What is Threat Modeling?
Threat modeling is a structured process to identify potential security threats and vulnerabilities, quantify their seriousness, and prioritize mitigations.
The STRIDE Methodology
The most common framework is Microsoft's STRIDE model:
Spoofing identity: Pretending to be someone else.
Tampering with data: Unauthorized modification.
Repudiation: Claiming you didn't do an action.
Information disclosure: Leaking data.
Denial of service: Exhausting resources.
Elevation of privilege: Gaining unauthorized administrative control.
Four Key Questions
Every threat modeling exercise must answer:
1. What are we building?
2. What can go wrong?
3. What are we going to do about it?
4. Did we do a good job?Devon is a security engineer and former software engineer passionate about DevSecOps.