Explore risk-centric threat modeling using the PASTA methodology in this 46-minute conference talk from AppSec EU 2017. Gain insights into preemptive design and coding techniques aligned with application use cases and threat contexts. Examine three detailed case studies covering IoT, E-Commerce, and Mobile Applications. Learn how to harvest and correlate threat patterns, define preemptive controls, and incorporate countermeasures into overall design. Delve into topics such as data flow diagramming, threat analytics, and security architecture. Discover the PASTA framework, risk formulas, probabilistic bands, and other artifacts essential for effective threat modeling. Analyze specific scenarios including consumer electronics, cloud pets, and teddy bears, mapping use cases to potential abuse cases. Understand the process of scenario threat analysis, attack tree construction, and residual risk assessment across various industries including healthcare and mobile applications.
Threat Modeling with PASTA - Application Security Case Studies