MikeShaw's WebLog

Developer Security and other stuff

A Threat Modelling book, tool, demo and links

Threat modelling should be a part of the design of any system, software or otherwise – hey, it’s just part of the design.

 

A post on Friday on the Channel 9 site by Frank Swiderski talks about the Threat Modelling tool he has written and mentions his book that has recently been published, co-authored with Window Snyder.  See his video here.  I can’t comment on the book as my copy is still in the post, but it’s a must for anyone interested in the subject of building secure systems!  The tool is pretty cool and helps with the modelling process, using threat trees, integrating with diagrams from Visio and will also output a few report.

 

For all the appropriate links to stuff about Threat Modelling, go here:

http://msdn.microsoft.com/security/securecode/threatmodeling/default.aspx

 

Mike

PS in the UK we do indeed spell modelling with 2 ‘l’s!

Posted: Jul 13 2004, 05:18 PM by mikeshaw | with 1 comment(s)
Filed under: ,

Comments

Chris said:

I couldn't help but laugh. Sorry :-) Threat Modelling written by a guy named "Window .." Should aptly read "Threat modelling should be a part of the design of any system, software written using Microsoft based technlogies..."
# July 13, 2004 5:40 PM
Leave a Comment

(required) 

(required) 

(optional)

(required)