Threat Analysis¶
Threat analysis is the process of identifying, assessing, and prioritizing potential threats to an organization’s assets and operations.
Threat Modeling¶
What is Threat Modeling?¶
A structured approach to identifying and addressing potential security threats during the design phase.
Common Methodologies¶
STRIDE¶
Developed by Microsoft, STRIDE categorizes threats: - Spoofing - Pretending to be someone else - Tampering - Modifying data or code - Repudiation - Denying actions performed - Information Disclosure - Exposing information - Denial of Service - Making systems unavailable - Elevation of Privilege - Gaining unauthorized access
DREAD¶
Risk assessment model: - Damage potential - Reproducibility - Exploitability - Affected users - Discoverability
PASTA¶
Process for Attack Simulation and Threat Analysis: 1. Define objectives 2. Define technical scope 3. Application decomposition 4. Threat analysis 5. Vulnerability analysis 6. Attack enumeration 7. Risk and impact analysis
Risk Assessment¶
Risk Calculation¶
Risk = Likelihood Ă— Impact
Risk Assessment Frameworks¶
- NIST Risk Management Framework (RMF)
- FAIR (Factor Analysis of Information Risk)
- OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)
Common Attack Vectors¶
Network-Based Attacks¶
- Man-in-the-Middle (MITM)
- DNS Spoofing
- ARP Poisoning
- DDoS Attacks
Application-Based Attacks¶
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Remote Code Execution (RCE)
Social Engineering¶
- Phishing
- Spear Phishing
- Pretexting
- Baiting
Vulnerability Management¶
Vulnerability Lifecycle¶
- Discovery
- Reporting
- Assessment
- Remediation
- Verification
- Documentation
Tools¶
- Vulnerability scanners (Nessus, OpenVAS)
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)