[00:00.000 --> 00:02.680] Sign up for the fourth track in Zeus. [00:03.880 --> 00:07.000] DVZ sales of all talks in vendor area on the 18th floor. [00:08.580 --> 00:10.980] And there is lots to see and do in the pavilion. [00:12.060 --> 00:16.960] And then I think the egg races and sack hopping is later. [00:17.580 --> 00:18.780] So anyways, hi, I'm Kevin Williams. [00:18.980 --> 00:24.280] And again, I'm here to talk to you about information security and Star Wars and what I call Death Star Threat Modeling. [00:24.960 --> 00:33.680] The objectives here is we're going to talk about the basics, what threat modeling is, identify threats, risks, vulnerabilities, vulnerabilities, how this can be integrated into a software development lifecycle. [00:34.080 --> 00:38.460] And then basically, we're going to use Star Wars to kind of aid in the comprehension of all this. [00:39.320 --> 00:43.780] A little disclaimer, of course, no way endorsed by Lucasfilm or Lucas or any of that junk. [00:43.960 --> 00:48.380] And this will hardly be the worst case of copyright infringement you'll see here this weekend. [00:51.180 --> 00:52.080] A little background. [00:52.420 --> 00:55.020] This is just basically the... I'm not some joker off the street. [00:55.080 --> 00:56.200] I kind of know what I'm talking about. [00:57.000 --> 00:59.380] You know, I hate to admit it, I was a Fed prior to this. [00:59.380 --> 01:01.420] You know, I was in the Air Force 10 years. [01:01.980 --> 01:03.740] Three years that I did information warfare. [01:04.180 --> 01:07.640] Currently, I'm a consultant getting paid for being a know-it-all. [01:08.400 --> 01:14.320] My background is in software engineering and currently I'm a grad student in information security at Our Lady of the Lake University. [01:15.020 --> 01:15.820] Plug for them. [01:16.000 --> 01:20.040] They're one of the 80 NSA certified centers of academic excellence in information assurance. [01:22.920 --> 01:24.600] So this is one of my favorite quotes here. [01:24.720 --> 01:26.200] This is from Sun Tzu's The Art of War. [01:26.200 --> 01:29.580] If you know the enemy and you know yourself, you need not fear the result of 100 battles. [01:29.780 --> 01:33.680] If you know yourself but not the enemy, for every victory gained, you'll suffer defeat. [01:33.920 --> 01:36.760] And then if you know neither the enemy nor yourself, you'll succumb in every battle. [01:37.160 --> 01:39.480] Or in layman's terms, know thyself, know thy enemy. [01:39.960 --> 01:43.600] So he wrote this 2,500 years ago, but it's as true then as it is today. [01:43.820 --> 01:47.520] And this is kind of the essence of information security and why we have to do threat modeling. [01:49.800 --> 01:50.920] So what is threat modeling? [01:51.280 --> 01:55.120] It's basically we're anticipating possible attacks and figuring out ways to fix this. [01:55.720 --> 02:02.640] So, you know, I think we've all had that look there that Vader's got that, you know, what do you mean your car got towed at 2 in the morning when you're at the strip club kind of look. [02:05.220 --> 02:06.880] Last month, that's another story I'll tell you later. [02:08.140 --> 02:13.920] So, you know, the primary goal here is to figure out, you know, how we can be attacked and then, you know, how we can go over prioritizing to fix those. [02:16.060 --> 02:19.740] So I use the term death star threat modeling because it's really easy for people to grasp. [02:20.180 --> 02:21.620] It's a common memory. [02:21.720 --> 02:22.500] Everybody shares it. [02:22.580 --> 02:26.300] We all know as soon as we say that term what we're talking about. [02:26.540 --> 02:32.540] And I've used this for years with, you know, my troops in the military and then my, you know, my coworkers now to explain what these things are. [02:32.600 --> 02:37.980] You know, because people throw around the terms threat and risk all the time that, oh, you know, driving down the highway is risky. [02:38.060 --> 02:40.820] Well, I mean, that doesn't mean the same thing as it does in information security. [02:40.820 --> 02:43.000] They have very specific words. [02:43.420 --> 02:44.980] So it's really good to get everybody on the same page. [02:45.120 --> 02:51.260] So if you're in a room with somebody and they say, you know, so when you say threat, do you mean what I mean when I say threat? [02:52.040 --> 02:53.980] And, you know, this right here, I'm sure we all remember this game. [02:54.080 --> 02:55.960] This is kind of the essence of what we're talking about, you know. [02:56.280 --> 02:59.480] What's the chance of the X-wing getting that proton torpedo to go down that little hole? [03:03.080 --> 03:05.760] So this is basics of death star threat modeling. [03:06.060 --> 03:07.220] So first off, you have your asset. [03:07.360 --> 03:08.820] That's a valuable resource, right? [03:08.820 --> 03:13.820] This would be your application, your website, the program you're coding, what have you. [03:15.300 --> 03:17.600] And that has a vulnerability, which is an exploitable weakness. [03:17.760 --> 03:20.940] In this case, it's the exhaust port that somebody didn't put a screen over. [03:23.780 --> 03:24.800] And then there's a threat. [03:25.000 --> 03:27.720] That's the thing that's going to come in and it's going to try to do harm. [03:28.020 --> 03:30.020] It's going to try to exploit