skip to content

STRIDE Analysis

Walking a data-flow diagram element by element to enumerate spoofing, tampering, repudiation, disclosure, denial of service and elevation threats. Interviewers make you apply it to a real design.

on this pageshow

explore

questions

page 1 of 2

In STRIDE, which property does Denial of Service violate, and how does it appear on a process, a store and a flow?

level: juniorimportance: must knowfreq 72%

answer

  1. one of the classic security triad
  2. not secrecy, not correctness
  3. some finite resource runs out
  4. processes, stores and flows each differ
  5. the property quotas and redundancy defend

basics

~20 s

Denial of Service violates availability - legitimate users stop being served. On a process it exhausts CPU, memory or threads; on a store it fills or locks storage; on a flow it saturates or cuts the channel.

solid answer

~50 s

The D in STRIDE is the availability letter — the threat that a legitimate user cannot use the system when they need it. Each element type on a data-flow diagram fails differently. A **process** runs out of a finite resource: CPU, heap, threads, file handles, database connections, or its own dependency budget. A **data store** fills to capacity, has its writes blocked by a lock or a hot partition, or is left in a state that needs operator recovery. A **data flow** is saturated, dropped, or delayed past its useful deadline. External entities are not something you can harden, so in the classic STRIDE-per-element chart they carry only spoofing and repudiation — you deny an external user service by taking down the process or flow they depend on. The answering control family is bounding and duplicating: quotas, timeouts, caps on input-driven work, backpressure, and redundancy for anything on the critical path.

go deeper

for a junior

Be ready to name the property the D violates and give one concrete example on each of a process, a store and a flow. Knowing that availability is what is under attack is the recall that gets asked.

for a middle

Explain the mechanics: which finite resource each element type runs out of, why a slow dependency denies service as effectively as a crashed one, and why external entities carry no D in the per-element chart.

for a senior

Show you enumerate the unglamorous ones in real designs — the log store filling, the poison message, the expiring certificate, the unbounded retry — and that you separate temporary exhaustion from failures needing operator recovery.

for a principal

Own the framing that availability is a security property, not a separate reliability budget, so outage threats get modeled, rated and funded alongside the other five letters rather than deferred to another team.

## What the D in STRIDE actually claims STRIDE is a threat taxonomy: each letter names a **security property under attack**, not a named exploit. Spoofing attacks authentication, Tampering attacks integrity, Repudiation attacks non-repudiation, Information Disclosure attacks confidentiality, **Denial of Service attacks availability**, and Elevation of Privilege attacks authorization. So the question the D asks of every element in your design is one sentence long: *what would stop this from serving a legitimate request?* That framing matters, because Denial of Service is the letter people most often narrow too far. It is not a synonym for a network flood. It is any way the system stops being usable — including ways with no adversary at all, which is why a threat model treats reliability failures and hostile exhaustion under the same heading. The threat is the outcome (service denied); the flood, the poison message, the missing timeout and the single dependency are just different causes. ## How it lands on each element type A data-flow diagram has four element shapes, and the D reads differently on each. | Element | What denial of service looks like | |---|---| | Process | Exhaustion of a finite resource: CPU, heap, thread pool, connection pool, file handles, disk for temp files. Also a crash loop from a message it cannot parse. | | Data store | Capacity exhausted (disk full, quota hit, partition hot), writes blocked by long-held locks, or the store left needing manual recovery. | | Data flow | Bandwidth saturated, connection dropped, latency pushed past a deadline so callers time out even though the far end is alive. | | External entity | Not a target you can harden — in the classic STRIDE-per-element chart, external entities carry only S and R. You deny that user service by hitting the process or flow they depend on. | The chart is a prompt, not a law. Its value is that walking every element with only its applicable letters makes the D findings show up in places people skip — the batch job, the log store, the certificate that expires, the queue with no dead-letter path. ## The resource lens The practical way to enumerate D threats is to ask, per element: **which finite resource does this consume, who can make it consume more, and what happens when it runs out?** Finite resources are broader than CPU and bandwidth: memory, disk, inodes, sockets, database connections, locks, entropy, quota against a paid third party, licences, identifiers in a bounded key space, and the time budget of an upstream caller. The last one is often the sharpest: a slow dependency denies service just as thoroughly as a crashed one, because the callers holding threads waiting on it exhaust their own pools. ## Temporary versus permanent Distinguish the two, because they have different mitigation costs. - **Temporary**: the resource is consumed while the pressure lasts and recovers on its own — a saturated thread pool, a full queue, bandwidth contention. - **Permanent**: the system cannot recover without operator action — a filled disk, a poison message that crashes every consumer on redelivery, a corrupted config or cache written by the failure, a wedged lock, an exhausted identifier space. Permanent denial deserves disproportionate attention in a design review, because the recovery cost and the outage length are set by human response time, not by the attacker walking away. ## Who does it D threats span every attacker position, and naming the position sharpens the mitigation. An anonymous internet caller triggering expensive work; an authenticated low-privilege tenant consuming a shared pool; an insider issuing an unbounded query; a compromised dependency changing resource behaviour; a component with no adversary at all, retrying a failed call in a tight loop. If the position is *nobody* — a single dependency whose outage stops everything — that is still a legitimate D entry in the model. Threat modeling asks what could go wrong, not only who is trying. ## The answering control family Availability is defended by **bounding** and **duplicating**: - Bound the work: timeouts everywhere, caps on request and response size, limits on recursion, nesting and expansion, cost-based limits rather than count-based ones, bounded pools that reject fast rather than queue forever. - Bound the consumer: per-principal quotas and concurrency slots, fair scheduling between classes of work, load shedding by priority, backpressure that propagates instead of buffering. - Duplicate and degrade: redundancy for anything single on the critical path, caches and locally held state that let the system serve a reduced answer, circuit breakers, retry with backoff and jitter, a defined degraded mode. ## Boundary Volumetric flooding at the network layer is a real availability threat, but its attack classes and mitigations belong to network defence, not to this design-time analysis. Likewise, *rating* how bad an outage threat is comes later, in risk rating. What this step owns is the enumeration: for each process, store and flow, one written threat sentence naming the resource, the actor who can exhaust it, and the effect on legitimate users.

