that's in fact how I got into security. And I've been trying to improve security of applications for the past 7 or 8 years now. **2:14 Robert Hurlbut:** Excellent. Thank you. **2:14 Chris Romeo:** So, what was the first— as a programmer, what were you actually writing? Were you writing web apps or— web apps might not have even existed back then. I can't remember. **2:25 Steven Wierckx:** Yeah, there were some web apps, but mainly I got started in Visual Basic 6, which I still think was one of the nicest languages to actually write in. Because you could just draw a GUI on screen with your customer and afterwards just put in the code to get the whole thing working. But it was a rapid application development, some possibilities that we had with Visual Basic 6 that I didn't see anywhere after. It did present us with the unique problem that whenever we drew all the screens, our customers thought that they would have the actual working program within a week, and usually that took us like 4 to 6 months of programming. So there were some, some challenges in explaining to customers there was a little bit more to just drawing some buttons on the screen. **3:23 Chris Romeo:** Yeah, I had the, uh, I had the advantage to do some Visual Basic programming back around that same time frame as well, and I, I also have fond memories of it as an environment and a language that really did make things quite easy to work with. And I even got my project to actually compile and burned it on a CD-ROM, if anybody remembers what those things are. **3:49 Steven Wierckx:** Yeah, yeah. I also remember that we used to have a problem which was like a real bubble that exploded into basically nothing happening. So that was around the same time. **4:04 Robert Hurlbut:** Well, thanks again for joining us, Stephen. So today what we want to cover is the OWASP Threat Modeling Project. And before we get into that, I wanted to also mention, I'm sure you'll talk a little bit about it as well, but I can remember a year ago we had a chance to meet and talk about threat modeling. And in particular, there was the OWASP Summit that happened last June, and that was a pretty exciting time to look at a lot of different projects going on, and in particular the threat modeling project. I remember being a part of that remotely at the time, but seeing what was going on, and I remember you and I talking at that time. And so in terms of talking about the OWASP threat modeling project, first of all, tell us about what it is and then maybe even how that relates to the OWASP summit and things that are going on there now? **5:00 Steven Wierckx:** Yeah, so the OWASP Threat Modeling Project is what is known within OWASP as a documentation project. So we should not confuse it with other related projects like, for example, the ThreadDragon project and some of the other tools that are currently being developed. So the whole purpose of the OWASP Threat Modeling Project is to be vendor and methodology independent. We are completely agnostic, and we would like to build a knowledge base on threat modeling. And we'll go deeper into exactly what are the things that we want to document then in just a little bit. But indeed, the project got started during that OWASP Summit. And we were lucky enough to have, I think, around 20 people that were interested in threat modeling at the time. And some of those were actually quite famous people, or at least famous within the threat model world. So we had not only very good practitioners there, but we had 2 different authors, so authors of 2 different threat modeling books present, and I think we were probably one of the bigger groups within the summit. So we did get a whole lot of work done in the sense that we created a lot of content. Unfortunately, once I got the project started, the actual putting out the content on the web pages got a bit delayed, but The second part of the OWASP Threat Modeling Project is where we're actually doing most of the work now. We are building a community which for which we primarily use the OWASP Slack workspace, and there we have the Threat Model channel. And basically we have, I think, about between 250 and 300 people there, some of them quite active to discuss. all things threat model related. So as a project leader, I have been more focusing on building a community on the Slack channel than actually writing the content of the website, because I think once we have a good community going, the content will materialize by itself. **7:42 Chris Romeo:** Hey, Steven, so I'm going to go back to something that you said kind of right off the beginning when you started to describe the project here. You said that the goal was to create something that was vendor and methodology agnostic. And so, I'm somebody who's done threat modeling quite a bit in my career. I rolled it out inside of a large technology company. And so, I'm curious as to, maybe you can explain a little bit for me, how could this possibly be methodology agnostic when, at least from my perspective, a lot of what goes into threat modeling is actually the methodology behind it? It's the taking Microsoft's kind of stride approach and applying that versus the folks that are advocating for PASTA or the folks that are advocating for more of a risk management-based decision. I see all of those as methodologies, and I guess I don't see how you could do— how you could have a threat modeling project that was— that didn't— wasn't specific to a methodology. So maybe you can gimme a little bit of an explanation of that if you could. **8:43 Steven Wierckx:** Yeah, so the very first idea that we had when people like Tony, who wrote the book on PASTA, and Adam, who wrote the book in which the methodology where you use TRITE is completely described, we all sat together and we figured out that basically all threat model methodologies use roughly the same steps. The first thing you need to do is create some kind of a model. And a model, I think most of us agree that we use the model just to communicate with each other. Now, what do we