Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Threat Modeling: Denial of Service and Expansion of Authority

Threat Modeling: Denial of Service and Expansion of Authority

48mAdvanced2024-09-04

Authors

Adam Shostack

Adam Shostack

Consultant, Entrepreneur, Technologist, and Game Designer

Course details

In this installment of Adam Shostack’s Threat Modeling series covering the STRIDE threat modeling framework, Adam goes over the D and E parts of the framework: denial-of-service and elevation-of-privilege. For both threats, Adam digs deep into two main questions: “What can go wrong?” and “What are we going to do about it?” He details the many targets of denial-of-service attacks like storage, memory, CPU bandwidth, and budget. Adam explains how elevation-of-privilege exists in basically any running code. He then goes over structured methods for ensuring that your systems are resistant to the various types of DoS attacks and elevation-of-privilege attacks. These attacks affect all manner of systems, and having an understanding of how they work and how to combat them are essential parts of a comprehensive approach to cybersecurity.

Skills covered

Software Development SecurityIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

0. Introduction

  • 01 - Let me interrupt you
  • 02 - STRIDE and the four question framework

1. DoS Targets

  • 03 - DoS in context
  • 04 - Attackers fill networks
  • 05 - How attackers redline your CPU
  • 06 - How attackers fill storage
  • 07 - How attackers spend your budget
  • 08 - How attackers drain your battery

2. Properties of DoS Attacks

  • 09 - Persistence and transience of DoS
  • 10 - Na ve to clever - Understanding DoS
  • 11 - Amplified or native - Two modes of DoS

3. DoS in Various Technologies

  • 12 - Mobile and IoT denial of service
  • 13 - Cloud denial of service

4. DoS Defenses

  • 14 - Designing for resilience
  • 15 - Quantity as a defense

5. EOP

  • 16 - What is elevation of privilege
  • 17 - Privilege and authority
  • 18 - Input corrupts
  • 19 - Main forms of corrupt input

6. EOP Defenses

  • 20 - Ways to defend against EOP
  • 21 - Validation to defend against elevation
  • 22 - Validate for purpose to prevent elevations
  • 23 - Validation not sanitization for defense
  • 24 - Attenuation in defense
  • 25 - Memory safety as a defensive tool
  • 26 - Stack canaries to protect your code
  • 27 - Sandboxes and isolation protect your environment
  • 28 - Bolt-on or built-in defenses

Conclusion

  • 29 - Security by design

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal