Automating Threat Modeling with Architectural Risk Patterns

A White Paper positioning Security Risk Advisor capability in the context of Threat Modeling

This paper presents a software-centric method that uses architectural risk patterns to greatly speed up the process of generating a threat model that also introduces a degree of consistency that is often lacking in purely manual approaches.

This method for creating patterns employs principals from Object Oriented software design such as inheritance and polymorphism so that the contents of the patterns can be practically maintained and extended without unnecessary repetition. 

Contents:

  1. Introduction
  2. Architectural Risk Patterns
  3. Inheritance and Polymorphism
  4. Pattern Assembly
  5. Limitations

 

 

Managing Security Risk Throughout the SDLC

Identifying Return On Investment against each security control

Send me the White Paper