Stride Threat Modeling

securityskills/skills/threat-modeling/stride-threat-modeling

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Run a STRIDE-based threat modeling workshop — diagram the system, enumerate threats per element, rank them, and drive mitigations into the backlog. Use during design reviews and new feature planning.

僅含說明Security
AI 產生的概覽

進行以 STRIDE 為基礎的威脅建模工作坊:繪製系統圖、列舉並排序威脅、規劃緩解措施。

功能
此技能引導一場結構化的 STRIDE 威脅建模工作坊。流程依序為:以處理程序、資料存放區、資料流、外部參與者和信任邊界為系統建模;依 STRIDE 類別逐元素列舉威脅;依影響與可能性排序;並為每項威脅選擇緩解策略。產出包括含信任邊界的系統圖、元素×STRIDE 威脅矩陣、排序後的風險登錄表,以及對應到待辦工單的緩解措施。
適用情境
適用於設計審查與新功能規劃,或需要對系統架構進行系統性安全威脅評估時。架構變更後(例如新增外部相依性、信任邊界或資料類別)重新檢視模型時也適用。
執行需求
不需要指令碼或特殊工具,僅為說明性技能。需要待分析的系統或設計,以及記錄系統圖、威脅矩陣、風險登錄表和工單的載體。

STRIDE Threat Modeling

Threat model a system in a structured workshop format.

1. Model the System

Draw the diagram: processes, data stores, data flows, external actors, and trust boundaries (dashed lines where privilege/context changes).

  • Every element numbered; technologies noted on processes/stores
  • Include the boring parts: auth flows, async jobs, admin tooling, backups

2. Enumerate with STRIDE

For each element, apply the applicable categories:

CategoryApplies ToQuestion
SpoofingProcesses, actorsCan someone pretend to be this? (auth)
TamperingFlows, storesCan data be modified in transit/at rest? (integrity)
RepudiationProcessesCan actions be denied? (logging/audit)
Information disclosureFlows, storesCan data leak to unauthorized parties? (confidentiality)
Denial of serviceProcesses, flowsCan this be exhausted or crashed? (availability)
Elevation of privilegeProcessesCan rights be gained? (authz)

Work systematically: element × category grid so nothing is skipped.

3. Rank

Score each threat by impact (worst realistic outcome) × likelihood (attack complexity, exposure). Prioritize: unauthenticated remote > authenticated remote > local > physical.

4. Mitigate

For each accepted threat, pick a strategy: reduce (control), transfer, accept (documented, with owner), or avoid (design change). Map mitigations to concrete backlog tickets with acceptance criteria.

5. Validate

  • Review the model when the architecture changes (trigger: new external dependency, new trust boundary, new data class)
  • Retro: incidents found in prod vs threats previously modeled — feed misses back into the method

Output

System diagram with trust boundaries, element × STRIDE threat grid, ranked risk register, and mitigations as tracked tickets.

來源與署名

來源:securityskills/skills位於threat-modeling/stride-threat-modeling提交b2b6b52

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架