developed with Next.js and Tailwind CSS
cover for Threat Modeling by Frank Swiderski, Window Snyder
Threat Modeling

by Frank Swiderski, Window Snyder

Paperback in English, 288 pages — category security

Published by Microsoft Press in 2004

I did not finish reading this book.

Description from the publisher:

In this straightforward and practical guide, Microsoft® application security specialists Frank Swiderski and Window Snyder describe the concepts and goals for threat modeling—a structured approach for identifying, evaluating, and mitigating risks to system security. Discover how to use the threat modeling methodology to analyze your system from the adversary’s point of view—creating a set of data points that help drive security specifications and testing. You’ll review application scenarios that illustrate threat modeling concepts in action, understanding how to use threat modeling to help improve the built-in security of a system—as well as your customer's confidence in the security of that system—regardless of development environment.

Gain an in-depth, conceptual understanding—along with practical ways to integrate threat modeling into your development efforts:

Help anticipate attacks by seeing how adversaries assess your system—and compare their view to the developer’s or architect’s view

Employ a data flow approach to create a threat profile for a system

Reveal vulnerabilities in system architecture and implementation using investigative techniques such as threat trees and threat model-directed code reviews

Develop a credible security characterization for modeling threats

Use threat modeling to help verify security features and increase the resilience of software systems

Increase customer confidence in your products!

designed and built from scratch - learn more