Skip to Content
97 Things Every Application Security Professional Should Know
book

97 Things Every Application Security Professional Should Know

by Reet Kaur, Yabing Wang
June 2024
Intermediate to advanced
310 pages
8h 59m
English
O'Reilly Media, Inc.
Content preview from 97 Things Every Application Security Professional Should Know

Chapter 72. Attack Models in SSDLC

Vinay Venkatesh

For a long time—at least since the start of my product security career—Secure Systems Development Lifecycle (SSDLC) has followed a four-step process:

  1. Define product security requirements at the beginning of the project.

  2. Threat model the product and identify security controls.

  3. Configure scanners to identify vulnerabilities in code as well as in open source packages it uses.

  4. Perform pen testing to confirm that the product is free of vulnerabilities or to identify and address security weaknesses before deployment.

While this process provides a lot of feedback, it is missing one key ingredient—there is no mechanism between threat modeling and code scanning to perform a security analysis of the detailed design. Some have addressed this by expanding the threat model to include component-level details. The usefulness of this approach is limited because threat modeling, by nature, is an architectural exercise where we model independent, interacting processes and data flows between them to identify security gaps. Detailed analysis involves a closer look at how the system should behave in every possible situation and for all possible inputs. I’ve found attack modeling to be a better fit here.

Attack modeling is not a new concept. It was first introduced by Bruce Schneier in his 1999 paper, “Attack Trees.”1 Since then it has been ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

97 Things Every Information Security Professional Should Know

97 Things Every Information Security Professional Should Know

Christina Morillo

Publisher Resources

ISBN: 9781098152161Errata Page