Threat-model a system with STRIDE
Draw how data flows, find trust boundaries, and ask what can go wrong at each one.
- Use the four threat-modeling questions
- Find trust boundaries in a data-flow diagram
- Apply STRIDE to each part of a system
Threat modeling is thinking like an attacker before you build - when fixing a design flaw costs a whiteboard eraser, not an incident. The Threat Modeling Manifesto boils it down to four questions:
- What are we working on? - draw the system.
- What can go wrong? - list threats.
- What are we going to do about it? - choose mitigations.
- Did we do a good enough job? - review and repeat.
For step 1, teams draw a data-flow diagram: external entities (users, other services), processes (your code), data stores (databases, files) and the data flows between them. Then they mark trust boundaries - lines where data passes between areas with different levels of trust, like the internet and your server. Most attacks happen where data crosses a boundary, so that’s where you validate input, authenticate and authorize.
STRIDE (created at Microsoft) is a checklist for step 2. Each letter is a threat and the property it violates:
| Threat | Violates | Example |
|---|---|---|
| Spoofing | Authentication | logging in with a stolen password |
| Tampering | Integrity | changing the price in a request |
| Repudiation | Non-repudiation | “I never made that transfer” - and no logs to prove otherwise |
| Information disclosure | Confidentiality | an error page showing database details |
| Denial of service | Availability | flooding the login endpoint |
| Elevation of privilege | Authorization | a normal user reaching the admin panel |
Try it
Name that STRIDE threat
You’re reviewing a food-delivery app. Sort each threat into its STRIDE category.
“A customer edits the request to set the order total to $0.01”
“An attacker signs in as a courier using a password from another site’s breach”
“A restaurant denies changing a menu price because nothing records who changed it”
“The order API returns other customers’ home addresses”
“Bots place thousands of fake orders, so real customers can’t check out”
“A courier account calls the admin refund endpoint successfully”
A handy shortcut, STRIDE-per-element, says which threats usually apply to each kind of element: external entities can be spoofed or deny their actions (S, R); processes face all six; data stores and data flows mainly face tampering, information disclosure and denial of service (T, I, D).
Key takeaways
Ask: what are we working on, what can go wrong, what will we do, did we do a good job?
Draw data flows and mark trust boundaries; attacks cluster where data crosses them.
STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
Lesson quiz
6 questions · pass with 5 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Practice: write Python
Write Python in the editor and run it against sample inputs. Python runs locally in your browser using a WebAssembly runtime.
STRIDE per element
Each input line is element name TYPE, where the last word is external, process, store or flow (names may contain spaces).
Print name: threats with the full threat names, comma-separated, in STRIDE order: external → Spoofing, Repudiation; process → all six; store and flow → Tampering, Information disclosure, Denial of service.
- A small shop
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Find trust-boundary crossings
The first line is JSON mapping each component to its trust zone. Each following line is a flow: source target label (the label may contain spaces).
For every flow between different zones, print source -> target: label (zone -> zone). Finish with N of M flows cross a trust boundary.
- Web shop
Python runs in a sandboxed browser worker with a 60 second time limit. Its runtime loads from the Pyodide CDN; your code stays in this browser.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…