Archives
- ► 2012 (8)
- ► 2011 (157)
- ► 2010 (174)
- ► 2009 (12)
Which topics would you like us to cover more?
Latest comments
- How to reset you Kindle
3, eve...
Thanks for this article and the related "Inside th...
By H K - How to reset you Kindle
3, eve...
How do you drain power on the board? I dont have r...
By Grace - How to reset you Kindle
3, eve...
You're welcome!
By Bas - How to reset you Kindle
3, eve...
Thanks man....removing the battery worked like a c...
By DaveMan - nHapi
example
Hi Slypete, Thank you for your comment. This way w...
By Bas - nHapi
example
Hello, Employing .Net dynamics, one can implement ...
By slypete - Implementing MLLP in C#
Hi Mayura, I'm not sure I understand your question...
By Bas - Implementing MLLP in C#
I have used SSL stream to secure the MLLP transact...
By Mayura
Latest tweets
| Making a threatmodel, part 3: Used technologies |
| Written by Division by Zero |
| Wednesday, 16 February 2011 07:23 |
|
In step one and two of this threat-model howto we looked at the use cases and the attack surface of our application landscape. The third step is to identify the technology used with each component and take a look at vulnerabilities that these technologies have. In this case it is possible to dive as deep as you wish. I won't dive too deep, I just want to give an impression on how to do this. The technology is also relevant in the choice of mitigations that are available to you. 1. Web-shop
2. Order information
3. CRM
Now we know what technology is used. For example: the web-shop is a public web-application using a database. This means we know we need to worry about input validation, especially check on sql-injection. The main business of our fictional company is their web-shop. We must make sure we handle possible vulnerabilities the right way. With the information listed here we know the type of possible problems we can expect. We also know what data is communicated between which components. The next step is to take the STRIDE approach and classify the risks and determine what to do about them. Tags:
|
Only put off until tomorrow what you are willing to die having left undone. - Pablo Picasso




