Threat Modeling

作者 bobmatnyc718070a7d622MIT77 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫2 個月前更新

Threat modeling workflow for software systems: scope, data flow diagrams, STRIDE analysis, risk scoring, and turning mitigations into backlog and tests. Use when designing new features, reviewing architecture changes, handling sensitive data, or hardening auth/payment/multi-tenant flows.

僅含說明Security
AI 產生的概覽

執行輕量級 STRIDE 威脅建模工作坊,並將辨識出的風險轉化為緩解措施、工單與測試。

功能
引導六步威脅建模流程:界定系統與資產範圍、繪製含信任邊界的資料流圖、對每個元素套用 STRIDE、評估影響與可能性,並將優先威脅轉化為緩解措施。產出包括資料流圖、威脅登錄表和緩解計畫,並落實為待辦工單、濫用情境測試和 PR 檢查清單項目。參考檔案提供工作坊議程、威脅目錄和可複製範本。
適用情境
適用於設計新功能、審查架構變更、處理敏感資料,或強化身分驗證、支付和多租戶流程的情境。適合希望在實作前或實作過程中進行結構化安全審查的團隊。
執行需求
無需工具或指令碼,僅提供說明和參考文件。此技能無法由使用者直接呼叫,且已停用模型呼叫。

Threat Modeling (STRIDE)

Workflow

  1. Scope — Identify the system boundary, assets (PII, credentials, payments), and availability requirements (SLO/SLA).
  2. Data Flow Diagram — Map actors, entry points, data stores, and external dependencies. Mark trust boundaries (public internet → edge → internal → database → third-party).
  3. STRIDE per element — For each element in the diagram, walk through all six STRIDE categories (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) and record threats.
  4. Risk score — Rate each threat by Impact (Low/Med/High) and Likelihood (Low/Med/High). Prioritize High-impact + Med/High-likelihood items first.
  5. Mitigate — Convert each prioritized threat into engineering tasks, verification tasks (tests, alerts), and operational controls (runbooks, access reviews).
  6. Tickets and tests — Create backlog items for mitigations and add abuse-case tests for critical flows. Add PR checklist items for ongoing verification.

Example: Threat Register Row

ElementSTRIDEThreatImpactLikelihoodMitigationOwnerStatus
API GatewaySpoofingStolen JWT reuse after session revocationHighMedShort-lived tokens (15 min TTL), refresh rotation, revocation list check on each requestSecurityOpen

This single row drives three artifacts: an engineering ticket (implement revocation-list middleware), a test (verify revoked token returns 401 within TTL window), and a PR checklist item (authz checks for new endpoints).

Validation Checkpoint

Before finalizing, verify completeness:

  • Every element in the data flow diagram has at least one STRIDE entry
  • All High-impact threats have an assigned owner and mitigation
  • Each mitigation maps to a backlog ticket or test case
  • Threat model doc includes assumptions and scope boundaries
  • PR checklist updated with new security requirements

Outputs (Definition of Done)

Produce a data flow diagram, a threat register, and a mitigation plan that becomes tickets and tests.

Load Next (References)

  • references/stride-workshop.md — step-by-step workshop agenda + DFD guidance
  • references/common-threats-and-mitigations.md — threat catalog with mitigations
  • references/templates.md — copy/paste templates for docs and tickets

來源與署名

來源:bobmatnyc/claude-mpm-skills位於universal/security/threat-modeling提交718070a

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架