Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

STRIDE model

From Wikipedia, the free encyclopedia

STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) is a threat model for identifying computer security threats.[1]

Developed by Praerit Garg and Loren Kohnfelder at Microsoft,[2] it provides a mnemonic for security threats in six categories.[3] Each STRIDE category corresponds to a core principle of information security: Authenticity, Integrity, Non-repudiability, Confidentiality, Availability and Authorization.

See also

[edit]
  • Attack tree – another approach to security threat modeling, stemming from dependency analysis
  • DREAD – a classification system for security threats
  • OWASP – an organization devoted to improving web application security through education
  • CIA also known as AIC – another mnemonic for a security model to build security in IT systems

References

[edit]
  1. Morana, Marco; UcedaVelez, Tony (2011). Application threat modeling. Oxford: Wiley-Blackwell. p. 36. ISBN 978-0-470-50096-5.
  2. Guzman, Aaron; Gupta, Aditya (2017). IoT Penetration Testing Cookbook: Identify Vulnerabilities and Secure your Smart Devices. Packt Publishing. pp. 34–35. ISBN 978-1-78728-517-0.
  3. "The STRIDE Threat Model". Microsoft. Microsoft.
[edit]