PTA Professional Edition
PTA Professional Edition is a desktop software tool developed with the Practical Threat Analysis
calculative technology that
helps security analysts build practical threat
models and perform a quantitative risk analysis of their clients' systems . You are invited to download the PTA
Professional Edition trial version at the
Free Practical Threat Analysis
Download page . The following list details the product's
features:
Easy Threat Modeling
-
User friendly data entry
screens and a specialized threat builder tool. Defining of assets,
vulnerabilities, threats and countermeasures entities and composing threat
scenarios is done in minutes.
-
Additional entities such as
entry points and attacker types can be added to the model to make it more
comprehensive.
Model entities can be adapted
and customized to best fit the specific features of the analyzed system.
-
Built-in spell checking and
search capabilities.
-
PTA supplies full descriptions
of the practical steps of the threat analysis process. Well structured context sensitive
help is available at any step of the modeling.
-
Parts of the model can be
easily excluded from the analysis to enable quick intermediate results.
Quantitative Threat Analysis
-
The PTA quantitative method
produce practical recommendations for reducing overall system risk. The
method uses parameters such as threats probabilities, potential damages,
countermeasures costs and countermeasures mitigation levels.
-
The financial value of assets
and cost of countermeasures can be presented as a combination of fixed and
recurring values.
-
The risk-reduction
optimization algorithm produces a prioritized list of the countermeasures.
Combining the most cost-effective countermeasures will reduce the overall
system risk level to a minimum.
Read More:
http://www.ptatechnologies.com/PTAPro.htm
Predefined Security Entity Libraries
-
Predefined entities, such as
assets, vulnerabilities, threats and countermeasures, can be easily loaded
from plug-in entity libraries.
Each entity library suits a
specific platform, environment, application type and architecture. For
example Web applications, Linux/Microsoft, SQL/Oracle, banking, telecom and
healthcare. The PTA plug-in libraries mechanism is intended to facilitate
the transforming of security standards compliance knowledge and data into
effective mitigation actions. Read more on PTA plug-in libraries in
Common Assets, Vulnerabilities,
Countermeasures and Threats Libraries and visit the
PTA Professional Forum
for getting tips on how to convert standard security compliance
methodologies such as ISO 27001 and PCI DSS 1.1 to PTA threat models and use them as a dynamic baseline for
employing modern risk management system based on quantitative risk analysis.
-
Import entities from text
enables importing data of threat model entities from comma delimited text
files and partial automating of the threat analysis process, for example,
combine standard scanners outputs with the PTA calculative model. Read more
on Integrating PTA with
Nessus in the PTA Professional Forum.
-
Entity libraries can be
customized by the user and shared among several projects to save the burden
of re-entering common entities when building application-specific threat
models.
Flexible Threat Model Database
-
Threat models are stored in a
dynamic database that can be shared between analysts and developers. There
is no limit to the number of entities in the model. Model entities can be added,
removed or changed at any time without disrupting the threat analysis
process.
-
The model recovery feature
enables safe and easy roll back of changes. It also supports ‘what if’
research process that immediately updates the analysis outcome.
Read More:
http://www.ptatechnologies.com/PTAPro.htm
Rich Security Reporting and Audit Subsystem
-
The reporting subsystem
provides diverse views of threat model parameters and entities
interrelations. For example: vulnerabilities and their associated
countermeasures, threats and assets, entities details, risk and mitigation
statistics etc. For a description of the basic threat analysis outcomes see
List of Practical Threat Analysis
Results and Reports.
-
Reports are displayed in a
viewer equipped with wide paging, zoom and printing capabilities.
-
Reports can be exported to
common formats (such as text, HTML, Excel, and RTF) and sent as e-mail
attachments.
Read More:
http://www.ptatechnologies.com/PTAPro.htm
Security Knowledge Management
-
PTA professional edition can
manage and maintain numerous threat analysis projects.
-
Projects can share entities
and parameters loaded form common predefined entities libraries created by
experts.
-
Projects properties support
versions management and keywords qualifications.
-
A variety of documents
types (such as PDF, text, Word, Visio and Rational) can be associated with
each of the threat model entities. This allows management of additional
unstructured information and sharing of knowledge between collaborative
parties.
-
System risk status and
project’s "bottom lines" are continuously monitored based on the identified
threats and rate of countermeasures implementation.
-
Project history is displayed
and the analysis progress is monitored throughout the system's lifecycle.
You are invited to download and
install the PTA Professional Edition at the
Free Practical Threat Analysis
Download page - the PTA Help file that comes with the software provides
detailed and updated description of the tool's features. Visit the
PTA Professional Edition
Latest Updates page for more information on latest changes and product
versions history.
Read More:
http://www.ptatechnologies.com/PTAPro.htm
***
Download the PTA
Professional Edition Tool
Home
Page