
π Cybersecurity Β· Sequence
How a login with MFA works: password check, risk evaluation, a push or TOTP challenge and session issue.
Drawing diagramβ¦
MFA login sequence: the user enters username and password in the app. The identity provider checks the password, then a risk engine scores the login (device, IP reputation, location, impossible travel). For higher risk it sends a push notification with number matching to the authenticator app (or asks for a TOTP code). After approval, the identity provider issues tokens and logs the event to the SIEM.
sequenceDiagram actor U as User participant APP as Application participant IDP as Identity Provider participant RISK as Risk Engine participant AUTH as Authenticator App participant SIEM as SIEM U->>APP: Username and password APP->>IDP: Authenticate IDP->>IDP: Verify password hash IDP->>RISK: Score device, IP, location RISK-->>IDP: Medium risk IDP->>AUTH: Push with number match U->>AUTH: Approve with matching number AUTH-->>IDP: Approved IDP-->>APP: ID and access tokens IDP-)SIEM: Login event
A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.