This Book about threat modeling, a process for identifying and mitigating security risks in software. The book explains various threat modeling strategies, including asset-centric, attacker-centric, and software-centric approaches. It also covers specific threat categories (like STRIDE), attack libraries, and tools for threat modeling. The text includes examples and case studies illustrating how to apply these techniques to different systems and technologies, such as web applications, cloud services, and mobile devices. Finally, it discusses human factors and usability considerations in security design.
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cyber_security_summary
Get the Book now from Amazon:
https://www.amazon.com/Threat-Modeling-Designing-Adam-Shostack/dp/1118809998?&linkCode=ll1&tag=cvthunderx-20&linkId=ee13c6dfbf6e7902c19808b7328cf6a2&language=en_US&ref_=as_li_ss_tl