The following are some screenshots of SecurITree with a sample decision tree loaded for analyzing home burglaries:
SecurITree's main interface showing the sample attack tree:

Drilling down to edit specific node data:

The process gets pretty technical and it's not for the faint of heart but the good news is that it's built-in Help explains just what you need to know.
SecurITree's Help window:

If you need details on which threats matter and the level of risk your business is up against, and don't know where to start you've got to check out SecurITree. This process can take some time, and as the folks at Amenaza admit, this process isn't foolproof but it could be well worth your investment.
While we're on the subject, check out this article I wrote on threat modeling.





0 comments:
Post a Comment