1 / 1100%
Here is what I would do to my residence towards threat modeling:
Step 1: Identify security objectives - To secure my house, I would have to start thinking about the
exterior first then focus on the interior. This means putting up gates or barriers to entry, such as doors
with locks and potential security cameras. When we want to protect is the valuable assets that we
have on the interior, if you have no valuable assets, there is no need to put up protective measures.$
Step 2: Identify assets and external dependencies - strictly from a network perspective, one should
note the things that are saved or connected to the network, such as family photos, important files,
home business information, and other personal items that live on a drive that is connected to your
network. The external dependencies is your internet service provider. The ISP provides connecting
points for you to access these files on the go and while you're at home sharing your photos on an
Amazon Alexa. It also allows users that have a security camera to access them while away from
home; therefore, once your network has been hacked, your camera or wifi door locks would be
compromised.
Step 3: Identify trust zones - Trust zones would be established in the form of guest connections or
shared access for known users, or in the case of a house, known residents. Those you connect to
your network as a guest should not have access to any asset. Similar to a guess coming to your
house you may not show them the layout of your master bedroom; in other words, there are limits to
what they can see and touch.
Step 4: Identify potential threats and vulnerabilities - Threats can come from anywhere or anyone with
malicious intent to take what is not there, so it would not be defined as one person or thing. Someone
who knows of the files you keep on your network and is trying to gain access, or someone who knows
you have a safety box inside the house with at least 100k for an emergency purpose, would be prime
suspects for trying to gain access the home and its network. Vulnerabilities would be your major
points of entry, as well as your minor points of entry, such as windows. Network vulnerabilities would
be the printer, phone, router/wifi extender, security hardware, and any connected device to my
network.
$$
Step 5: Document your threat model - Secure the home with external gates, secure the network with
firewalls, secure the home with a security alarm system that will protect the doors and windows. Lock
down the network with a secure password, and to close the loop, make sure all connected device is
updated to the latest security and firmware.
source:
https://www.techtarget.com/searchsecurity/definition/threat-modeling
https://www.youtube.com/watch?v=h_BC6QMWDbA
Students also viewed