The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise Level
Rock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern, Patrick Sweeney, Michelle L. Mazurek
摘要
Digital security professionals use threat modeling to assess and improve the security posture of an organization or product. However, no threat-modeling techniques have been systematically evaluated in a real-world, enterprise environment. In this case study, we introduce formalized threat modeling to New York City Cyber Command: the primary digital defense organization for the most populous city in the United States. We find that threat modeling improved self-efficacy; 20 of 25 participants regularly incorporated it within their daily duties 30 days after training, without further prompting. After 120 days, implemented participantdesigned threat mitigation strategies provided tangible security benefits for NYC, including blocking 541 unique intrusion attempts, preventing the hijacking of five privileged user accounts, and addressing three public-facing server vulnerabilities. Overall, these results suggest that the introduction of threat modeling can provide valuable benefits in an enterprise setting. * We would like to thank the leadership and strategic communications personnel of NYC Cyber Command for making this study possible. Additionally, we would like to thank Lujo Bauer of Carnegie Mellon University for his advice and expertise in shaping this study.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili 等CCS 2019 · 被引用 134 次
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar 等S&P 2022 · 被引用 51 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- "There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical DevicesRonald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel VotipkaUSENIX Security 2024 · 被引用 15 次
- Understanding the How and the Why: Exploring Secure Development Practices through a Course CompetitionKelsey R. Fulton, Daniel Votipka, Desiree Abrokwa, Michelle L. Mazurek 等CCS 2022 · 被引用 7 次
相关 Paper
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl 等USENIX Security 2025
- SoK: Quantifying Cyber RiskDaniel W. Woods, Rainer BöhmeS&P 2021 · 被引用 54 次
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
- SoK: A Framework and Guide for Human-Centered Threat Modeling in Security and Privacy ResearchWarda Usman, Daniel ZappalaS&P 2025
- A limited technical background is sufficient for attack-defense tree acceptabilityNathan Daniel Schiele, Olga GadyatskayaUSENIX Security 2025
