Skip to content

Threat Analysis

Threat analysis is the process of identifying, assessing, and prioritizing potential threats to an organization’s assets and operations.

Threat Modeling

What is Threat Modeling?

A structured approach to identifying and addressing potential security threats during the design phase.

Common Methodologies

STRIDE

Developed by Microsoft, STRIDE categorizes threats: - Spoofing - Pretending to be someone else - Tampering - Modifying data or code - Repudiation - Denying actions performed - Information Disclosure - Exposing information - Denial of Service - Making systems unavailable - Elevation of Privilege - Gaining unauthorized access

DREAD

Risk assessment model: - Damage potential - Reproducibility - Exploitability - Affected users - Discoverability

PASTA

Process for Attack Simulation and Threat Analysis: 1. Define objectives 2. Define technical scope 3. Application decomposition 4. Threat analysis 5. Vulnerability analysis 6. Attack enumeration 7. Risk and impact analysis

Risk Assessment

Risk Calculation

Risk = Likelihood Ă— Impact

Risk Assessment Frameworks

  • NIST Risk Management Framework (RMF)
  • FAIR (Factor Analysis of Information Risk)
  • OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation)

Common Attack Vectors

Network-Based Attacks

  • Man-in-the-Middle (MITM)
  • DNS Spoofing
  • ARP Poisoning
  • DDoS Attacks

Application-Based Attacks

  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Remote Code Execution (RCE)

Social Engineering

  • Phishing
  • Spear Phishing
  • Pretexting
  • Baiting

Vulnerability Management

Vulnerability Lifecycle

  1. Discovery
  2. Reporting
  3. Assessment
  4. Remediation
  5. Verification
  6. Documentation

Tools

  • Vulnerability scanners (Nessus, OpenVAS)
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)