| STRIDE Threat | STRIDE tree node | Description | Key mitigation actions | Metrics for continuous monitoring | Monitored components |
|---|---|---|---|---|---|
| Spoofing External Entities (S_e) | Transit | An attacker copies an authenticator from a non-encrypted channel or tamper with the connection. | Use standard authentication protocols, instead of your own. Use strong encryption and authentication. | Continuous authenticator detector warnings (comparing data in the channel with user database) | Network/Communication Channels |
| Obtain credential from storage at a 3rd party | Reuse of passwords is common. 3rd parties may leak passwords your customers use. | Avoid static passwords. Avoid using e-mail addresses as usernames. Detect brute-force attempts, or increase in successful logins from new locations. | Monitoring of number of brute-force attempts or successful logins from a new location or IP. Continuous user behavior analysis. | Network/Communication Channels | |
| Predictable credentials | Predictable usernames or a poor random generator for passwords. | If assigning passwords, use strong randomness. | Detect usernames sent matching actual user names in your internal databases. | Database/Data store | |
| STRIDE Threat | STRIDE tree node | Description | Key mitigation actions | Metrics for continuous monitoring | Monitored components |
| Spoofing External Entities (S_e) | Transit | An attacker copies an authenticator from a non-encrypted channel or tamper with the connection. | Use standard authentication protocols, instead of your own. Use strong encryption and authentication. | Continuous authenticator detector warnings (comparing data in the channel with user database) | Network/Communication Channels |
| Obtain credential from storage at a 3rd party | Reuse of passwords is common. 3rd parties may leak passwords your customers use. | Avoid static passwords. Avoid using e-mail addresses as usernames. Detect brute-force attempts, or increase in successful logins from new locations. | Monitoring of number of brute-force attempts or successful logins from a new location or IP. Continuous user behavior analysis. | Network/Communication Channels | |
| Predictable credentials | Predictable usernames or a poor random generator for passwords. | If assigning passwords, use strong randomness. | Detect usernames sent matching actual user names in your internal databases. | Database/Data store | |
| Information Disclosure at Data Flow (ID_df) | No or Weak Confidentiality (Observing a Message Structure) | Content of a message not protected or weakly protected. | Cryptographic. Use available message protection add-ons or tunneling. | Continuous monitoring message content readability. Can we detect some content structure or detect words with meaning? | Network/Communication Channels |
| No or Weak Confidentiality (Observing a Channel) | No or weak protection of channel contents. Data about the messages can be revealing. | Encrypt the channel. Tunneling. | Continuous channel monitoring content readability. Can we get some structure of the content? Or detect words with meaning? | Network/Communication Channels | |
| Tampering at Data Store (T_ds) | Bypassing protection rules because of no or weak protection | ACLs, permissions, policies, etc allow people to alter data without a clear justification. | Ensure data is created with appropriate permissions. Change permissions. | Random data editor reporting the number of successful attempts to change data with no or low privileges. | Database/Data store |
| Information Disclosure of a Process (ID_p) | Timing | Code time execution can reveal confidential information. | Design for cryptography to take constant time. | Monitoring execution time and control variability. | Software components to solve tasks requiring secrecy. |
| STRIDE Threat | STRIDE tree node | Description | Key mitigation actions | Metrics for continuous monitoring | Monitored components |
|---|---|---|---|---|---|
| Spoofing External Entities (S_e) | Transit | An attacker copies an authenticator from a non-encrypted channel or tamper with the connection. | Use standard authentication protocols, instead of your own. Use strong encryption and authentication. | Continuous authenticator detector warnings (comparing data in the channel with user database) | Network/Communication Channels |
| Obtain credential from storage at a 3rd party | Reuse of passwords is common. 3rd parties may leak passwords your customers use. | Avoid static passwords. Avoid using e-mail addresses as usernames. Detect brute-force attempts, or increase in successful logins from new locations. | Monitoring of number of brute-force attempts or successful logins from a new location or IP. Continuous user behavior analysis. | Network/Communication Channels | |
| Predictable credentials | Predictable usernames or a poor random generator for passwords. | If assigning passwords, use strong randomness. | Detect usernames sent matching actual user names in your internal databases. | Database/Data store | |
| STRIDE Threat | STRIDE tree node | Description | Key mitigation actions | Metrics for continuous monitoring | Monitored components |
| Spoofing External Entities (S_e) | Transit | An attacker copies an authenticator from a non-encrypted channel or tamper with the connection. | Use standard authentication protocols, instead of your own. Use strong encryption and authentication. | Continuous authenticator detector warnings (comparing data in the channel with user database) | Network/Communication Channels |
| Obtain credential from storage at a 3rd party | Reuse of passwords is common. 3rd parties may leak passwords your customers use. | Avoid static passwords. Avoid using e-mail addresses as usernames. Detect brute-force attempts, or increase in successful logins from new locations. | Monitoring of number of brute-force attempts or successful logins from a new location or IP. Continuous user behavior analysis. | Network/Communication Channels | |
| Predictable credentials | Predictable usernames or a poor random generator for passwords. | If assigning passwords, use strong randomness. | Detect usernames sent matching actual user names in your internal databases. | Database/Data store | |
| Information Disclosure at Data Flow (ID_df) | No or Weak Confidentiality (Observing a Message Structure) | Content of a message not protected or weakly protected. | Cryptographic. Use available message protection add-ons or tunneling. | Continuous monitoring message content readability. Can we detect some content structure or detect words with meaning? | Network/Communication Channels |
| No or Weak Confidentiality (Observing a Channel) | No or weak protection of channel contents. Data about the messages can be revealing. | Encrypt the channel. Tunneling. | Continuous channel monitoring content readability. Can we get some structure of the content? Or detect words with meaning? | Network/Communication Channels | |
| Tampering at Data Store (T_ds) | Bypassing protection rules because of no or weak protection | ACLs, permissions, policies, etc allow people to alter data without a clear justification. | Ensure data is created with appropriate permissions. Change permissions. | Random data editor reporting the number of successful attempts to change data with no or low privileges. | Database/Data store |
| Information Disclosure of a Process (ID_p) | Timing | Code time execution can reveal confidential information. | Design for cryptography to take constant time. | Monitoring execution time and control variability. | Software components to solve tasks requiring secrecy. |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.