|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/stride-threat-modeling-step-by-step/
课程评论:没有评论
课程名称:STRIDE:一步步进行威胁建模 课程概述:在设计过程中及早理解和减少安全威胁对于构建安全的应用程序和系统至关重要。在这门实用的课程“STRIDE:一步步进行威胁建模”中,您将学习如何使用广泛应用的STRIDE框架系统地识别、分析和减轻威胁。此课程面向希望在软件开发生命周期中融入安全性的软体工程师、安全分析师、架构师和产品经理。无论您是在保护云应用、微服务、移动应用还是API,这种逐步结构将帮助您掌握基础知识并直接应用于工作中。 课程将首先介绍威胁建模的关键概念,讲述其重要性以及在系统设计中的定位。接下来,您将学习数据流图(DFD),作为模型化数据在系统中移动及可能产生的漏洞的基础。STRIDE模型的每个阶段——欺骗、篡改、否认、信息披露、服务拒绝及特权提升——都将详细讲解,配以真实案例分析。您将学习如何将威胁映射到系统组件,使用风险矩阵评估其严重性,并通过威胁表进行记录。更重要的是,您将了解如何将每个威胁映射到合适的安全控制措施,包括预防性、探测性或纠正性措施。 课程还教授您如何在系统不断演变的过程中跟踪和重新评估威胁,从而实现持续安全,并与OWASP、ISO/IEC 27001及DevSecOps实践等框架保持一致。我们将使用一个实际案例研究——健康跟踪应用程序,详细展示每个概念,使您可以从头到尾看到STRIDE的实际应用。 通过完成这门课程,您将能够: - 从零开始创建STRIDE威胁模型 - 建立和解释系统的DFD - 识别和优先处理安全风险 - 应用可行的减轻措施 - 在威胁建模研讨会上自信合作 本课程不需要您具备网络安全方面的先前经验。立即加入,掌握在攻击者发现弱点之前保护您系统的技能。
Understanding and mitigating security threats early in the design process is critical to building secure applications and systems. In this practical and hands-on course, "STRIDE: Threat Modeling Step by Step," you will learn how to systematically identify, analyze, and mitigate threats using the STRIDE framework - one of the most widely used methodologies in application security.This course is designed for software engineers, security analysts, architects, and product managers who want to embed security into the software development lifecycle. Whether you're securing cloud applications, microservices, mobile apps, or APIs, the step-by-step structure will help you master the fundamentals and apply them directly in your work.You will start by learning the key concepts of threat modeling, why it matters, and where it fits into system design. Then, you'll explore Data Flow Diagrams (DFDs) as the foundation for modeling how data moves through your system and where vulnerabilities may arise.Each stage of the STRIDE model - Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege - is covered in detail with real examples. You'll learn how to map threats onto system components, assess their severity using risk matrices, and document them using threat tables. More importantly, you'll discover how to map each threat to appropriate security controls, whether preventive, detective, or corrective.The course also teaches you how to track and reassess threats as your system evolves over time, enabling continuous security and alignment with frameworks like OWASP, ISO/IEC 27001, and DevSecOps practices.We use a realistic case study - a health tracking application - to demonstrate each concept, so you can see STRIDE in action from start to finish.By the end of this course, you'll be able to:Create threat models from scratch using STRIDEBuild and interpret DFDs for your systemsIdentify and prioritize security risksApply actionable mitigationsCollaborate confidently in threat modeling workshopsNo prior experience in cybersecurity is required. Join now and gain the skills to secure your systems before attackers find the weaknesses.