000 02446nam a2200229Ia 4500
003 NULRC
005 20250520100703.0
008 250520s9999 xx 000 0 und d
020 _a9781118809990
040 _cNULRC
050 _aQA 76.9.A25 .S567 2014
100 _aShostack, Adam
_eauthor
245 0 _aThreat modeling :
_bdesigning for security /
_cAdam Shostack
260 _aIndianapolis, Indiana :
_bJohn Wiley & Son, Inc.,
_cc2014
300 _axxxiii, 590 pages :
_billustrations ;
_c24 cm.
365 _bUSD484.04
504 _aIncludes bibliographical references and index.
505 _aPart 1. Getting started -- 1. Dive in and threat model! -- 2. Strategies for threat modeling -- Part 2. Finding threats -- 3. Stride -- 4. Attack trees -- 5. Attack libraries -- 6. Privacy tools -- Part 3. Managing and addressing threats -- 7. Processing and managing threats -- 8. Defensive tactics and technologies -- 9. Trade-offs when addressing threats -- 10.Validating that threats are addressed -- 11.Threat modeling tools -- Part 4. Threat modeling in technologies and tricky areas -- 12. Requirements cookbook -- 13. Web and cloud threats -- 14. Accounts and identity -- 15. Human factors and usability -- 16. Threats to cryptosystems -- Part 5. Taking it to the next level -- 17. Bringing threat modeling to your organization -- 18. Experimental approaches -- 19. Architecting for success.
520 _aAdam Shostack is responsible for security development lifecycle threat modeling at Microsoft and is one of a handful of threat modeling experts in the world. Now, he is sharing his considerable expertise into this unique book. With pages of specific actionable advice, he details how to build better security into the design of systems, software, or services from the outset. You'll explore various threat modeling approaches, find out how to test your designs against threats, and learn effective ways to address threats that have been validated at Microsoft and other top companies. Systems security managers, you'll find tools and a framework for structured thinking about what can go wrong. Software developers, you'll appreciate the jargon-free and accessible introduction to this essential skill. Security professionals, you'll learn to discern changing threats and discover the easiest ways to adopt a structured approach to threat modeling.
650 _aCOMPUTER NETWORKS -- SECURITY MEASURES
942 _2lcc
_cBK
999 _c11450
_d11450