2 ms·
I'm not sure we actually would disagree on anything concrete but for the sake of argument: > 2. Who is interested in those assets. This is the wrong question
by thinkharderdev 4y ago
I'm not sure we actually would disagree on anything concrete but for the sake of argument:
> 2. Who is interested in those assets.
This is the wrong question to ask. The right question is how important is it to US to keep this asset confidential/available/unmolested. That is a question that is actually tractable and understandable. If you have a service where it is very important that it is always available, then you need to have mitigations in place to prevent DDoS attacks. Whether or not you have some hypothesis as to who exactly might want to attack you is beside the point. If it's important to YOU then you should just assume that there is some threat actor out there who will attack you. On the other hand, if it doesn't matter at all whether said service is consistently available, then it's not worth the time/effort/expense to put in place DDoS mitigations regardless of whether there is any threat actor out there.
- MattPalmer1086 4y agoI think the who question is not so much about determining exactly who might attack you. Its about thinking what types of threat actor you might be exposed to. They all have different motivations and capabilities and resources. This can help you determine if it's worth trying to mitigate certain kinds of attack path, and how likely it is you may be exposed to them. You can do threat modelling without considering threat actors and just focus on attack paths and asset values to prioritise or rule out any mitigations as well. At the end of the day, there is no one true way to do threat modelling. Everyone has a slightly different approach. I'd say do what works for you, but be open to other approaches.
- thinkharderdev 4y ago> At the end of the day, there is no one true way to do threat modelling. Everyone has a slightly different approach. I'd say do what works for you, but be open to other approaches. Absolutely!