Threat Modeling: Information Disclosure in Depth

Go to class
Write Review

Free Online Course: Threat Modeling: Information Disclosure in Depth provided by LinkedIn Learning is a comprehensive online course, which lasts for Less than 1 hour of material. The course is taught in English and is free of charge. Upon completion of the course, you can receive an e-certificate from LinkedIn Learning. Threat Modeling: Information Disclosure in Depth is taught by Adam Shostack.

Overview
  • Learn about the information disclosure pillar in the STRIDE threat modeling framework. Discover how to preserve the confidentiality of the data, secrets, and other information you store.

Syllabus
  • Introduction

    • Allow me to disclose something
    • Four-question framework
    • Information disclosure as a part of STRIDE
    1. Data at Rest
    • Authorized access
    • Physical layer
    • Metadata
    2. Data in Motion
    • Encrypted and unencrypted
    • Metadata in motion
    • Non-internet data
    3. Information Disclosure by Processes
    • Intentional disclosure
    • Metadata and security
    4. Side Effects
    • Radios: Intentional and accidental
    • Timing
    • Interpretation
    5. Disclosure in Certain Technologies
    • Cloud
    • IoT and mobile
    • AI and machine learning
    6. Defenses
    • Metadata management
    • Secrets and secrets management
    • Cryptography
    Conclusion
    • Next steps