Upload_transparent

Experiences Threat Modeling at Microsoft

 
 
 
 
 
macro

by macro

Value This
Doc
Scribd
Average
     
Pages: 10 43
Words: 4136 13640
Characters: 26300 81678
Lines: 178 623
     
     
Letters per word: 6.36 5.99
Words per line: 23.24 21.89
Words per page: 413.6 317.21

Add to your reading list

Flag_red Flag this document

Document Information

1,352 Reads | 0 Comments

Description

Describes a decade of experience threat modeling products and services at Microsoft. Describes the current threat modeling methodology used in the Security Development Lifecycle. The methodology is a practical approach, usable by non-experts, centered on data flow diagrams and a threat enumeration technique of `STRIDE per element.' The paper covers some lessons learned which are likely applicable to
other security analysis techniques. The paper closes with some possible questions for academic research.

Pdf_16x16 10 Pages


Date Added

10/13/2008

Category

Uncategorized.

Tags
Groups
Copyright

Attribution Non-commercial

More info »