Octotrike.org
Papers Talks Tools FAQ IRC Contact
¤ ToorCon 2007 Presentation
Privilege-Centric Security Analysis

From the conference website:

Brenda will present a simple, uniform model for expressing both intended behavior and security problems in terms of privilege. The model, which is a work in progress for the Trike development team, applies at any point during the development process, from requirements to a deployed implementation. This model could be used to automatically combine simple attacks with intended system behavior to achieve more complicated attack goals, replacing the effort-intensive tree-based portion of traditional threat modeling techniques.

Slides

Privilege-Centric Security Analysis



Octopus

News

22 Dec 2010
The first fully functional spreadsheet is available.

03 Jan 2011
Slides from Brenda's talk at BayThreat 2010 are available.

Thanks

SourceForge.net Logo

Copyright © 2004-2008 Brenda Larcom, Eleanor Saitta, and Stephanie Smith. Copyright © 2009-2011 Brenda Larcom and Eleanor Saitta. All rights reserved.