that vulnerability. [03:30.960 --> 03:33.600] So then the risk is the chance of that occurring. [03:33.600 --> 03:37.740] So what's the chance of a proton torpedo is going to hit the wall versus it's actually going to go down in the hole? [03:38.280 --> 03:40.020] And then lastly, a countermeasure. [03:40.160 --> 03:42.700] That's something that you put in place to reduce the risk. [03:44.340 --> 03:47.120] And this, you know, in a sense is threat modeling. [03:47.360 --> 03:51.180] But in this context, you know, we use a little Star Wars clip art to help you guys remember. [03:52.180 --> 03:53.220] So let's break these down. [03:54.020 --> 03:54.780] Your asset. [03:54.780 --> 03:56.260] This is anything with value. [03:56.420 --> 03:59.220] Now that value can be perceived or it can be literal value. [03:59.520 --> 04:06.840] So there's things that you may consider, you know, a commodity or resource like, you know, disk space or your IP addresses or something like that. [04:07.100 --> 04:13.060] You know, to an attacker, these can, you know, these have value to them because they can leverage them to do other nasty things. [04:13.500 --> 04:15.860] You know, and basically, if it's worth having, it's worth protecting. [04:16.020 --> 04:17.320] And that goes for everything. [04:20.060 --> 04:20.460] Vulnerabilities. [04:20.560 --> 04:21.800] This is an exploitable weakness. [04:21.800 --> 04:24.920] It's something that's not supposed to be there and it can hurt you. [04:25.240 --> 04:26.620] That's the bottom line. [04:27.020 --> 04:30.880] So this can come in the form of unintended functionality, bugs, glitches, errors. [04:31.020 --> 04:35.020] These are things that happen that you didn't expect to happen or intend to happen. [04:35.360 --> 04:40.460] Versus intended functionality, which is design flaws, you know, assumptions in the code. [04:41.040 --> 04:45.980] Oh, it never occurred to me that they could use that portion of my application to hurt me or somebody else. [04:46.560 --> 04:50.600] These are still vulnerabilities, whether or not, you know, it's a glitch or an error. [04:52.080 --> 04:52.500] Threats. [04:52.700 --> 04:54.540] This is what is causing you harm. [04:54.740 --> 04:55.780] It can be a person. [04:55.940 --> 04:56.720] It can be man-made. [04:56.940 --> 04:57.960] It can be a natural. [04:58.060 --> 04:59.420] A natural disaster is a threat. [05:00.000 --> 05:11.700] You know, maybe not something that we always think about when we look at information systems, but, you know, HVAC, fire suppression, ups, those kind of things are countermeasures to natural disasters. [05:12.620 --> 05:14.900] And it really doesn't matter what the intent of that threat is. [05:15.200 --> 05:16.760] You know, it could be the insider threat. [05:16.880 --> 05:18.940] Somebody's intentionally trying to hurt you, doing it manually. [05:19.200 --> 05:21.920] It could be automated, somebody just doing ping sweeps, what have you. [05:22.120 --> 05:24.320] So it doesn't matter if it's chosen and discriminated. [05:24.420 --> 05:25.240] It's all a threat. [05:26.760 --> 05:27.640] And then the risk. [05:27.840 --> 05:30.520] Again, that's the likelihood that the threat's gonna cause harm. [05:31.220 --> 05:37.060] So the little pseudocode here that, you know, the threat probability plus the severity of the vulnerability equals your amount of risk. [05:37.060 --> 05:43.280] So the more likely something is to happen, and the worse it will be if that thing happens, the more risk you have. [05:44.020 --> 05:47.200] And you just remember, you will always have a risk in any system. [05:48.020 --> 05:50.980] If you didn't have a risk, then you basically wouldn't have a system. [05:51.300 --> 05:57.940] So you're not gonna have anything that has no user interaction, that isn't online, that isn't storing something that's of some value. [05:58.220 --> 06:01.060] And if you did, you know, it'd be a self-contained running thing. [06:03.600 --> 06:04.500] So a countermeasure. [06:04.500 --> 06:07.620] These are the controls that reduce risk to an acceptable level. [06:07.720 --> 06:08.780] That's the key word, is acceptable. [06:09.040 --> 06:10.320] You're never gonna get rid of risk. [06:10.440 --> 06:11.420] You're always gonna have risk. [06:11.500 --> 06:14.320] And there's always gonna be things that you're not going to know that are gonna hurt you. [06:15.120 --> 06:19.120] But the basic idea here is to balance it against both the risk and the asset. [06:19.700 --> 06:20.960] So again, a little pseudocode here. [06:21.280 --> 06:26.900] The cost of the control, you know, that is whatever it is we're implementing, has to be less than or equal to the asset. [06:27.000 --> 06:27.940] Otherwise, it's not worth it. [06:28.100 --> 06:31.400] You know, we're not gonna spend, you know, a million dollars to protect something worth a hundred. [06:31.900 --> 06:39.040] And then the protection that we're implementing has to be, you know, stronger or at least equal to the risk that's happening. [06:39.500 --> 06:40.760] You know, otherwise it's not worth it. [06:40.860 --> 06:41.340] And so... [06:43.200 --> 06:44.840] So how do we use threat modeling? [06:45.040 --> 06:45.260] Okay? [06:45.360 --> 06:48.080] This is just the basic, you know, five-step process. [06:48.240 --> 06:49.960] The first thing is identifying critical