Building Software

Engineering Fundamentals for the Agent Era

Contents Section 8, Security

Security Boundaries and Threat Modeling

Mistakes to catch in review

  1. An internal service that trusts any caller on the network because it is considered internal.

  2. A debug endpoint or admin route added during development and left reachable in production.

  3. A security check that fails open, allowing access whenever the authorization service is down.

  4. A new integration granted full administrative scope when it needed read access to one resource.

Finding where trust changes in a system, what crosses each boundary, and what an attacker would try there.

Topics

Trust Boundaries
Browser to server, service to service, user to admin and agent to tool: every point where the level of trust changes.
Threat Modeling
Asking what can go wrong, with methods such as STRIDE and attack trees, early enough to change the design.
Attack Surface
Counting every input, endpoint, dependency and credential an attacker could reach, and shrinking that list.
Least Privilege
Giving each person, service and agent only the access its job requires.
Defense in Depth and Secure Defaults
Layered controls that fail closed, so a single mistake does not become a breach.

You understand it when you can

  • Draw the trust boundaries of an application and list the data and commands that cross each one.
  • Produce a threat model for a new feature with its top threats and a mitigation for each.
  • Apply least privilege to a service account and demonstrate what it can no longer do.

Drill

An agent added an internal reporting service that accepts requests from any machine on the network, exposes a /debug/env route, and treats a timeout from the policy service as permission granted. Draw the trust boundaries and find each way an attacker gets in.

Start here

Watch

Threat Modeling Lessons from Star Wars (and Elsewhere)

Adam Shostack, 2014. 57-minute talk.

Shostack teaches his four questions (what are we working on, what can go wrong, what are we going to do about it, did we do a good job), using data-flow diagrams and STRIDE, so a developer can threat-model a feature before it ships.

Watch

Read

Threat Modeling: Designing for Security

Adam Shostack, 2014.

The standard text on drawing trust boundaries with data-flow diagrams and working through STRIDE and attack trees systematically; it covers the subsection's core method end to end.

Primary sources