want to communicate? We want to create a list of threats against the thing we're doing the threat modeling on, which when we look at OWASP, it's mainly web applications, but you could threat model Basically anything you want, and so you want to create this list of threats. And in theory, that would be a threat model. But to make it interesting for an organization, of course, you're also going to look at how are we going to make sure that none of these threats materialize. And basically, the people that we had at the summit, so we had some people that were proficient in trike. We had some people. Coming out of the, let's say, the Microsoft Threat Model Methodology background. We had people that were doing PASTA. And basically, these 3 steps are always present in each of these methodologies. It is the way in which they handle these questions, in how they formalize all these things, how they break them up into smaller, more manageable parts, that is where the threat model methodology actually comes into play. We, during the summit, we also discussed with a group of people how you could actually do threat modeling in, for example, an agile environment. **10:45 Robert Hurlbut:** Mm-hmm. **10:46 Steven Wierckx:** Because none of the methodologies I mentioned can just be plugged into an agile environment. So We did a lot of work around that. Basically, what we all agree upon is that you ask yourself, we call it the 4 questions. What are you building? It is your model. What can go wrong? What are you going to do about it? Then the 4th one is your QA step. Did we do a good enough job? No matter which methodology you use, you're always going to have in some form or another these 4 steps. So that's how we can say we, we're methodology agnostic. **11:31 Chris Romeo:** Yeah, that makes sense. Thank you for explaining that. And just for our listeners' reference point, so Steven mentioned threat modeling and agile. We had Irene Michelin on a few episodes ago to talk about that, that entire idea of how agile and threat modeling kind of fit together. And you also mentioned Tony, which I'm assuming you're talking about Tony UV since he's the only threat modeling author named Tony that I'm aware of. **11:59 Steven Wierckx:** Yes, yes. **11:59 Chris Romeo:** As well as Adam Szostak. So, Tony and Adam have both been on the show previously. So, listeners, if you want to dive back into a little bit more of the history of the things we've talked about regarding threat modeling, we've had 3 different perspectives and 3 different awesome experts that have already been on in the past to talk about threat modeling. So, Yeah, so that's kind of— it's just a point of reference, something you can go back and take a little closer look at here. So Robert, where are we going next with our threat modeling OWASP journey? **12:30 Robert Hurlbut:** Well, I think we talked a little bit about where things are currently in the threat modeling universe for OWASP. What does— you mentioned Slack, and so getting people together and building a community community. What does community mean then to threat modeling? How is that important? **12:53 Steven Wierckx:** Well, in order to explain that, I'll first explain how we work, or at least what I propose as the way of working within this OWASP project. So we want to publish a whole range of different types of information. And the way we go about it is that we're working on some Google documents, and I post something on Slack, or let's say somebody else asks a question on Slack, and I think, okay, that would be a good thing to have on the website. So we create a Google Doc for that, and people can go to the Google Doc and they can share their insights. So we work a lot with a comment system there. At some point, we as a group decide that, okay, the content that's on there is a consensus that most of us can get behind. And at that point, normally I would create an actual web page and post it on the website, the OWASP Threat Model website. Which is actually also completely hosted on the Git versioning system. So later on, if people want to make an addendum or they have an opinion or they want to make a change, they can just create a pull request with the new information. I'll have a look at it. And if I think it's a good thing to have, I'll immediately put it on. If I'm not entirely sure or it's a completely new viewpoint, we'll go back to the Google Doc and everybody again can give his input on the content. So we use that way of working in which I, as the project leader, I'm more of a moderator. I'm not actually driving the content by itself. The content is a consensus that was achieved within our threat model community. And I think that's why it might be a slightly different OWASP project than, for example, the Threat Dragon tool or something like the ZAttack proxy, in which people are just working together creating a great tool. We are working together but more in the sense of creating a consensus on some information. **15:32 Robert Hurlbut:** Okay, good. So go ahead. **15:34 Chris Romeo:** Yeah, I was just going to say, so Stephen, what do you see as the future then of this OWASP Threat Modeling Project? What does 1.0 look like for this project? **15:46 Steven Wierckx:** Yeah, so when we were at the summit and we were lucky enough to have people like Irene and Tony and Adam, but also lots of other people there, We decided that what the world actually needed from a threat model project was, at the first place, a large amount of example threat models. In the best case, we would have an application that we threat model in all the different methodologies, and we would publish those so people could compare If I would threat model, let's say, a CMS system with PASTA, or we do it with TRIKE, what would be the outcome? I'm fairly convinced that the outcome for most of threat model methodologies will be roughly the same. I claim that between 75 and 85% of the threats and mitigations found will be the same. What do we also want to do? We want to create some reference threat models. A