Threat modeling concept page (STRIDE methodology). DFD with trust boundaries (Internet -> DMZ -> App tier -> Data tier). Three scenarios: STRIDE walkthrough on login flow (Spoofing/Tampering/Repudiation/Information disclosure/DoS/Elevation), STRIDE on file upload feature, LINDDUN privacy threat model for GDPR PII flow. Includes ADR on lightweight vs formal SDLC threat modeling.
Threat modeling is a repeatable risk-analysis activity grounded in the actual system, assets, data flows, trust boundaries, actors, and assumptions. STRIDE elicits security threats; LINDDUN elicits privacy threats. Neither acronym ranks risk or replaces validation.
| Component | Responsibility |
|---|---|
external-user | External User |
browser | Browser Process |
gateway | Public Trust Boundary |
service | Application Service |
database | Sensitive Data Store |
third-party | Third-Party Processor |
attacker | Threat Actor |
threat-register | Threat and Assumption Register |
security-controls | Security and Privacy Requirements |
verification-tests | Abuse, Failure, and Control Tests |
privacy-review | LINDDUN Privacy Review |
Topology edges represent authenticated or otherwise explicit communication paths. Responses reuse those physical paths in reverse; no response-only or bypass edges are added.
model-the-system — Model assets, flows, stores, actors, and trust boundariesThe team first agrees on what exists and which assumptions apply; an acronym applied to an inaccurate diagram produces false confidence.
stride-spoofing — STRIDE: spoofingAsk how an actor, service, device, or message source can be impersonated at every trust boundary and bind mitigations to verifier behavior.
stride-tampering-repudiation — STRIDE: tampering and repudiationIntegrity and accountability are separate: prevent or detect unauthorized modification and retain trustworthy evidence for disputed security-relevant actions.
stride-disclosure — STRIDE: information disclosureTrace sensitive data through process memory, logs, stores, backups, networks, errors, and third parties rather than checking only the primary database.
stride-dos-elevation — STRIDE: denial of service and elevation of privilegeAvailability budgets and privilege boundaries are explicit; a valid account or internal network path does not justify unlimited resources or higher authority.
linddun-privacy — LINDDUN privacy threat elicitationPrivacy analysis examines Linking, Identifying, Non-repudiation, Detecting, Disclosure, Unawareness, and Non-compliance across data interactions.
risk-response — Prioritize and respond to concrete threatsSTRIDE and LINDDUN elicit threats; likelihood, impact, exposure, business context, and evidence rank them. Each threat is mitigated, eliminated, transferred, or explicitly accepted.
architecture-change — Revisit the model when the system changesNew data, dependencies, trust boundaries, identity flows, or failure modes invalidate prior assumptions and trigger focused re-analysis.
Введите числа или выберите пресет