Stride Analysis Patterns

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

僅含說明Security
AI 產生的概覽

指導使用 STRIDE 方法系統化地進行威脅建模,辨識系統設計中的安全威脅。

功能
此技能提供使用 STRIDE 方法進行威脅辨識的結構化流程。它說明六個 STRIDE 類別,將每個類別對應到其回答的安全問題及相應的控制族,並提供進行威脅建模工作坊的最佳實務建議。它也指向一個包含範本與範例的參考檔案。
適用情境
適用於開始威脅建模工作坊、分析現有系統架構或審查安全設計決策時。也適合撰寫安全文件、培訓團隊進行威脅辨識,以及合規或稽核準備工作。
執行需求
不需要指令碼或工具,僅為說明性內容。建議閱讀隨附的參考檔案 references/details.md 以取得範本與範例。

STRIDE Analysis Patterns

Systematic threat identification using the STRIDE methodology.

When to Use This Skill

  • Starting new threat modeling sessions
  • Analyzing existing system architecture
  • Reviewing security design decisions
  • Creating threat documentation
  • Training teams on threat identification
  • Compliance and audit preparation

Core Concepts

1. STRIDE Categories

S - Spoofing       → Authentication threatsT - Tampering      → Integrity threatsR - Repudiation    → Non-repudiation threatsI - Information    → Confidentiality threats    DisclosureD - Denial of      → Availability threats    ServiceE - Elevation of   → Authorization threats    Privilege

2. Threat Analysis Matrix

CategoryQuestionControl Family
SpoofingCan attacker pretend to be someone else?Authentication
TamperingCan attacker modify data in transit/rest?Integrity
RepudiationCan attacker deny actions?Logging/Audit
Info DisclosureCan attacker access unauthorized data?Encryption
DoSCan attacker disrupt availability?Rate limiting
ElevationCan attacker gain higher privileges?Authorization

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Involve stakeholders - Security, dev, and ops perspectives
  • Be systematic - Cover all STRIDE categories
  • Prioritize realistically - Focus on high-impact threats
  • Update regularly - Threat models are living documents
  • Use visual aids - DFDs help communication

Don'ts

  • Don't skip categories - Each reveals different threats
  • Don't assume security - Question every component
  • Don't work in isolation - Collaborative modeling is better
  • Don't ignore low-probability - High-impact threats matter
  • Don't stop at identification - Follow through with mitigations

來源與署名

來源:wshobson/agents位於plugins/security-scanning/skills/stride-analysis-patterns提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架