field notes

defense · process

A threat model that fits on an index card

· 1 min read

AbstractFour questions from Shostack's framework, kept short enough that a team will actually answer them before shipping.

Contents

The four questions

  1. What are we building? Draw the data-flow diagram. If you cannot draw it, you do not understand it well enough to secure it.
  2. What can go wrong? Walk the diagram with STRIDE — Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
  3. What are we going to do about it? Each threat gets one of: mitigate, eliminate, transfer, or accept.
  4. Did we do a good job? Review the diagram against the shipped system.

Why it stays short

The failure mode of threat modeling is the 40-page document nobody reads. Keeping it to one diagram and one table per feature means it gets revisited when the design changes, which is the only time it is worth anything.

Element Trust boundary Top threat
Browser → API yes tampered requests
API → database no over-broad queries
API → third party yes data disclosure

Reference

  • Adam Shostack, Threat Modeling: Designing for Security.