Trike threat modeling methodology v1 paper release

"Paul B. Saitta" <[email protected]> Wed, 20 Jul 2005 16:35:50 -0700
Newsgroups gmane.comp.security.web-applications,gmane.comp.security.programming
Message-ID <[email protected]>
--LQksG6bCIzRHxTLp
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,

I'm happy to announce the release of a new paper detailing the current state
of a new conceptual framework and methodology for threat modeling, Trike.
Although Trike is a work in progress, this (draft) release is intended to
share the work we're doing with the larger community.

The paper is available at http://dymaxion.org/trike/ or
http://www.hhhh.org/trike/papers.

To subscribe to the announcements list for future work, send mail
with "subscribe trike-announce" in the body to [email protected]

Paul Saitta

----

Abstract:

Trike is a unified conceptual framework for security auditing from a risk
management perspective through the generation of threat models in a reliabl=
e,
repeatable manner.  A security auditing team can use it to completely and
accurately describe the security characteristics of a system from its high-
level architecture to its low-level implementation details.  Trike also
enables communication among security team members and between security teams
and other stakeholders by providing a consistent conceptual framework.  This
document describes the current version of the methodology (currently under
heavy de- velopment) in sufficient detail to allow its use.  In addition to
detail on the threat model itself (including automatic threat generation and
attack graphs), we cover the two models used in its generation, namely the
requirements model and the implementation model, along with notes on risk
analysis and work flows.  The final version of this paper will include a fu=
lly
worked example for the entire process.  Trike is distinguished from other
threat modeling methodologies by the high levels of automation possible wit=
hin
the system, the defensive perspective of the system, and the degree of
formalism present in the methodology.  Portions of this methodology are
currently experimental; as they have not been fully tested against real
systems, care should be exercised when using them.

The methodology described in this document is copyright 2003-2005 Paul Sait=
ta,
Brenda Larcom, and Michael Eddington, excluding those covered under other
copyrights, and the whole may be used under the MIT license
(http://www.opensource.org/licenses/mit-license.  php), "Software" being
replaced with "methodology" throughout.  This document is published under t=
he
Creative Commons attribution-noncommercial-sharealike 2.0 license (http://
creativecommons.org/licenses/by-nc-sa/2.0/legalcode).

--=20
Ideas are my favorite toys.

--LQksG6bCIzRHxTLp
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)

iD8DBQFC3t/WI1DqjdStVGgRAsLFAKCC1sNufeyYY1gsr1Yyc+Vwj6Yd+gCeM0mC
LfY0dzut4Wezp8qJrSA8zDw=
=f2gD
-----END PGP SIGNATURE-----

--LQksG6bCIzRHxTLp--