Submit Event
TMC Tokyo Local Meetup: Threat Modeling Night #18

TMC Tokyo Local Meetup: Threat Modeling Night #18

25 Aug 202619:00 - 21:30 Asia/TokyoChiyoda City, Japan10 AttendeesOpen

Description

An open community aimed at sharing knowledge about threat modelingThis community meetup is a vendor-neutral open community event focused on sharing insights about threat modeling, featuring various talks by speakers. Open discussions are encouraged.OrganizerThreat Modeling Connect Tokyo Chapter (abbreviated: TMC Tokyo)Global Community Sponsor IriusRisk (https://www.iriusrisk.com/)Chapter Sponsor Secure Modeling Inc. (https://secure-modeling.jp/)Target Audience Anyone interested in threat modelingTalksTeam-Based Threat Modeling Transition Model - From Expert-Led to Team-Led - Overview: The goal of threat modeling is to create a state where the entire organization can work on security. Each member of the organization should naturally consider threats and their countermeasures in their daily activities. I believe it's ideal to instill the habit of thinking about threats throughout the organization.However, to achieve full participation, we must scale the activities of threat modeling (or the habit of thinking about threats) within the organization. This requires starting from a phase led by security experts and gradually transitioning to a model where on-site members are the main actors.This talk will break down that transition process into stages and organize the roles and scope of involvement at each stage as a model.The main target audience is practitioners aiming to expand threat modeling within their organizations. At the same time, I want to create content through discussions with all participants that will provide insights and clues for those who don't have practical experience yet but may engage in this area in the future.Speaker: Takaharu Ogasa, Secure Modeling Inc.Speaker Profile: President of Secure Modeling Inc. He has been involved in security evaluations in the application and mobile fields for many years and currently provides consulting, education, and internalization support for incorporating security from the design phase, focusing on threat modeling. He is also involved in the operation of OWASP Sendai and Threat Modeling Connect Tokyo and is working on practical application and dissemination in the domestic field.Threat Modeling for Applications Using AIOverview: While applications incorporating generative AI and LLM are rapidly gaining popularity, a common understanding of how to evaluate them at the design stage has not yet been fully established. Threats such as prompt injection, contamination of training data, and autonomous external manipulation by agents present challenges not previously considered in traditional application security. However, these are not entirely new problems, and many can be framed within existing threat modeling frameworks. It is important to clarify the points to consider based on how AI is utilized, whether it remains at API calls, involves RAG, or acts as an agent. This talk will categorize AI usage patterns and discuss the best methods for conducting threat modeling.The primary audience includes those involved in the development and design of AI-driven applications and those who wish to expand existing threat modeling practices into the AI domain.Speaker: Yuichi Hattori, Secure Cycle Inc.Speaker Profile: Graduated from Kyushu Institute of Technology. During his studies, he was engaged in research on behavior recognition using smartphones and worked as a Research Intern at Microsoft Research Asia in the field of behavior recognition. After gaining experience as a Chief Engineer at a venture company in developing new web services and vulnerability assessment, he became the CTO of an information security firm before his current position. He has given many lectures and training sessions at security-related events across various regions, universities, and companies. He is also involved in practical work such as vulnerability assessments and consulting on security measures during development.ScheduleCode of Conduct1. Spirit of RespectAll participants, speakers, sponsors, and volunteers are expected to treat each other with respect regardless of gender, sexual orientation, disability, appearance, body size, race, ethnicity, age, religion, or technology choice.2. Harassment ProhibitionHarassment behaviors such as the following are not tolerated within the community:3. Participant ResponsibilityParticipants of the meetup are responsible for adhering to these rules. If harassment is witnessed, it is expected to report it to the organizers.4. Organizer's RoleOrganizers will take appropriate action against behaviors that violate the code of conduct. This may include issuing warnings or expelling individuals from the meetup.5. Ensuring a Safe EnvironmentOur goal is to provide a safe and positive experience for all. Each participant is asked to contribute to this.

Event location

Let your network know you're going

Share this event to start conversations, invite colleagues, and connect before it begins.

about_us.editorial_intelligence_platform

Free
Register for free