Developer-Driven Threat Modeling: Lessons Learned in the Trenches

Danny Dhillon · IEEE Security & Privacy · 2011

This article describes EMC/s real-world experiences with threat modeling, including major challenges encountered, lessons learned, and a description of the company's current developer-driven approach. Threat modeling is a conceptual exercise in which we analyze a system's architecture or design to find security flaws and reduce architectural risk.

Read the paper · More papers on PaperTik