resources. [06:50.160 --> 06:52.520] You gotta know what you have if you're gonna protect it. [06:52.920 --> 06:56.500] So then you gotta figure out, you know, how it can be harmed, stolen, broken, what have you. [06:56.500 --> 06:58.600] And so these, again, are your assets and your vulnerabilities. [06:59.440 --> 07:04.380] Now critical resources is completely, you know, subjective. [07:04.660 --> 07:07.600] So what's critical to one person in one system is not critical to another. [07:08.100 --> 07:11.340] You know, you start thinking about it, you know, you got a web application. [07:11.340 --> 07:13.640] So you got the, you know, the web layer. [07:13.740 --> 07:16.560] You got your routers and your servers and the database layer and then the backup. [07:16.780 --> 07:20.500] And, you know, so then you have to make some sort of determination which of those is the most critical. [07:20.500 --> 07:24.640] You know, if something's gotta go down, which one can I accept? [07:25.400 --> 07:28.240] And then two, it's just the best guess is what's gonna cause harm. [07:28.400 --> 07:33.740] So you just gotta look at these critical resources and say, okay, what are the possible threats to my web server? [07:33.900 --> 07:35.640] You know, I could be hit by a flood. [07:35.860 --> 07:38.060] I could be denial of service, et cetera, et cetera. [07:38.140 --> 07:39.780] And these are what your threats and risks are. [07:42.060 --> 07:45.660] Next, you wanna determine every possible way of preventing or reducing the damage. [07:45.800 --> 07:47.120] And then compare the cost and implementation. [07:47.240 --> 07:48.240] What we talked about, countermeasures. [07:48.580 --> 07:49.680] And again, just brainstorm. [07:49.940 --> 07:54.740] So you sit there and think, okay, so I'm worried that somebody's gonna denial of service my web application. [07:54.920 --> 07:56.280] So what are the things I can do against that? [07:56.560 --> 07:57.940] Well, you know, I could do load balancing. [07:57.940 --> 07:59.920] I could do some sort of this or that. [08:00.100 --> 08:01.520] Or, you know, I could just take the thing offline. [08:01.940 --> 08:03.160] That'd be a way of stopping it, right? [08:03.840 --> 08:04.160] So... [08:04.700 --> 08:08.760] But then, step four, we wanna implement the best control and evaluate it, right? [08:08.880 --> 08:12.860] So my e-commerce site is taking it offline, the best solution to that problem. [08:13.580 --> 08:14.420] So maybe not. [08:14.580 --> 08:17.720] So then we wanna document those results and lessons learned, you know. [08:17.720 --> 08:22.280] So, you know, dear IT staff, I found out that taking the web server offline is not the best idea. [08:22.760 --> 08:23.160] So... [08:23.160 --> 08:26.300] And the most important part of step five is continued process improvement. [08:26.480 --> 08:29.440] Is to take what you learned and go back and do it all over again. [08:33.560 --> 08:36.800] So now, let's go through and identify all the parts that we just talked about. [08:39.000 --> 08:40.720] So asset management is key here. [08:41.280 --> 08:42.780] You know, you gotta know what you have again. [08:42.960 --> 08:44.140] Where it's located at. [08:44.240 --> 08:45.720] You know, who's responsible for it. [08:46.240 --> 08:47.320] How do we get another one? [08:47.460 --> 08:50.020] You know, if the server goes offline, can we get a second one somewhere? [08:50.600 --> 08:52.580] And don't lure yourself into a false sense of security. [08:52.660 --> 08:55.000] That idea, well, you know, that happens to other people. [08:55.180 --> 08:56.720] You know, nobody would wanna attack my system. [08:56.720 --> 09:02.300] You know, we'd argue that if you have a system, it's online, it accepts user input, it's gonna be attacked. [09:04.740 --> 09:05.100] Vulnerabilities. [09:05.420 --> 09:11.220] Now, this is the hard thing to find, is because if you knew there was a vulnerability there, you wouldn't have to look for it. [09:11.340 --> 09:12.740] You know, you would probably fix it. [09:12.880 --> 09:16.660] So, the hard part here is we're trying to find something that may or may not exist. [09:17.520 --> 09:19.920] So, we want to both look at it internally and externally. [09:20.040 --> 09:21.460] Doing things like penetration testing. [09:22.060 --> 09:23.360] You know, white box, black box scanning. [09:23.500 --> 09:26.180] Looking at it from the security from the outside looking in or the inside looking out. [09:26.620 --> 09:27.540] Source code analysis. [09:27.760 --> 09:30.780] Looking at it in both a static and a dynamic state. [09:30.940 --> 09:34.080] You know, executing the code or also looking at the code itself for flaws. [09:35.060 --> 09:36.440] And again, you know, back to Sun Tzu. [09:36.540 --> 09:38.460] You have to know yourself and the enemy. [09:38.580 --> 09:41.200] So, you gotta know what you have going on in your own system. [09:42.420 --> 09:43.480] So, identifying the threats. [09:43.480 --> 09:46.000] You're never gonna know all the threats that are out there. [09:47.100 --> 09:50.120] You know, I mean, the best thing you do is make a best guess. [09:50.300 --> 09:51.140] You know, an educated guess. [09:51.580 --> 09:52.720] You know, stay current. [09:53.120 --> 09:54.960] You know, with current events. [09:55.080 --> 09:57.060] Read the blogs, forum posts, what have