Loading
0x10Lesson 2 of 13

Threat-model a system with STRIDE

Draw how data flows, find trust boundaries, and ask what can go wrong at each one.

22 min 6-question quiz 2 code exercises
By the end of this lesson you can
  • Use the four threat-modeling questions
  • Find trust boundaries in a data-flow diagram
  • Apply STRIDE to each part of a system

Threat modeling is thinking like an attacker before you build - when fixing a design flaw costs a whiteboard eraser, not an incident. The Threat Modeling Manifesto boils it down to four questions:

  1. What are we working on? - draw the system.
  2. What can go wrong? - list threats.
  3. What are we going to do about it? - choose mitigations.
  4. Did we do a good enough job? - review and repeat.

For step 1, teams draw a data-flow diagram: external entities (users, other services), processes (your code), data stores (databases, files) and the data flows between them. Then they mark trust boundaries - lines where data passes between areas with different levels of trust, like the internet and your server. Most attacks happen where data crosses a boundary, so that’s where you validate input, authenticate and authorize.

STRIDE (created at Microsoft) is a checklist for step 2. Each letter is a threat and the property it violates:

ThreatViolatesExample
SpoofingAuthenticationlogging in with a stolen password
TamperingIntegritychanging the price in a request
RepudiationNon-repudiation“I never made that transfer” - and no logs to prove otherwise
Information disclosureConfidentialityan error page showing database details
Denial of serviceAvailabilityflooding the login endpoint
Elevation of privilegeAuthorizationa normal user reaching the admin panel

Try it

Name that STRIDE threat

You’re reviewing a food-delivery app. Sort each threat into its STRIDE category.

0 of 6 sortedScore 0/0
  • “A customer edits the request to set the order total to $0.01”

  • “An attacker signs in as a courier using a password from another site’s breach”

  • “A restaurant denies changing a menu price because nothing records who changed it”

  • “The order API returns other customers’ home addresses”

  • “Bots place thousands of fake orders, so real customers can’t check out”

  • “A courier account calls the admin refund endpoint successfully”

A handy shortcut, STRIDE-per-element, says which threats usually apply to each kind of element: external entities can be spoofed or deny their actions (S, R); processes face all six; data stores and data flows mainly face tampering, information disclosure and denial of service (T, I, D).

Key takeaways

  • Ask: what are we working on, what can go wrong, what will we do, did we do a good job?

  • Draw data flows and mark trust boundaries; attacks cluster where data crosses them.

  • STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

Lesson quiz

6 questions · pass with 5 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Practice: write Python

Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.

Exercise 1

STRIDE per element

+25 XP

Each input line is element name TYPE, where the last word is external, process, store or flow (names may contain spaces).

Print name: threats with the full threat names, comma-separated, in STRIDE order: external → Spoofing, Repudiation; process → all six; store and flow → Tampering, Information disclosure, Denial of service.

  • A small shop
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Exercise 2

Find trust-boundary crossings

+25 XP

The first line is JSON mapping each component to its trust zone. Each following line is a flow: source target label (the label may contain spaces).

For every flow between different zones, print source -> target: label (zone -> zone). Finish with N of M flows cross a trust boundary.

  • Web shop
main.py
Loading editor…

Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Did you like the lesson? 😆👍
Consider a donation to support our work: