Threat Modeling: Tampering in Depth
32mIntermediate2019-09-06
Authors

Adam Shostack
Consultant, Entrepreneur, Technologist, and Game Designer
Course details
Threat modeling allows security pros and software developers to proactively address the inevitable—hackers trying to compromise a system—early on in a project's life cycle. In this course, Adam Shostack covers tampering, the second stage in the STRIDE threat modeling framework. Tampering can compromise the integrity of a variety of systems and tools, from debuggers to Iocal storage. Throughout this course, Adam describes how different tampering threats work, as well as what you can do about them. Learn how attackers can tamper with libraries, IoT devices, cloud services, and more.
Learning objectives
Tampering as part of STRIDE
How debuggers can be exploited by attackers
Effects of tampering on storage
Tampering with data flows
Physical tampering
Tampering with cloud services
Prevention and detection goals
Learning objectives
Tampering as part of STRIDE
How debuggers can be exploited by attackers
Effects of tampering on storage
Tampering with data flows
Physical tampering
Tampering with cloud services
Prevention and detection goals
Skills covered
Software Development SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Mitigate tampering threats
- 02 - Four-question framework
- 03 - Tampering as part of STRIDE
1. Tampering with a Process
- 04 - Debuggers and input
- 05 - Libraries
- 06 - Mobile
2. Tampering with Storage
- 07 - Tampering with local storage
- 08 - Permissions
- 09 - Effects of tampering
3. Tampering with Things
- 10 - Whose screw Physical tampering matters
- 11 - Debug interfaces are exposed
4. Tampering with Time Itself
- 12 - Time is increasingly important
5. Tampering with Cloud
- 13 - Controls and authentication
- 14 - Becoming Jane Admin
6. Tampering with Data Flows
- 15 - Channels and messages
- 16 - Replay and reflection
- 17 - Headers - Injection and order
7. Integrity Defenses
- 18 - Prevention and detection goals
- 19 - Crypto
- 20 - Something more privileged
Conclusion
- 21 - Next steps