| name | stride-analysis-patterns |
| description | Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation. |
STRIDE Analysis Patterns
Systematic threat identification using the STRIDE methodology.
When to Use This Skill
- Starting new threat modeling sessions
- Analyzing existing system architecture
- Reviewing security design decisions
- Creating threat documentation
- Training teams on threat identification
- Compliance and audit preparation
Core Concepts
1. STRIDE Categories
S - Spoofing → Authentication threats
T - Tampering → Integrity threats
R - Repudiation → Non-repudiation threats
I - Information → Confidentiality threats
Disclosure
D - Denial of → Availability threats
Service
E - Elevation of → Authorization threats
Privilege
2. Threat Analysis Matrix
| Category | Question | Control Family |
|---|
| Spoofing | Can attacker pretend to be someone else? | Authentication |
| Tampering | Can attacker modify data in transit/rest? | Integrity |
| Repudiation | Can attacker deny actions? | Logging/Audit |
| Info Disclosure | Can attacker access unauthorized data? | Encryption |
| DoS | Can attacker disrupt availability? | Rate limiting |
| Elevation | Can attacker gain higher privileges? | Authorization |
Templates
Template 1: STRIDE Threat Model Document
# Threat Model: [System Name]
## 1. System Overview
### 1.1 Description
[Brief description of the system and its purpose]
### 1.2 Data Flow Diagram
[User] --> [Web App] --> [API Gateway] --> [Backend Services]
|
v
[Database]
### 1.3 Trust Boundaries
- **External Boundary**: Internet to DMZ
- **Internal Boundary**: DMZ to Internal Network
- **Data Boundary**: Application to Database
## 2. Assets
| Asset | Sensitivity | Description |
|-------|-------------|-------------|
| User Credentials | High | Authentication tokens, passwords |
| Personal Data | High | PII, financial information |
| Session Data | Medium | Active user sessions |
| Application Logs | Medium | System activity records |
| Configuration | High | System settings, secrets |
## 3. STRIDE Analysis
### 3.1 Spoofing Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| S1 | Session hijacking | User sessions | High | Medium |
| S2 | Token forgery | JWT tokens | High | Low |
| S3 | Credential stuffing | Login endpoint | High | High |
**Mitigations:**
- [ ] Implement MFA
- [ ] Use secure session management
- [ ] Implement account lockout policies
### 3.2 Tampering Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| T1 | SQL injection | Database queries | Critical | Medium |
| T2 | Parameter manipulation | API requests | High | High |
| T3 | File upload abuse | File storage | High | Medium |
**Mitigations:**
- [ ] Input validation on all endpoints
- [ ] Parameterized queries
- [ ] File type validation
### 3.3 Repudiation Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| R1 | Transaction denial | Financial ops | High | Medium |
| R2 | Access log tampering | Audit logs | Medium | Low |
| R3 | Action attribution | User actions | Medium | Medium |
**Mitigations:**
- [ ] Comprehensive audit logging
- [ ] Log integrity protection
- [ ] Digital signatures for critical actions
### 3.4 Information Disclosure Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| I1 | Data breach | User PII | Critical | Medium |
| I2 | Error message leakage | System info | Low | High |
| I3 | Insecure transmission | Network traffic | High | Medium |
**Mitigations:**
- [ ] Encryption at rest and in transit
- [ ] Sanitize error messages
- [ ] Implement TLS 1.3
### 3.5 Denial of Service Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| D1 | Resource exhaustion | API servers | High | High |
| D2 | Database overload | Database | Critical | Medium |
| D3 | Bandwidth saturation | Network | High | Medium |
**Mitigations:**
- [ ] Rate limiting
- [ ] Auto-scaling
- [ ] DDoS protection
### 3.6 Elevation of Privilege Threats
| ID | Threat | Target | Impact | Likelihood |
