Threat Modeling: Repudiation in Depth
25mIntermediate2020-02-07
Authors

Adam Shostack
Consultant, Entrepreneur, Technologist, and Game Designer
Course details
Repudiation—the third stage in the STRIDE threat modeling framework—involves the acceptance or denial of responsibility. In the case of identity theft, repudiation comes into play when victims deny involvement with the charges racked up by the criminal. These threats impact all sorts of systems, and security professionals and developers need to understand how they work, and how they can ensure that their systems offer defenses that accurately indicate responsibility. In this installment of his Threat Modeling series, Adam Shostack takes a deep dive into the subject of repudiation. Using practical examples, Adam covers the issues of fraud, identity theft, attacks on logs, and repudiation in specific technologies such as blockchain and the cloud.
Topics include:
- Message and operational repudiation
- Fraud, including account takeover
- Identity theft, including deepfakes and voice cloning
- Attacks on logs
- Repudiation in AI, machine learning, and blockchain
- Applying cryptographic defenses
Topics include:
- Message and operational repudiation
- Fraud, including account takeover
- Identity theft, including deepfakes and voice cloning
- Attacks on logs
- Repudiation in AI, machine learning, and blockchain
- Applying cryptographic defenses
Skills covered
Software Development SecurityIncident ResponseCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - The threat of repudiation
- 02 - Four-question framework
- 03 - Repudiation as part of STRIDE
1. Technical Repudiation
- 04 - Message repudiation
- 05 - Operational repudiation
2. Fraud
- 06 - Buyers and sellers
- 07 - Intermediaries
- 08 - Account takeover
3. Identity Theft
- 09 - Identity theft and repudiation
- 10 - Catfishing, deepfakes, and voice cloning
4. Attacks on Logs
- 11 - Attacks on logs
- 12 - Attacks via logs and response systems
5. Repudiation in Specific Technologies
- 13 - Cloud
- 14 - AI and machine learning
- 15 - Crypto and blockchain
6. Defenses
- 16 - Cryptographic defenses
- 17 - Logs
- 18 - Log analysis
- 19 - Anti-fraud
Conclusion
- 20 - Next steps