Stride Analysis Patterns

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

仅含说明Security
AI 生成的概览

指导使用 STRIDE 方法系统化地开展威胁建模,识别系统设计中的安全威胁。

功能
该技能提供使用 STRIDE 方法进行威胁识别的结构化流程。它讲解六个 STRIDE 类别,将每个类别对应到其回答的安全问题及相应的控制族,并给出开展威胁建模会话的最佳实践建议。它还指向一个包含模板和示例的参考文件。
适用场景
适用于启动威胁建模会话、分析现有系统架构或评审安全设计决策时。也适合编写安全文档、培训团队进行威胁识别,以及合规或审计准备工作。
运行要求
无需脚本或工具,仅为说明性内容。建议阅读随附的参考文件 references/details.md 以获取模板和示例。

STRIDE Analysis Patterns

Systematic threat identification using the STRIDE methodology.

When to Use This Skill

  • Starting new threat modeling sessions
  • Analyzing existing system architecture
  • Reviewing security design decisions
  • Creating threat documentation
  • Training teams on threat identification
  • Compliance and audit preparation

Core Concepts

1. STRIDE Categories

S - Spoofing       → Authentication threatsT - Tampering      → Integrity threatsR - Repudiation    → Non-repudiation threatsI - Information    → Confidentiality threats    DisclosureD - Denial of      → Availability threats    ServiceE - Elevation of   → Authorization threats    Privilege

2. Threat Analysis Matrix

CategoryQuestionControl Family
SpoofingCan attacker pretend to be someone else?Authentication
TamperingCan attacker modify data in transit/rest?Integrity
RepudiationCan attacker deny actions?Logging/Audit
Info DisclosureCan attacker access unauthorized data?Encryption
DoSCan attacker disrupt availability?Rate limiting
ElevationCan attacker gain higher privileges?Authorization

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Involve stakeholders - Security, dev, and ops perspectives
  • Be systematic - Cover all STRIDE categories
  • Prioritize realistically - Focus on high-impact threats
  • Update regularly - Threat models are living documents
  • Use visual aids - DFDs help communication

Don'ts

  • Don't skip categories - Each reveals different threats
  • Don't assume security - Question every component
  • Don't work in isolation - Collaborative modeling is better
  • Don't ignore low-probability - High-impact threats matter
  • Don't stop at identification - Follow through with mitigations

来源与署名

来源:wshobson/agents位于plugins/security-scanning/skills/stride-analysis-patterns提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架