|----|--------|--------|--------|------------|
| E1 | IDOR vulnerabilities | User resources | High | High |
| E2 | Role manipulation | Admin access | Critical | Low |
| E3 | JWT claim tampering | Authorization | High | Medium |
**Mitigations:**
- [ ] Proper authorization checks
- [ ] Principle of least privilege
- [ ] Server-side role validation
## 4. Risk Assessment
### 4.1 Risk Matrix
IMPACT
Low Med High Crit
Low 1 2 3 4
L Med 2 4 6 8
I High 3 6 9 12
K Crit 4 8 12 16
### 4.2 Prioritized Risks
| Rank | Threat | Risk Score | Priority |
|------|--------|------------|----------|
| 1 | SQL Injection (T1) | 12 | Critical |
| 2 | IDOR (E1) | 9 | High |
| 3 | Credential Stuffing (S3) | 9 | High |
| 4 | Data Breach (I1) | 8 | High |
## 5. Recommendations
### Immediate Actions
1. Implement input validation framework
2. Add rate limiting to authentication endpoints
3. Enable comprehensive audit logging
### Short-term (30 days)
1. Deploy WAF with OWASP ruleset
2. Implement MFA for sensitive operations
3. Encrypt all PII at rest
### Long-term (90 days)
1. Security awareness training
2. Penetration testing
3. Bug bounty program
Template 2: STRIDE Analysis Code
from dataclasses import dataclass, field
from enum import Enum
from typing import List, Dict, Optional
import json
class StrideCategory(Enum):
SPOOFING = "S"
TAMPERING = "T"
REPUDIATION = "R"
INFORMATION_DISCLOSURE = "I"
DENIAL_OF_SERVICE = "D"
ELEVATION_OF_PRIVILEGE = "E"
class Impact(Enum):
LOW = 1
MEDIUM = 2
HIGH = 3
CRITICAL = 4
class Likelihood(Enum):
LOW = 1
MEDIUM = 2
HIGH = 3
CRITICAL = 4
@dataclass
class Threat:
id: str
category: StrideCategory
title: str
description: str
target: str
impact: Impact
likelihood: Likelihood
mitigations: List[str] = field(default_factory=list)
status: str = "open"
@property
def risk_score() -> :
.impact.value * .likelihood.value
() -> :
score = .risk_score
score >= :
score >= :
score >= :
:
name:
sensitivity:
description:
data_classification:
:
name:
description:
from_zone:
to_zone:
:
name:
version:
description:
assets: [Asset] = field(default_factory=)
boundaries: [TrustBoundary] = field(default_factory=)
threats: [Threat] = field(default_factory=)
() -> :
.threats.append(threat)
() -> [Threat]:
[t t .threats t.category == category]
() -> [Threat]:
[t t .threats t.risk_level (, )]
() -> :
{
: {
: .name,
: .version,
: (.threats),
: ([t t .threats t.risk_level == ]),
: ([t t .threats t.risk_level == ]),
},
: {
cat.name: (.get_threats_by_category(cat))
cat StrideCategory
},
: [
{
: t.,
: t.title,
: t.risk_score,
: t.risk_level
}
t (.threats, key= x: x.risk_score, reverse=)[:]
]
}
:
STRIDE_QUESTIONS = {
StrideCategory.SPOOFING: [
,
,
,
,
],
StrideCategory.TAMPERING: [
,
,
,
,
],
StrideCategory.REPUDIATION: [
,
,
,
,
],
StrideCategory.INFORMATION_DISCLOSURE: [
,
,
,
,
],
StrideCategory.DENIAL_OF_SERVICE: [
,
,
,
,
],
StrideCategory.ELEVATION_OF_PRIVILEGE: [
,
,
,
,
],
}
() -> []:
questionnaire = []
category, questions .STRIDE_QUESTIONS.items():
q questions:
questionnaire.append({
: component,
: category.name,
: q,
: ,
:
})
questionnaire
() -> []:
mitigations = {
StrideCategory.SPOOFING: [
,
,
,
,
,
],
StrideCategory.TAMPERING: [
,
,
,
,
,
],
StrideCategory.REPUDIATION: [
,
,
,
,
,
],
StrideCategory.INFORMATION_DISCLOSURE: [
,
,
,
,
,
],
StrideCategory.DENIAL_OF_SERVICE: [
,
,
,
,
,
],
StrideCategory.ELEVATION_OF_PRIVILEGE: [
,
,
,
,
,
],
}
mitigations.get(category, [])
Template 3: Data Flow Diagram Analysis
from dataclasses import dataclass
from typing import List, Set, Tuple
from enum import Enum
class ElementType(Enum):
EXTERNAL_ENTITY = "external"
PROCESS = "process"
DATA_STORE = "datastore"
DATA_FLOW = "dataflow"
@dataclass
class DFDElement:
id: str
name: str
type: ElementType
trust_level: int
description: str = ""
@dataclass
class DataFlow:
id: str
name: str
source: str
destination: str
data_type: str
protocol: str
encrypted: bool = False
class DFDAnalyzer:
"""Analyze Data Flow Diagrams for STRIDE threats."""