good example is a web application. Let's say we would draw a standard web application in the form of having a frontend, a business logic API thing, and a database behind, which is the format that I think most web applications actually fall into. If you were to create some very good threat models on that, then an organization that is new to threat modeling could just take the reference threat model, see how their applications differ from that one, and then you just need to do the threat modeling on the small differences. But the bulk of the content will already be there. And because it's something that the community has worked on, you will have had input from all these, let's say, more or less famous people in the threat model world. So they would be very good threat models that you could use as a reference. That is the first part of the website. The second part of the website is where we create a searchable database not only of methodologies and tools, but also techniques. The STRIDE was already mentioned. STRIDE in itself is not so much a methodology as it is a technique to find threats against an application. You could potentially replace STRIDE with something like ATT&CK trees. So I want to create a database of all these techniques, methodologies, and tools, and you could say in the search box, I'm looking for a technique that answers the questions, which threats exist against my applications? And it would give you a list of all the tools and the techniques that you could use to find that out. I think that's something that is currently lacking, and it's also something that is quite difficult if you want to look online. To find information on. And the third and final part is currently the company I work for has a graduate, a PhD student working on a comparison of threat model tools. So he's going to invent, let's say, a methodology to compare threat model tools Once he finishes his PhD, he has agreed that we could use this methodology in the OWASP project, and I would like to see some effort from the community to keep that up to date. So every time a tool gets a major upgrade, we would update our information and you could have a comparison of all the different threat model tools. So these are the 3 large pillars, let's say, of our documentation project. **20:05 Chris Romeo:** Yeah, sounds like all really useful stuff that will help folks that are, especially those that are new to threat modeling, give them a place to start. I love the idea of the example models and the reference model that will be a place that people can start. So I got another question I'm seeing seeing, you know, you mentioned the OWASP Threat Dragon, and we talked to Mike Goodwin on a previous episode about the tool, and he took us through and talked about all the different things that the tool can do and his vision for the roadmap. What do you see as— what's the connection that you see between the OWASP Threat Model Project and the OWASP Threat Dragon, as well as I see you have the Cloud Security Project listed as another related project. What do you see as the connections and the kind of the— what's the benefit of these things kind of working together? How do you see them connecting? **20:59 Steven Wierckx:** Well, what I would most certainly like to see is the use of some of these tools to do some of the example threat models, because when you first get into threat modeling, I think most of us learn how to thread model just with a pen and a paper, and there is a whole bunch of tools out there. But if you can use an open source tool that's for free, then I think that for a beginner, that's a really nice place to start. I think once we have, for the Thread Model Project at least, more content, then we will probably get together with both, let's say, the project leaders of the related projects, and we're going to sit together and see how we can build more of an integration. One of the topics that is suggested for the upcoming summit, for example, is asking, is it possible to create some type of a descriptive language in which you could write just in an ASCII format a complete threat model. So when you look at the ThreadDragon project, right now everything there is working with JavaScript and it outputs a very nice model. So if we could have that model in some kind of a text basis, then we could use it in other tools that might actually do different parts of the threat model methodology. Or perhaps the people of the Thread Dragon project say like, okay, we are going to implement a stride analysis part within our tool. Either way, I think to keep the things open, we will need to have some kind of a language in which you can actually describe a threat model. So not just, let's say, the analysis of the threats, but also the model part. And several proposals have been done in the Slack channel. Some people were looking at YAML files, other people were already working on using the DOT language to render a model. But the DOT language itself is actually a JSON file. And if you have things in a YAML file or a JSON file, you can parse it with basically any programming language and get some information out of it. And perhaps somebody wants to write a PASTA analysis tool on such a file. Somebody else might want to do it for the, the Microsoft Threat Model methodology. So you'll want to do a STRIDE analysis on it. So we're hoping to find a format to describe threat models in that would actually be open and be usable by multiple tools. **24:15 Robert Hurlbut:** Lots of great stuff going on then. Hey, Steven, so just to finish out a little bit here today, we talked a little bit about the future and so forth, but I'm curious about the OWASP Summit, just going back to that for a moment. Are you Are you working with the team and putting together the agenda for the summit? **24:37 Steven Wierckx:** Yes. So first of all, just to make things clear, it's called the Open Security Summit. **24:45 Robert Hurlbut:** Okay. **24:46 Steven Wierckx:** It's sponsored by OWASP, but it's not organized by OWASP itself. **24:52 Robert