you. [09:57.220 --> 09:58.420] And the best thing is be proactive. [09:58.540 --> 09:59.600] Don't wait till you're attacked. [09:59.780 --> 10:03.000] Don't wait till somebody, you know, hits you before you do something. [10:04.460 --> 10:08.240] And then, identify areas where the CIA triad is affected. [10:08.460 --> 10:12.980] And this is kind of like a basic information security 101 kind of concept. [10:12.980 --> 10:16.460] The CIA stands for confidentiality, availability, and integrity. [10:16.740 --> 10:21.640] So, when you're looking at your system, think, okay, where in my system is confidentiality important? [10:21.840 --> 10:24.360] Am I storing something that other people wouldn't wanna see? [10:24.660 --> 10:27.540] Passwords, credit cards, phone numbers, social security, what have you. [10:27.860 --> 10:30.660] You know, how can that confidentiality be compromised? [10:31.240 --> 10:32.000] The integrity. [10:32.000 --> 10:40.820] Are people relying on my system and the data it serves to be what it's supposed to be? [10:41.160 --> 10:45.540] Is there some sort of assumption or reliability involved in it, you know? [10:45.760 --> 10:51.660] So, if I'm ordering a product on eBay, you know, I wanna make sure that that is the actual product and, you know, it's not something false. [10:52.080 --> 10:54.820] And then availability, you know, this is a denial of service. [10:54.820 --> 11:01.000] We wanna make sure that these assets are there when our, you know, our customers, our clients, you know, want them to be there. [11:01.520 --> 11:03.760] So, this kind of makes up the CIA triad. [11:03.940 --> 11:08.420] So, when you talk about information security concepts, like take cryptography, for instance. [11:09.160 --> 11:13.140] Cryptography always enhances confidentiality because you're making it, you know, more private. [11:13.520 --> 11:16.600] It enhances the integrity in the sense that it's been encrypted. [11:16.600 --> 11:22.460] So, you know, using like PKI and digital signature stuff, you can assume that it hadn't been, you know, contaminated in route. [11:23.480 --> 11:25.660] But cryptography will only ever hamper availability. [11:26.400 --> 11:28.980] You can't encrypt something and make it more easy to access. [11:29.880 --> 11:34.060] So, these are just kind of like, you know, ideas, concepts you wanna keep in mind when you look at these things. [11:35.780 --> 11:37.440] So, taint propagation analysis. [11:37.880 --> 11:40.760] I'll give you a second to handle the name there. [11:41.120 --> 11:43.240] There's always, you know, giggles whenever you say that. [11:45.960 --> 11:48.380] So, you wanna assume that all user input is tainted. [11:49.380 --> 11:56.460] So, the easiest way to find vulnerabilities in your system is look at it and figure out where stuff's coming in and where stuff's going out. [11:56.580 --> 11:57.440] And those are your vulnerabilities. [11:58.240 --> 12:01.940] If you didn't accept user input, it would run exactly as it's supposed to run. [12:02.060 --> 12:02.740] There'd be no problem. [12:03.500 --> 12:06.280] This is an example here from this company called Fortify. [12:06.420 --> 12:08.120] They're a source code analysis software. [12:08.900 --> 12:11.200] And here's an example of what we call taint analysis. [12:11.200 --> 12:15.400] So, you know, up here at the top, we're taking in a user argument. [12:15.580 --> 12:17.600] It's being stored here as args. [12:17.820 --> 12:20.320] Then those arguments are being passed into username string. [12:20.600 --> 12:24.620] And then that's being concatenated with this SQL-like statement for this query string. [12:24.780 --> 12:26.060] And then that's being executed. [12:26.360 --> 12:26.580] Right? [12:26.700 --> 12:27.800] That seems perfectly fine, right? [12:28.080 --> 12:29.120] So, I put in Bob. [12:29.360 --> 12:31.520] Bob gets, you know, eventually transferred down here to query. [12:31.680 --> 12:34.200] And then it executes and looks for username and password equal to Bob. [12:34.320 --> 12:34.400] Right? [12:34.560 --> 12:35.000] No problem. [12:35.540 --> 12:38.660] But what if they put Bob semicolon and then something bad afterwards? [12:38.980 --> 12:41.020] You know, that's the essence of a command-injection attack. [12:41.900 --> 12:44.880] So, again, this is a very basic, you know, kind of academic example. [12:45.020 --> 12:46.320] But this is the kind of stuff you want to do. [12:46.400 --> 12:52.160] You want to look, you know, where the stuff's going in, where it's bouncing around internally, and what happens to it once it's in there. [12:52.960 --> 12:53.760] A good example. [12:53.880 --> 12:58.860] I was working with one of our developers, and they had this disk-based backup system. [12:58.860 --> 13:06.560] And the idea is you would log in this application, give it credentials, it would go mount a drive somewhere using those credentials, back up whatever needed to, and get rid of the mount. [13:07.100 --> 13:07.920] Well, that's great. [13:08.020 --> 13:11.200] So, I started asking them, you know, okay, so where is the credential stored? [13:11.660 --> 13:12.660] Okay, well, they're in the database. [13:12.820 --> 13:13.480] Are they secure? [13:13.580 --> 13:14.060] Yeah, they're encrypted. [13:14.400 --> 13:16.480] So, we started talking about, you know, where the stuff is and whatnot. [13:16.700 --> 13:24.140] And then we eventually realized that, well, the logging is set by verbose, for example, by default, the logging is verbose. [13:24.180 --> 13:27.040] And the application is actually doing command-line connections. [13:27.580 --> 13:29.900] So, those credentials are in the log files. [13:30.620 --> 13:32.140] So, that's probably not a good thing. [13:32.420 --> 13:39.040] You know, so that's the idea of, you know, you want to look where the stuff that's going into your application, where it ends up, and how it's handled. [13:40.920 --> 13:45.140] And this brings us to the second Death Star, and where we talk about dependencies. [13:45.540 --> 13:53.680] So, not only do we have to worry about, you know, the user inputs we're taking, but we got to worry about any third parties that are associated, you know, with our application. [13:55.000 --> 13:57.280] So, the Empire tried to learn a lesson from the first one. [13:57.480 --> 14:00.520] So, when they had the second Death Star, Rebels came to blow it up. [14:00.700 --> 14:01.600] This time, they were prepared. [14:02.120 --> 14:06.760] They had, you know, a third-party dependency here with the shield generator down on Endor, right? [14:07.820 --> 14:10.740] And this, you know, was their countermeasure, right? [14:11.260 --> 14:16.600] And the idea here was that this reduced the risk, you know, from the Millennium Falcon coming in, right? [14:16.600 --> 14:22.060] But the problem here is that the dependency is now a link, is now a link in your chain. [14:22.220 --> 14:24.280] You know, the old cliche that you're only strong is the weakest link. [14:24.480 --> 14:27.800] Well, that was the case here, because your dependency is a system. [14:28.240 --> 14:29.780] And that system has countermeasures. [14:30.440 --> 14:34.260] And if the Sister Emma has countermeasures, that's because there's threats to that system. [14:41.910 --> 14:46.770] So, essentially what happens is, by having a dependency, you inherit their threats. [14:47.690 --> 14:50.330] So, what happens when your dependency's countermeasure fails? [14:51.450 --> 14:54.070] Then those threats can exploit that dependency. [14:54.670 --> 14:55.850] Dependency goes offline. [14:56.790 --> 14:58.610] And now your risk is high. [14:59.190 --> 15:05.490] You know, and this is all because, you know, you're assuming that this dependency is going to be secure. [15:05.730 --> 15:07.430] And that's a bad assumption, you know? [15:07.510 --> 15:09.830] If it's beyond your control, don't trust it. [15:09.910 --> 15:12.750] Just like user input, you shouldn't trust a dependency. [15:15.650 --> 15:17.030] So, how do we identify these risks? [15:17.230 --> 15:20.950] And this is a common, you know, four-square, you know, matrix thing. [15:21.070 --> 15:22.210] I'm sure you've seen these hundreds of times. [15:22.430 --> 15:23.630] But it's a helpful tool. [15:23.770 --> 15:26.550] You know, so you look at, you've got probability on one axis, severity on another. [15:26.750 --> 15:30.490] And you just start throwing vulnerabilities and, you know, risks and threats against it. [15:30.550 --> 15:31.690] And see where they land, you know? [15:32.090 --> 15:35.210] So, your category one, we've got low probability, low severity. [15:35.390 --> 15:36.330] Like information disclosure. [15:36.650 --> 15:38.750] Oh, I go to the website, I malformed the address. [15:39.030 --> 15:41.570] You know, it gives me a verbose error message back from the server. [15:41.890 --> 15:44.530] Not a good thing, but, you know, it's not the end of the world. [15:45.230 --> 15:47.350] Category two, we've got low probability, high severity. [15:47.610 --> 15:49.490] You know, this is, again, the natural disaster. [15:49.890 --> 15:50.810] It could happen. [15:50.810 --> 15:52.150] Am I going to waste a lot of time on it? [15:52.210 --> 15:52.630] Maybe not. [15:52.810 --> 15:54.050] You know, I'm going to get an HVAC system. [15:54.050 --> 15:54.930] I'm going to have insurance. [15:54.930 --> 15:57.710] I'm going to have, you know, fire suppression and whatnot. [15:58.290 --> 16:02.110] But, you know, in the grand scheme of things, it's going to come secondary to most other stuff. [16:02.730 --> 16:04.950] Category three, high probability, low severity. [16:04.950 --> 16:08.790] So this is going to be like spam, you know, ping sweeps, port scans, that kind of stuff. [16:08.950 --> 16:09.650] It happens. [16:10.210 --> 16:11.370] Is it a big deal by itself? [16:11.490 --> 16:12.030] Not really. [16:12.290 --> 16:14.870] It's something we've got to look at, but we're not going to waste too much time on. [16:15.090 --> 16:17.690] And then category four, high probability, high severity. [16:18.230 --> 16:19.850] This is like a major design fault. [16:19.970 --> 16:20.870] This is a problem. [16:21.550 --> 16:27.230] You know, so if you have something like that, that's when you've got to stop things, you've got to say, let's reevaluate this kind of stuff. [16:29.890 --> 16:31.570] So that rolls into stride and dread. [16:31.810 --> 16:33.970] These are our two techniques. [16:34.230 --> 16:40.210] You know, they're definitely not the end-all, be-all, but they're tools that you can use to categorize risks and threats. [16:40.410 --> 16:50.430] And this is the kind of stuff that we see when we do, like, consulting reports, is, you