def __init__(self):
self.elements: Dict[str, DFDElement] = {}
self.flows: List[DataFlow] = []
() -> :
.elements[element.] = element
() -> :
.flows.append(flow)
() -> [[DataFlow, ]]:
crossings = []
flow .flows:
source = .elements.get(flow.source)
dest = .elements.get(flow.destination)
source dest source.trust_level != dest.trust_level:
trust_diff = (source.trust_level - dest.trust_level)
crossings.append((flow, trust_diff))
(crossings, key= x: x[], reverse=)
() -> [, [StrideCategory]]:
threat_mapping = {
ElementType.EXTERNAL_ENTITY: [
StrideCategory.SPOOFING,
StrideCategory.REPUDIATION,
],
ElementType.PROCESS: [
StrideCategory.SPOOFING,
StrideCategory.TAMPERING,
StrideCategory.REPUDIATION,
StrideCategory.INFORMATION_DISCLOSURE,
StrideCategory.DENIAL_OF_SERVICE,
StrideCategory.ELEVATION_OF_PRIVILEGE,
],
ElementType.DATA_STORE: [
StrideCategory.TAMPERING,
StrideCategory.REPUDIATION,
StrideCategory.INFORMATION_DISCLOSURE,
StrideCategory.DENIAL_OF_SERVICE,
],
ElementType.DATA_FLOW: [
StrideCategory.TAMPERING,
StrideCategory.INFORMATION_DISCLOSURE,
StrideCategory.DENIAL_OF_SERVICE,
],
}
result = {}
elem_id, elem .elements.items():
result[elem_id] = threat_mapping.get(elem., [])
result
() -> [DataFlow]:
risky_flows = []
flow .flows:
flow.encrypted:
source = .elements.get(flow.source)
dest = .elements.get(flow.destination)
source dest source.trust_level != dest.trust_level:
risky_flows.append(flow)
risky_flows
() -> []:
threats = []
element_threats = .identify_threats_per_element()
elem_id, categories element_threats.items():
elem = .elements[elem_id]
category categories:
threats.append({
: elem_id,
: elem.name,
: elem..value,
: category.name,
: ,
: elem.trust_level
})
threats
Template 4: STRIDE per Interaction
from typing import List, Dict, Optional
from dataclasses import dataclass
@dataclass
class Interaction:
"""Represents an interaction between two components."""
id: str
source: str
target: str
action: str
data: str
protocol: str
class StridePerInteraction:
"""Apply STRIDE to each interaction in the system."""
INTERACTION_THREATS = {
("external", "process"): {
"S": "External entity spoofing identity to process",
"T": "Tampering with data sent to process",
"R": "External entity denying sending data",
"I": "Data exposure during transmission",
"D": "Flooding process with requests",
"E": "Exploiting process to gain privileges",
},
("process", "datastore"): {
"T": "Process tampering with stored data",
"R": "Process denying data modifications",
"I": "Unauthorized data access by process",
"D": ,
},
(, ): {
: ,
: ,
: ,
: ,
: ,
},
}
() -> []:
threats = []
key = (source_type, target_type)
applicable_threats = .INTERACTION_THREATS.get(key, {})
stride_code, description applicable_threats.items():
threats.append({
: interaction.,
: interaction.source,
: interaction.target,
: stride_code,
: description,
: ,
})
threats
() -> []:
all_threats = []
interaction interactions:
source_type = element_types.get(interaction.source, )
target_type = element_types.get(interaction.target, )
threats = .analyze_interaction(
interaction, source_type, target_type
)
all_threats.extend(threats)
all_threats
Best Practices
Do's
- Involve stakeholders - Security, dev, and ops perspectives
- Be systematic - Cover all STRIDE categories
- Prioritize realistically - Focus on high-impact threats
- Update regularly - Threat models are living documents
- Use visual aids - DFDs help communication
Don'ts
- Don't skip categories - Each reveals different threats
- Don't assume security - Question every component
- Don't work in isolation - Collaborative modeling is better
- Don't ignore low-probability - High-impact threats matter
- Don't stop at identification - Follow through with mitigations
Resources