Threat Modeling: Repudiation in Depth

Threat Modeling: Repudiation in Depth

25mIntermediate2020-02-07

Authors

Adam Shostack

Adam Shostack

Consultant, Entrepreneur, Technologist, and Game Designer

Course details

Repudiation—the third stage in the STRIDE threat modeling framework—involves the acceptance or denial of responsibility. In the case of identity theft, repudiation comes into play when victims deny involvement with the charges racked up by the criminal. These threats impact all sorts of systems, and security professionals and developers need to understand how they work, and how they can ensure that their systems offer defenses that accurately indicate responsibility. In this installment of his Threat Modeling series, Adam Shostack takes a deep dive into the subject of repudiation. Using practical examples, Adam covers the issues of fraud, identity theft, attacks on logs, and repudiation in specific technologies such as blockchain and the cloud.

Topics include:
- Message and operational repudiation
- Fraud, including account takeover
- Identity theft, including deepfakes and voice cloning
- Attacks on logs
- Repudiation in AI, machine learning, and blockchain
- Applying cryptographic defenses

Skills covered

Software Development SecurityIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • The threat of repudiation
  • Four-question framework
  • Repudiation as part of STRIDE

Technical Repudiation

  • Message repudiation
  • Operational repudiation

Fraud

  • Buyers and sellers
  • Intermediaries
  • Account takeover

Identity Theft

  • Identity theft and repudiation
  • Catfishing, deepfakes, and voice cloning

Attacks on Logs

  • Attacks on logs
  • Attacks via logs and response systems

Repudiation in Specific Technologies

  • Cloud
  • AI and machine learning
  • Crypto and blockchain

Defenses

  • Cryptographic defenses
  • Logs
  • Log analysis
  • Anti-fraud

Conclusion

  • Next steps