3 ms·
> by which I mean realistic groups with goals and capabilities TBH I think you are missing the point of threat modeling. It's not an exercise in determining th
by thinkharderdev 4y ago
> by which I mean realistic groups with goals and capabilities
TBH I think you are missing the point of threat modeling. It's not an exercise in determining the exact adversary you will face and what capabilities they will have. That is impossible to know with any precision. It's more an exercise in thinking through 1. What your assets are. 2. What attack vectors exist for compromising those assets and 3. What mitigations can be put in place for those attack vectors.
In doing that you may reasonably conclude that for a given attack vector, an adversary sufficiently advanced to pull it off would not be interested in you and that is fine. But you should still start from what you know concretely, which is what your system architecture and assets are.
- generalizations 4y agoYou missed a step there. It's actually closer to: 1. What your assets are. 2. Who is interested in those assets. 3. What attack vectors exist that are feasible/available to the interested parties for compromising those assets 4. What mitigations can be put in place for those attack vectors. Otherwise, as I said elsewhere, there will always be an attack vector, right up to the point where the computers are turned off and in a locked room. The only way to explicitly choose not to take that extreme measure is to figure out who you are, and are not, defending against.
- jdsnape 4y agoInstead of focusing on ‘who’ specifically, step 3 of threat modelling actually focuses on the likelihood of something happening and the impact of it does. From that you can determine whether the cost of applying the mitigation is ‘worth’ applying in terms of reducing the impact of the threat to an acceptable level that the business can accept. Of course, the ‘who’ is part of that consideration of likelihood, but it’s not the only part.
- thinkharderdev 4y agoI'm not sure we actually would disagree on anything concrete but for the sake of argument: > 2. Who is interested in those assets. This is the wrong question to ask. The right question is how important is it to US to keep this asset confidential/available/unmolested. That is a question that is actually tractable and understandable. If you have a service where it is very important that it is always available, then you need to have mitigations in place to prevent DDoS attacks. Whether or not you have some hypothesis as to who exactly might want to attack you is beside the point. If it's important to YOU then you should just assume that there is some threat actor out there who will attack you. On the other hand, if it doesn't matter at all whether said service is consistently available, then it's not worth the time/effort/expense to put in place DDoS mitigations regardless of whether there is any threat actor out there.
- MattPalmer1086 4y agoI think the who question is not so much about determining exactly who might attack you. Its about thinking what types of threat actor you might be exposed to. They all have different motivations and capabilities and resources. This can help you determine if it's worth trying to mitigate certain kinds of attack path, and how likely it is you may be exposed to them. You can do threat modelling without considering threat actors and just focus on attack paths and asset values to prioritise or rule out any mitigations as well. At the end of the day, there is no one true way to do threat modelling. Everyone has a slightly different approach. I'd say do what works for you, but be open to other approaches.
- thinkharderdev 4y ago> At the end of the day, there is no one true way to do threat modelling. Everyone has a slightly different approach. I'd say do what works for you, but be open to other approaches. Absolutely!