Stride Threat Modeling

securityskills/skills/threat-modeling/stride-threat-modeling

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a无许可证收录于 2026年10月9日更新于 2026年10月9日

Run a STRIDE-based threat modeling workshop — diagram the system, enumerate threats per element, rank them, and drive mitigations into the backlog. Use during design reviews and new feature planning.

仅含说明Security
AI 生成的概览

开展基于 STRIDE 的威胁建模工作坊:绘制系统图、枚举并排序威胁、规划缓解措施。

功能
该技能指导一场结构化的 STRIDE 威胁建模工作坊。它依次完成:用进程、数据存储、数据流、外部参与者和信任边界为系统建模;按 STRIDE 类别逐元素枚举威胁;依据影响与可能性排序;并为每个威胁选择缓解策略。产出包括带信任边界的系统图、元素×STRIDE 威胁矩阵、排序后的风险登记表,以及映射到待办工单的缓解措施。
适用场景
适用于设计评审和新功能规划,或需要对系统架构进行系统性安全威胁评估时。架构发生变化(如新增外部依赖、信任边界或数据类别)后重新评审模型时也适用。
运行要求
无需脚本或特殊工具,仅为说明性技能。需要待分析的系统或设计,以及记录系统图、威胁矩阵、风险登记表和工单的载体。

STRIDE Threat Modeling

Threat model a system in a structured workshop format.

1. Model the System

Draw the diagram: processes, data stores, data flows, external actors, and trust boundaries (dashed lines where privilege/context changes).

  • Every element numbered; technologies noted on processes/stores
  • Include the boring parts: auth flows, async jobs, admin tooling, backups

2. Enumerate with STRIDE

For each element, apply the applicable categories:

CategoryApplies ToQuestion
SpoofingProcesses, actorsCan someone pretend to be this? (auth)
TamperingFlows, storesCan data be modified in transit/at rest? (integrity)
RepudiationProcessesCan actions be denied? (logging/audit)
Information disclosureFlows, storesCan data leak to unauthorized parties? (confidentiality)
Denial of serviceProcesses, flowsCan this be exhausted or crashed? (availability)
Elevation of privilegeProcessesCan rights be gained? (authz)

Work systematically: element × category grid so nothing is skipped.

3. Rank

Score each threat by impact (worst realistic outcome) × likelihood (attack complexity, exposure). Prioritize: unauthenticated remote > authenticated remote > local > physical.

4. Mitigate

For each accepted threat, pick a strategy: reduce (control), transfer, accept (documented, with owner), or avoid (design change). Map mitigations to concrete backlog tickets with acceptance criteria.

5. Validate

  • Review the model when the architecture changes (trigger: new external dependency, new trust boundary, new data class)
  • Retro: incidents found in prod vs threats previously modeled — feed misses back into the method

Output

System diagram with trust boundaries, element × STRIDE threat grid, ranked risk register, and mitigations as tracked tickets.

来源与署名

来源:securityskills/skills位于threat-modeling/stride-threat-modeling提交b2b6b52

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架