know, telling them that this is secure is really a qualitative measure. [16:50.530 --> 16:51.550] It's a measure of quality. [16:51.550 --> 16:52.650] It's good or it's bad. [16:52.650 --> 16:56.050] It's not very quantitative because we can't say, well, it's 80% secure. [16:56.490 --> 17:00.770] So this is a way of kind of giving people who are more comfortable with numbers, numbers. [17:02.010 --> 17:09.570] So if we look at a particular, you know, threat or risk, so for dread, for instance, you know, we say, oh, well, you sign arbitrary numbers. [17:09.630 --> 17:10.030] It doesn't matter. [17:10.130 --> 17:11.610] It could be one through three, one through five, one through ten. [17:11.650 --> 17:12.070] It doesn't matter. [17:12.210 --> 17:13.550] So you sign at some sort of level. [17:13.670 --> 17:18.310] You see, for this particular attack, you know, it has a, you know, on a level on a one, two, three scale. [17:18.310 --> 17:21.850] It has a three percent chance of, you know, damage. [17:22.550 --> 17:23.550] The reproducibility is a two. [17:23.710 --> 17:24.310] You can do it sometimes. [17:24.410 --> 17:25.010] You can't do it all times. [17:25.070 --> 17:26.330] But the discoverability is real low. [17:26.450 --> 17:28.410] You know, it's really hard for them to find that we have this error. [17:28.770 --> 17:33.230] You know, compared with, like, you know, something that may be really easy to discover, but it has a low amount of damage. [17:33.430 --> 17:41.650] Then you average all together, so you have some sort of quantifiable number that you can compare to another one and say, okay, you should probably look at this one first before you move on to this one. [17:41.650 --> 17:45.630] And then stride is just a way of categorizing different attacks. [17:45.870 --> 17:47.410] You know, is it a spoofing attack? [17:47.590 --> 17:48.190] Is it tampering? [17:48.550 --> 17:50.990] You know, some things are going to be, you know, multiple ones. [17:51.970 --> 17:54.250] And again, you just sign arbitrary numbers, average it. [17:54.410 --> 17:58.810] It gives you something to work from, you know, for proprietors and categorizing stuff. [18:01.570 --> 18:02.350] Risk management. [18:03.390 --> 18:04.990] So, we have this risk. [18:05.110 --> 18:07.870] It's never going to go away, so we got to deal with it, okay? [18:07.870 --> 18:12.850] The Mon Calamari cruiser here has got to deal with the fact that he's going to get blown out of the sky, okay? [18:13.110 --> 18:15.110] So, what is he going to do with that, you know? [18:15.330 --> 18:18.850] So, you can accept it, you can transfer it, or you can mitigate it, right? [18:19.010 --> 18:19.990] So, we can accept the risk. [18:20.130 --> 18:20.990] This is basically gambling. [18:21.210 --> 18:22.770] This is saying, you know, I know there's a risk. [18:22.810 --> 18:23.590] I know it's bad. [18:23.590 --> 18:24.430] I know it could happen. [18:24.770 --> 18:26.270] But, you know, I can live with the odds. [18:27.130 --> 18:34.830] Some people call this risk denial in saying that, okay, I know there's a risk, but I don't believe it's as bad as you think it is. [18:35.270 --> 18:37.410] I kind of think that's a bad way of looking at it. [18:38.890 --> 18:40.770] So, then you can transfer the risk. [18:40.970 --> 18:46.650] Now, this can be like a literal transfer in, you know, I want to set up my e-commerce site. [18:46.770 --> 18:47.390] I'm a coder. [18:47.450 --> 18:50.050] I don't know anything about web servers, so I'm going to have it outsourced. [18:50.090 --> 18:55.090] I'm going to have a hosting company deal with the problems of the routers and the firewalls and all that stuff. [18:55.410 --> 18:57.090] Or this could be like insurance. [18:57.430 --> 18:58.510] You know, I know there's a risk. [18:58.570 --> 19:01.890] I know something bad could happen, so I'm going to take out insurance in case it does. [19:02.230 --> 19:07.170] So, that way, you know, I can mitigate how much damage it's going to cause because they're going to pay for it. [19:07.810 --> 19:09.150] And then the third way, mitigation. [19:09.350 --> 19:10.750] This is probably the best idea. [19:11.050 --> 19:14.790] You know, try the best you can to reduce the threat again to an acceptable level. [19:18.520 --> 19:20.040] And this rolls us into countermeasures. [19:20.200 --> 19:23.160] So, countermeasures are going to be what you use to mitigate that risk, right? [19:23.260 --> 19:24.120] They have to be cost effective. [19:24.120 --> 19:28.360] Again, we're not going to spend more money, you know, outrageous amount of money to fix something. [19:28.460 --> 19:32.500] You know, we're not going to have a 24-hour armed guard to protect the snack bar, right? [19:32.500 --> 19:34.120] So, the right tool for the job. [19:34.680 --> 19:35.360] You know, we're... [19:35.920 --> 19:38.060] You know, again, this goes with the panacea. [19:38.140 --> 19:39.620] There's no one fix to everything. [19:40.060 --> 19:41.720] You often hear people say, well, I've got a firewall, right? [19:41.900 --> 19:43.040] That's going to protect me, right? [19:43.520 --> 19:44.720] Well, you know, from some things. [19:44.740 --> 19:46.980] It's not going to protect you from, you know, a SQL injection attack. [19:47.180 --> 19:49.020] You know, because you're asking people to come to your