Distinguished Seminar: Adventures in threat modeling with Nancy Mead

April 16, 2018

12:00 p.m. - 1:00 p.m. ET

DEC, CIC Building


This talk will focus on the SEI’s recent threat modeling research.  After briefly revisiting our initial 2015-16 research project examining STRIDE, Security Cards, and Persona non Grata, a new hybrid threat modeling method (hTMM) will be described.  The methods used on the initial research project and the hTMM have been used to perform threat modeling of small case studies, and the hTMM is now ready for use on larger projects.  The threat modeling work has also been documented in an SEI report, and incorporated into an SEI certificate program on cyber security and software assurance.  A current CMU student project on machine learning may further inform the research work.


Mead, NancyNancy R. Mead is a Fellow and Principal Researcher at the Software Engineering Institute (SEI).  Mead is an Adjunct Professor of Software Engineering at Carnegie Mellon University.  She is currently involved in the study of security requirements engineering and the development of software assurance curricula.  She also served as director of software engineering education for the SEI from 1991 to 1994. Her research interests are in the areas of software security, software requirements engineering, and software architectures. 

Prior to joining the SEI, Mead was a senior technical staff member at IBM Federal Systems, where she spent most of her career in the development and management of large real-time systems.  She also worked in IBM's software engineering technology area and managed IBM Federal Systems' software engineering education department.  She has developed and taught numerous courses on software engineering topics, both at universities and in professional education courses.

Mead authored more than 150 publications and invited presentations. She is a Fellow of the Institute of Electrical and Electronic Engineers, Inc. (IEEE) and the IEEE Computer Society, and is a Distinguished Educator of the Association of Computing Machinery. She received the 2015 Distinguished Education Award from the IEEE Computer Society Technical Council on Software Engineering. The Nancy Mead Award for Excellence in Software Engineering Education is named for her and has been awarded since 2010, with Mary Shaw as the first recipient.

Mead received her PhD in mathematics from the Polytechnic Institute of New York, and received a BA and an MS in mathematics from New York University.