The Value of Threat Models in Enterprise Security Testing of Database Systems & Services
Timothy D. Williams · 2015
The Value of Threat Models in Enterprise Security Testing of Database Systems & Services by Timothy D. Williams Master of Science in Information Security Royal Holloway, University of London 2013/2014 This thesis explores the value of threat models in organisation-wide security testing of databases. Factors that drive security testing are explored. Different types of security testing, different approaches to threat modeling and different database technologies are considered. The importance of metadata management, particularly for newer schemaless databases, is highlighted. An integrated approach to database security testing is proposed which includes white-box, black-box and grey-box techniques. Sequence dependencies affecting database security testing are identified. The need for explicit architecture tiers in database security testing is explained. An approach to threat modeling and testing based on zones is proposed. Potential benefits of the proposed approach are described. The main conclusion is that further research is needed, both theoretical and applied, into the best ways for organisations to plan, execute and respond to database security tests. It is possible that a similar threat-based approach could be applied to testing other architecture components. A number of other possible research topics are identified including: threat information exchanges, threat model tool development and penetration test data management.