The chapter on threatmodeling and risk assessment is particularly important.
“威协建模和危险评估”这一章非常重要。
2
Threatmodeling is composed of three high-level steps: understanding the adversary's view, characterizing the security of the system, and determining threats.
威胁模型是由三个高阶步骤所组成:了解敌人的观点、描绘系统安全性的特徵,以及判断威胁来源。
3
Threatmodeling is an iterative approach to assessing vulnerabilities in your application to find those that are the most dangerous because they expose the most sensitive data.