kirancodes.me
To Proof Maintenance & Beyond!

Checking threat modeling data flow diagrams for implementation conformance and security

Marwan Abi-Antoun, Daniel Wang, Peter Torr

Abstract

Threat modeling is a lightweight approach to reason about application security and uses Data Flow Diagrams (DFDs) with security annotations. We extended Reflexion Models to check the conformance of an as-designed DFD with an approximation of the as-built DFD obtained from the implementation. We also designed a set of properties and an analysis to help novice designers think about security threats such as spoofing, tampering and information disclosure.

BibTeX
@inproceedings{AbiAntoun-al:ASE07,
  author    = {Marwan Abi{-}Antoun and
               Daniel Wang and
               Peter Torr},
  title     = {Checking threat modeling data flow diagrams for implementation conformance and security},
  booktitle = {ASE},
  pages     = {393--396},
  publisher = {{ACM}},
  year      = {2007},
}

Related papers