
π Cybersecurity Β· Mindmap
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.
Drawing diagramβ¦
Mindmap of a STRIDE threat model for a web app: Spoofing (stolen passwords, session hijack; MFA, secure cookies), Tampering (API parameter changes, SQL injection; validation, parameterised queries), Repudiation (users deny actions; audit logs), Information disclosure (data leaks, verbose errors; encryption, least privilege), Denial of service (traffic floods, expensive queries; rate limits, CDN), Elevation of privilege (broken access control; server-side authorisation checks).
mindmap
root((STRIDE Threat Model))
Spoofing
Stolen passwords
Session hijacking
Mitigate: MFA, secure cookies
Tampering
Changed API parameters
SQL injection
Mitigate: validation, parameterised queries
Repudiation
User denies an action
Mitigate: tamper-proof audit logs
Information disclosure
Data leaks
Verbose error messages
Mitigate: encryption, least privilege
Denial of service
Traffic floods
Expensive queries
Mitigate: rate limits, CDN
Elevation of privilege
Broken access control
Mitigate: server-side authorisationA zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.