The Threat Modeling Naturally Tool: An Interactive Tool Supporting More Natural Flexible and Ad-Hoc Threat Modeling

dc.contributor.authorThompson, Ronald E.
dc.contributor.authorRed, Madison
dc.contributor.authorZhang, Richard
dc.contributor.authorKwon, Yaejie
dc.contributor.authorDang, Lisa
dc.contributor.authorPellegrini, Christopher
dc.contributor.authorNesru, Esam
dc.contributor.authorJain, Mira
dc.contributor.authorChin, Caroline
dc.contributor.authorVotipka, Daniel
dc.contributor.authorUniversity, Tufts
dc.contributor.authorCollege, Swarthmore
dc.contributor.authorUniversity, Northeastern
dc.date.accessioned2024-10-28T14:30:27Z
dc.date.available2024-10-28T14:30:27Z
dc.date.issued2024
dc.descriptionUSENIX Symposium on Usable Privacy and Security (SOUPS) 2024. August 11–13, 2024, Philadelphia, PA, United States.
dc.description.abstractThreat modeling is an important process in achieving secureby-design software systems. While some tools have been developed to aid system architects in building threat models, many of these do not support the more flexible ways that threat modeling occurs in practice. We present the Threat Modeling Naturally Tool as the first step in providing architects with a tool that allows for a more natural threat modeling process that is modular in design. This tool consists of a threat modeling Domain-Specific Language and a series of modular components that allow users to specify their system and assign threats and mitigations without disrupting their brainstorming. We describe the design and implementation of our tool using a mock medical device as a case study as well as discuss how the tool can be used for future work supporting threat modeling research.
dc.description.urihttps://security-information-workers.github.io/downloads/wsiw2024-final18.pdf
dc.format.extent8 pages
dc.genreconference papers and proceedings
dc.genrepreprints
dc.identifierdoi:10.13016/m2uapb-eyuv
dc.identifier.urihttp://hdl.handle.net/11603/36740
dc.language.isoen_US
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.relation.ispartofUMBC Student Collection
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.titleThe Threat Modeling Naturally Tool: An Interactive Tool Supporting More Natural Flexible and Ad-Hoc Threat Modeling
dc.typeText

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
wsiw2024final18.pdf
Size:
5.13 MB
Format:
Adobe Portable Document Format