An Introduction to Threat Modelling: Modelling Steps, Model Types, Benefits and Challenges

  • Nitin Naik*
  • , Paul Jenkins
  • , Paul Grace
  • , Dishita Naik
  • , Shaligram Prajapat
  • , Jingping Song
  • *Awdur cyfatebol y gwaith hwn

Allbwn ymchwil: Pennod mewn Llyfr/Adroddiad/Trafodion CynhadleddCyfraniad mewn cynhadleddadolygiad gan gymheiriaid

Crynodeb

The proliferation of cybersecurity threats is posing substantial security risks to organisations; therefore, it requires robust countermeasures and defence mechanisms for organisational IT systems, applications and data. Threat modelling is a process of identifying, analysing, prioritising and mitigating threats and their associated vulnerabilities in a system or network. Understanding the threat modelling process, as well as its benefits and limitations, whilst selecting an appropriate threat modelling method that may assist cybersecurity experts in their comprehensive security assessments. The assessments are designed to uncover security gaps and potential threats, to develop robust countermeasures against these potential threats and strengthening the security of organisational IT systems, applications and data. This paper will present a comprehensive study concerning threat modelling including the phases involved in threat modelling, types of threat models and benefits and challenges of threat modelling. Therefore, this comprehensive study concerning threat modelling will simplify the essential terminologies of threat modelling to users in a clear and concise manner.

Iaith wreiddiolSaesneg
TeitlContributions Presented at The International Conference on Computing, Communication, Cybersecurity and AI - The C3AI 2024
GolygyddionNitin Naik, Paul Grace, Paul Jenkins, Shaligram Prajapat
CyhoeddwrSpringer Science and Business Media Deutschland GmbH
Tudalennau260-270
Nifer y tudalennau11
ISBN (Argraffiad)9783031744426
Dynodwyr Gwrthrych Digidol (DOIs)
StatwsCyhoeddwyd - 20 Rhag 2024
DigwyddiadInternational Conference on Computing, Communication, Cybersecurity and AI, C3AI 2024 - London, Y Deyrnas Unedig
Hyd: 3 Gorff 20244 Gorff 2024

Cyfres gyhoeddiadau

EnwLecture Notes in Networks and Systems
Cyfrol884 LNNS
ISSN (Argraffiad)2367-3370
ISSN (Electronig)2367-3389

Cynhadledd

CynhadleddInternational Conference on Computing, Communication, Cybersecurity and AI, C3AI 2024
Gwlad/TiriogaethY Deyrnas Unedig
DinasLondon
Cyfnod3/07/244/07/24

Dyfynnu hyn