Threat Modeling: Denial of Service and Expansion of Authority

Threat Modeling: Denial of Service and Expansion of Authority

48mAdvanced2024-09-04

Authors

Adam Shostack

Adam Shostack

Consultant, Entrepreneur, Technologist, and Game Designer

Course details

In this installment of Adam Shostack’s Threat Modeling series covering the STRIDE threat modeling framework, Adam goes over the D and E parts of the framework: denial-of-service and elevation-of-privilege. For both threats, Adam digs deep into two main questions: “What can go wrong?” and “What are we going to do about it?” He details the many targets of denial-of-service attacks like storage, memory, CPU bandwidth, and budget. Adam explains how elevation-of-privilege exists in basically any running code. He then goes over structured methods for ensuring that your systems are resistant to the various types of DoS attacks and elevation-of-privilege attacks. These attacks affect all manner of systems, and having an understanding of how they work and how to combat them are essential parts of a comprehensive approach to cybersecurity.

Skills covered

Software Development SecurityIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Let me interrupt you
  • STRIDE and the four question framework

DoS Targets

  • DoS in context
  • Attackers fill networks
  • How attackers redline your CPU
  • How attackers fill storage
  • How attackers spend your budget
  • How attackers drain your battery

Properties of DoS Attacks

  • Persistence and transience of DoS
  • Na ve to clever - Understanding DoS
  • Amplified or native - Two modes of DoS

DoS in Various Technologies

  • Mobile and IoT denial of service
  • Cloud denial of service

DoS Defenses

  • Designing for resilience
  • Quantity as a defense

EOP

  • What is elevation of privilege
  • Privilege and authority
  • Input corrupts
  • Main forms of corrupt input

EOP Defenses

  • Ways to defend against EOP
  • Validation to defend against elevation
  • Validate for purpose to prevent elevations
  • Validation not sanitization for defense
  • Attenuation in defense
  • Memory safety as a defensive tool
  • Stack canaries to protect your code
  • Sandboxes and isolation protect your environment
  • Bolt-on or built-in defenses

Conclusion

  • Security by design
40,000 Toman