website. [19:49.420 --> 19:52.560] So, you've got to make sure that your countermeasure, you know, is... [19:52.560 --> 19:54.880] actually works with what you're trying to prevent. [19:55.220 --> 19:56.400] And then proportionality. [19:56.620 --> 19:58.520] You know, there's no need an overkill here. [19:58.520 --> 20:03.040] Again, you know, oh, we got a spam message, so I'm going to take my e-commerce site offline. [20:03.320 --> 20:04.980] You know, that's overkill in a sense. [20:09.080 --> 20:11.400] So, how do we integrate this into a software development lifecycle? [20:13.460 --> 20:17.820] So, typically in software development, you see security kind of just tacked on at the end. [20:18.140 --> 20:19.140] You know, the guys build it. [20:19.300 --> 20:20.740] It gets to some testing stage. [20:20.740 --> 20:23.080] And then there's some sort of security testing that goes involved. [20:23.340 --> 20:27.540] Or, you know, oh, hey, let's invite that guy from the security group over to sit in on our Q&A session. [20:28.240 --> 20:32.680] All right, but the idea here is we really want to integrate this thing in the lifecycle from start to finish. [20:33.960 --> 20:36.240] You know, so the initial requirements gathering. [20:36.420 --> 20:38.700] You know, does this thing have to be over HTTPS? [20:39.020 --> 20:41.560] You know, are you storing something sensitive? [20:41.740 --> 20:42.800] How sensitive is it? [20:43.140 --> 20:47.140] Do you have any sort of regulatory compliance, HIPAA SOCs, that kind of stuff? [20:47.400 --> 20:50.580] Then when you go to code it, you know, you want to do, like, the source code analysis, like we said. [20:50.700 --> 20:51.320] You know, desk checks. [20:51.340 --> 20:53.020] Have other people look through it, step through it. [20:53.540 --> 20:55.700] Again, with testing, you're always going to do security there. [20:55.700 --> 20:59.300] And then, you know, finally, with, you know, implementation and deployment of the system. [21:01.800 --> 21:06.520] So here's an example of a security in a software development lifecycle. [21:06.860 --> 21:11.300] Yes, I know it's Microsoft, but, you know, this is actually a pretty good thing that they implemented. [21:11.620 --> 21:19.840] You know, they kind of realized that, you know, their operating systems and stuff weren't the cream of the crop. [21:19.840 --> 21:21.960] You know, there were prettier dogs at the show. [21:22.320 --> 21:27.660] So the, the, this, this guy, Michael Howard, the third link here, I highly recommend this. [21:28.040 --> 21:30.000] He literally wrote the book on secure coding. [21:30.120 --> 21:30.880] It's called Secure Coding. [21:31.260 --> 21:34.940] And this guy, it really is. [21:35.780 --> 21:39.840] Imagine if Simon Cowell from American Idol was a corporate security guy. [21:40.100 --> 21:41.160] That's, that's Michael Howard. [21:42.000 --> 21:47.320] So he basically sat down and said, okay, we need to do something during the development thing. [21:47.400 --> 21:49.940] Because this is ridiculous having to patch all this stuff afterwards. [21:51.240 --> 21:54.220] So this is kind of the secure development lifecycle that they came up with. [21:54.740 --> 21:58.900] So every time they develop a new thing at Microsoft, they run through this process. [21:59.140 --> 22:00.700] So you can see the first step is training. [22:01.280 --> 22:03.600] So these are coders that have been there for who knows how long. [22:03.780 --> 22:07.000] But every time they start a new process, they're required to go to security training. [22:07.920 --> 22:12.140] But that's a good thing, you know, because you're never going to be, you're never going to be aware of everything. [22:12.320 --> 22:15.340] And you've got to stay current with the thing, with all the new security developments. [22:16.140 --> 22:20.240] You can see that then, you know, they go ahead and analyze the risk, you know, design, they do threat modeling. [22:20.540 --> 22:21.760] You know, you see, I'm not making this up. [22:21.840 --> 22:22.300] It's right here. [22:23.060 --> 22:25.660] You know, they specify tools and it goes on throughout the lifecycle. [22:25.920 --> 22:29.100] And there's white papers and all kinds of examples out of the websites here that they talk about. [22:29.460 --> 22:36.880] You know, they've got some metrics that, you know, oh, we reduce the amount of, you know, one year patches by 70% or whatnot. [22:37.240 --> 22:41.880] There's different things that they have on the website, you know, that kind of validate the fact that all this works. [22:43.780 --> 22:46.680] So, here's my favorite example of real-world threat modeling. [22:47.560 --> 22:48.720] So, I have a six-year-old daughter. [22:49.320 --> 22:51.540] And we got her this thing called Alphabet Pal. [22:51.820 --> 22:53.620] And it's made by this company called LeapFrog. [22:53.900 --> 22:55.340] It makes all these educational toys. [22:56.020 --> 22:59.060] So, it's got these, you know, you see it's got the letter feet along the bottom. [22:59.260 --> 23:00.680] And you can put a little, there's a little switch there. [23:00.760 --> 23:02.740] You put it on a mode, you hit the letter, it says A, B, C. [23:02.740 --> 23:04.400] Put another one and play songs. [23:04.680 --> 23:06.260] Well, one of the modes is phonetics. [23:06.720 --> 23:10.900] And so, you put it on