{"id":10988,"date":"2022-04-21T11:08:33","date_gmt":"2022-04-21T09:08:33","guid":{"rendered":"https:\/\/www.dp-institute.eu\/?p=10988"},"modified":"2024-01-09T16:06:30","modified_gmt":"2024-01-09T15:06:30","slug":"dice-threat-modeling-in-4-steps","status":"publish","type":"post","link":"https:\/\/www.dp-institute.eu\/nl\/dice-threat-modeling-in-4-steps\/","title":{"rendered":"DICE – threat modeling in 4 steps"},"content":{"rendered":"
Is securing systems a game or a gamble? As the attacking factor is uncertain and unpredictable, you might have the feeling that security is more like a gamble. However, you can turn security into a game that – when using the right tactics – can be won. In this article we will present threat modeling as an effective way to turn the table and get a better control on your application risk. We will introduce you to the 4 steps of threat modeling with the DICE acronym. <\/strong><\/p>\n Threat modeling<\/a>\u00a0is performed through a series of multi-stakeholder workshops. Architects, developers and system administrators are guided through the threat modeling process. It is the primary security analysis task executed during the software design stage. Threat modeling is typically performed in 4 stages or steps:<\/p>\n <\/p>\n We named the 4 steps this way to match the acronym DICE<\/strong>. Not only because it is easier to remember the steps. It also introduces the concepts of luck and risk. In a game you throw the dice to advance and possibly win or lose. With threat modeling you get a better understanding of the risks and reduce the amount of luck to prevent or detect an attack on your system.<\/p>\n Step 1: diagram the application<\/strong><\/p>\n In this step, you gain a comprehensive understanding of the mechanics of your application. In other words: you understand what you are building. That makes it a lot easier for you to uncover more relevant and more detailed threats. This also includes the identification of clear security objectives. They help you to focus the threat modeling activity and determine how much effort to spend in the following steps. When you have documented the important characteristics of your application and actors, you can identify relevant threats during the next step more easily.<\/p>\n Step 2: identify threats with STRIDE<\/strong><\/p>\n You use details from the previous step in the STRIDE phase to identify threats relevant to your application scenario and context. With STRIDE, you can flawlessly identify what can go wrong.<\/p>\n STRIDE<\/a>\u00a0was developed by Microsoft to educate developers on how to think about computer security threats, and is an acronym for:<\/p>\n <\/p>\n Each of these threats is the opposite of a property that you want your system to have. Spoofing \u2013 for example \u2013 is the opposite of authentication.<\/p>\n Step 3: Countermeasures: mitigate identified vulnerabilities<\/strong><\/p>\n In this step, you review the layers of your application to identify the necessary security controls related to your threats. Vulnerability categories help you focus on those areas where mistakes are most often made.<\/p>\n Step 4: Evaluate<\/strong><\/p>\n The final step is to evaluate the whole threat model. Is each threat mitigated or not? And for unmitigated threats: are the residual risks clearly explained and tied into business risks? In this validation step, you also decide and follow-up on the next steps to manage the identified threats.<\/p>\n Is securing systems a game or a gamble? As the attacking factor is uncertain and unpredictable, you might have the feeling that security is more like a gamble. However, you can turn security into a game that – when using the right tactics – can be won. In this article we will present threat modeling […]<\/p>\n","protected":false},"author":10,"featured_media":10986,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[615],"tags":[],"class_list":["post-10988","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ciso"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/posts\/10988","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/comments?post=10988"}],"version-history":[{"count":2,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/posts\/10988\/revisions"}],"predecessor-version":[{"id":10990,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/posts\/10988\/revisions\/10990"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/media\/10986"}],"wp:attachment":[{"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/media?parent=10988"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/categories?post=10988"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/nl\/wp-json\/wp\/v2\/tags?post=10988"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}\n
\n
Do you want to take your application security controls to the next level? Do you want to apply DICE to your system? Then book a seat in one of our upcoming Threat modeling Practitioner trainings<\/a>.<\/em><\/strong><\/h6>\n","protected":false},"excerpt":{"rendered":"