Hurlbut:** Okay. **24:54 Steven Wierckx:** It's just a technical detail. And I'm sure if you can get some of the organizers to speak to you. They can explain you how that came to be. I don't have any of the details on that, but there is going to be a summit, and at the summit there is going to be a threat model track. People have been suggesting agenda points, and the way that this open summit works is I can create a whole bunch of working sessions. And the moment the people register for the summit, so let's say they create a user for themselves, you don't even need to buy a ticket, you just need to create a user. You can start sort of voting on each of the working sessions. How do you vote? Well, basically you just say, I want to be in this working session. And if I see that there is enough people in a working session, I will foresee a slot in the agenda and it will be held at that moment in time, hoping that all the people that registered for it actually show up and they will actually do the work. Now, I will be at the summit, but considering that last year the threat model group was by far the biggest group, I'm hoping for the same response this year. And I'm aiming for between 20 and 40 people interested in track modeling. So it might very well be that we have 2 or 3 working sessions going on in parallel. I'm also looking into a way for people to participate remotely, which was sort of possible last year. We tried some things with Google Hangouts, but the quality of those connections were not fantastic, as Robert might attest to. Also, the threat model activities do not lend themselves for using Google Hangouts unless you have one or two extra webcams to actually show the whiteboards and the flip charts where all the models are being drawn on. If I can get some hardware and get all these things working, then the remote participation will be of a much higher quality than it was last year. So that is one of the things I'm currently actively working on, which is also one of the reasons, like, I'm active in the Slack channel, I'm trying to get a good summit going. So the actual work of writing out all the web pages with all the content is a bit lagging behind. I'm fully aware of that. But yeah, so far I have found more pressing issues that we need to tackle. **27:48 Robert Hurlbut:** Okay, so in terms of the summit, in this case, as it was last year, some of these things will hopefully push towards some updates to the OWASP threat modeling project as well. Is that correct? Is that what I understand? **28:05 Steven Wierckx:** Yes, so the way a working session is organized is that there will be an organizer and people participating. And there will be in most of these sessions also a technical writer or somebody will need to take notes. At the end of the session, the technical writer will actually go sit by himself. He will do a write-up of the session and it will already be published on the website of the summit, just like it was for the OWASP Summit that we did last year. Now I've had several proposals of people that say, okay, let's not make the same mistake as we made last year. Why don't we foresee some working sessions to actually write out all the content and put it already on the web page? So by the end of the summit, I'm hoping to have a somewhat populated threat model web page where we actually have all the information already on the web page. So that would be our ultimate deliverable, let's say. The ultimate goal of the summit is by the end of the summit have a web page for the OWASP Threat Model Project with loads of information that is, let's call it, production ready. So there is a consensus on it, there are no spelling mistakes in it, the layout is okay. So it's an actual page that we can leave and let it live its life just like that. **29:39 Chris Romeo:** And, let me just throw out a couple of facts about the summit just in case you're listening and you think you're curious as to how you can participate. Check the shownotes. We'll have a link in there for the website for the Open Security Summit. But, just so you know, the summit itself runs from the 4th through the 8th of June, 2018. And Steven, correct me if I'm wrong, that's in London, I believe. Is that where it's happening? **30:05 Steven Wierckx:** Yeah, so, um, it's, uh, called London, uh, but it's actually, uh, in the Center Parcs, uh, just like last year. Uh, and, uh, it's not really in the center of London. So if you, uh, take the train to London, you're probably still gonna need to take another means of transport to actually arrive there. **30:25 Chris Romeo:** Okay. **30:28 Robert Hurlbut:** Okay, well, another great opportunity to get involved in threat modeling and to certainly push forward some of the work that's being done on the OWASP Threat Modeling Project. Great. Well, thank you, Stephen, for joining us. Do you have any last words you'd like to leave to our listeners about threat modeling or the project? **30:49 Steven Wierckx:** Well, I just wanted to stress that, okay, it's an OWASP threat model, which means it's open source. And the whole idea with open source is, of course, if you have a problem or a question, then you just throw it out to the community. And if it is a question that multiple people have, you just come together, you work on it a bit, and you publish your content. And that is, in fact, what we're trying to achieve, which is, of course, why we invite everyone on the OWASP Slack. workspace and go to the Threat Model channel and just have a look over there. Post some questions. If it is an interesting question or some questions come back, you can be sure that we'll gather some information and post it on the website at some point. **31:41 Robert Hurlbut:** Okay, great. Thank you. Well, again, thank you, Steven, for joining us today. **31:46 Steven Wierckx:** So thanks again for having me and have a nice evening. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.org. Thanks for listening. --- Source: https://appsecpodcast.com/steven-wierckx-the-owasp-threat-modeling-project/