the switch and it hit F and it goes F and it hit K and it goes K. [23:11.260 --> 23:12.620] And it hit S and it goes Sh. [23:12.900 --> 23:14.100] And it hit T and it goes T. [23:14.220 --> 23:15.040] Do you see where I'm going with this? [23:17.000 --> 23:19.380] So, one day she's just like mashing keys on the thing. [23:19.540 --> 23:21.060] And I hear it go, hee hee, that tickles. [23:21.280 --> 23:22.840] I was like, what was that about? [23:23.060 --> 23:24.820] So, I picked the thing up and I started pushing things. [23:24.820 --> 23:28.260] And I realized on certain combinations or patterns, it laughed. [23:29.180 --> 23:31.080] And so, I started looking at it more. [23:31.220 --> 23:34.240] And, you know, being a troublemaker, I started like trying to spell curse words. [23:35.200 --> 23:38.900] And whenever I put in that last letter, it laughed at me. [23:40.600 --> 23:47.120] And, you know, that was kind of disconcerting that this little toy knew, you know. [23:47.120 --> 23:50.660] So, it was like, you know, F, U, C, and it laughed. [23:50.780 --> 23:53.060] And I was like, okay, well, F, U, K, and it laughed. [23:53.180 --> 23:55.620] And I'm like, wait a minute, somebody threat modeled this. [23:55.780 --> 23:59.500] Somebody sat down and thought that this would happen. [23:59.680 --> 24:03.800] So, through my own testing and blogs, I found this blacklist. [24:04.020 --> 24:05.480] I'm sure there's more out there. [24:12.310 --> 24:14.590] If you need any of these explained, see me afterwards. [24:14.850 --> 24:16.110] I can let you in on the joke. [24:22.120 --> 24:24.060] But, my favorite here is the last ones. [24:24.060 --> 24:24.600] Yuck. [24:25.560 --> 24:26.720] Yuck is blacklisted. [24:27.380 --> 24:30.520] All I can think is I guess they don't want the kids, like, critiquing their mom's cooking or something. [24:31.200 --> 24:32.760] I'm not really sure why that's there. [24:33.600 --> 24:34.880] But I read this one blog post. [24:34.960 --> 24:37.460] Somebody tried over 50 racial slurs and they all went through. [24:38.540 --> 24:41.280] So, at least they're like an equal opportunity, you know. [24:41.680 --> 24:49.660] So, but yeah, I mean, this is hilarious that some guy, as part of his job, sat down and threat modeled this. [24:49.860 --> 24:53.100] You know, this is what they considered a problem, you know. [24:53.100 --> 24:56.160] All I can imagine in my head is that they got an intern to do it. [24:56.360 --> 24:58.460] Because this sounds like the kind of work you would give an intern. [24:59.020 --> 25:01.080] And, you know, especially like a really good intern. [25:01.220 --> 25:07.100] One of those guys, you give them a project and they do it like a thousand times better than you'd assume anybody in the company would ever do it. [25:07.700 --> 25:12.500] You know, because if you gave this to like a regular salary guy, you know, bottom of the barrel. [25:12.740 --> 25:13.540] It would kind of work here, yeah. [25:13.980 --> 25:16.120] But this is a perfect example of threat modeling. [25:18.520 --> 25:23.620] So, the key points, you know, the takeaways here is that, you know, you want to know yourself, know the enemy. [25:23.820 --> 25:25.100] Again, back to Sun Tzu again. [25:26.040 --> 25:28.440] Again, you want to never trust user inputs or dependencies. [25:31.560 --> 25:33.900] It's, you know, they are the enemy. [25:34.120 --> 25:35.260] That's the best way to think of it. [25:35.380 --> 25:37.020] You know, just always default to that assumption. [25:37.500 --> 25:39.920] And so, you want to think in terms again of the CIA triad. [25:40.400 --> 25:41.840] Confidentiality, integrity, availability. [25:42.180 --> 25:44.780] And then again, the most important part, the rebels were terrorists. [25:45.620 --> 25:46.620] Long live the Galactic Empire. [25:46.960 --> 25:49.560] And I realize I talk way too fast. [25:49.960 --> 25:52.680] So, is there any questions, discussions? [25:54.040 --> 25:55.640] Share some more anecdotes about toys? [26:00.320 --> 26:03.480] And apparently with that toy, there's newer models out there. [26:03.540 --> 26:07.040] I saw a video on YouTube just the other day of a new one that actually will spell the words. [26:07.560 --> 26:09.200] And then there was like, there was some uproar of it. [26:09.260 --> 26:12.040] So, I don't know if they redid the firmware or whatnot. [26:12.380 --> 26:15.160] But yeah, so now apparently there are some that can curse. [26:15.440 --> 26:22.140] So, if you go to, if you Google it on YouTube, I think one of them is called like, F-U-C-K-A-Pillar or something like that. [26:22.480 --> 26:25.940] Or F-U-C-K-P-E-D-E, I think is what they call it. [26:26.380 --> 26:28.340] So, if you just Google it on YouTube, you'll find it. [26:28.800 --> 26:30.740] So, questions? [26:31.900 --> 26:33.000] Alright, thank you all for coming. [26:45.980 --> 26:48.060] Yeah, they go and hack the sound chips and stuff. [26:48.520 --> 26:48.660] Yeah. [26:49.060 --> 26:49.680] Hey, how you doing? [26:50.900 --> 26:53.300] Um, yeah, you know, they're going to be... [26:53.300 --> 26:54.240] Here, let me give you a business card. [26:55.280 --> 26:56.860] They'll probably be on my... [26:56.860 --> 26:59.740] I always advertise my company, but they'll be on that website. [26:59.920 --> 27:01.440] Probably on dinner.com or on the blog.