  • Can an external entity on a data-flow diagram be the target of a Denial of Service threat?
    In the classic STRIDE-per-element chart external entities carry only spoofing and repudiation, because they sit outside your design and you cannot harden them. You deny that user service by exhausting or breaking the process, store or flow they depend on, so the D entries belong on the elements you own and operate.
  • What is the difference between a temporary and a permanent denial of service, and why track it?
    Temporary means the resource is consumed while the pressure lasts and recovers on its own — a saturated pool, contended bandwidth. Permanent means the system cannot recover without a human: a filled disk, a wedged lock, a poison message that crashes every consumer on redelivery. Permanent ones deserve more design effort because outage length is set by response time, not by the attacker stopping.
  • Give a Denial of Service threat that has no attacker in it at all.
    A single dependency on the critical path with no fallback: when it is unavailable, every request fails. Or a retry loop with no backoff that turns a brief blip into a self-sustaining storm. Threat modeling asks what could go wrong, so these belong in the model as D entries even though nobody is attacking.

saying these in an interview costs you the question

  • Says denial of service only means flooding a server with traffic
  • Maps the D in STRIDE to confidentiality or integrity
  • Believes a denial-of-service threat requires an external attacker
  • Looks only at the web tier and never at stores or batch jobs
  • Assumes every denial of service recovers by itself

context

open as a page

In STRIDE, what does the Elevation of Privilege category cover and which property does it violate?

level: juniorimportance: must knowfreq 76%

basics

~20 s

Elevation of Privilege is STRIDE's category for an actor gaining rights it was never granted - doing something it is not permitted to do. It violates authorization, and the answering controls are authorization decisions plus least privilege.

open as a page

A production API returns unhandled stack traces and still routes /debug/env — why is this an information-disclosure threat?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Both hand an unauthenticated stranger internal detail for free: stack traces expose paths, versions and sometimes a connection string; a debug route dumps environment variables including keys. Return generic errors, keep the route out of production builds, and rotate anything exposed.

open as a page

What is the Repudiation threat in STRIDE, and which security property does it violate?

level: juniorimportance: must knowfreq 75%

basics

~20 s

Repudiation is an actor plausibly denying an action they took, or falsely claiming one they did not, because the system kept no trustworthy evidence. It violates non-repudiation, and the answering control family is identity plus auditing.

open as a page

In STRIDE, which security property does Tampering violate, and which diagram elements can carry it?

level: juniorimportance: must knowfreq 82%

basics

~20 s

Tampering violates integrity: someone modifies data or code they are not authorized to change. On a data-flow diagram it applies to processes, data flows and data stores, but not to external entities, which get spoofed instead.

open as a page

In a Denial of Service review, why does unauthenticated expensive work dominate the findings?

level: middleimportance: must knowfreq 58%

basics

~20 s

One cheap request forces the server to spend seconds of CPU or gigabytes of memory, and any anonymous caller can send it. Fix the ordering - identity and cheap checks first - and cap what the expensive step may consume.

open as a page

In STRIDE, what is the Information Disclosure category and which security property does it violate?

level: middleimportance: must knowfreq 78%

basics

~20 s

Information Disclosure is STRIDE's category for data being exposed to someone not authorised to see it. It violates confidentiality. It is modelled on data flows, data stores and processes, wherever data can be read, copied or inferred.

open as a page

In STRIDE-per-element analysis, which of the six STRIDE categories apply to each DFD element type?

level: middleimportance: must knowfreq 72%

basics

~10 s

External entities take spoofing and repudiation; processes take all six; data flows and data stores take tampering, information disclosure and denial of service, with repudiation added for stores that hold logs or audit records.

open as a page

In STRIDE, which security property does Spoofing violate, and which DFD element types can be spoofed?

level: middleimportance: must knowfreq 78%

basics

~20 s

Spoofing violates authentication: something claims an identity that is not its own. On a data-flow diagram it attaches to external entities and to processes, including the machines they answer on, and never to data flows or data stores.

open as a page

How do you restate the mitigation note "validate the uploaded XML" as a testable requirement?

level: seniorimportance: must knowfreq 52%

basics

~20 s

A verification requirement names a component, a condition and an observable outcome, so one input can make it fail: the ingest service parses XML with external entity resolution disabled and rejects a DOCTYPE with a 400. Tag it CWE-611.

open as a page

In a parcel-locker threat model, 'more logging' is proposed against a spoofed-courier threat - how do you check a control answers the threat?

level: seniorimportance: must knowfreq 58%

basics

~20 s

Ask three things: does the control restore the property the threat violates, does it sit where the attack crosses the flow, and does the attack still complete once you assume it works. Logging fails the first - impersonation needs authentication.

open as a page

A PDF renderer fetches whatever URL a user's render job names, including the instance metadata endpoint. What threat do you raise?

level: seniorimportance: must knowfreq 58%

basics

~10 s

Elevation of Privilege by confused deputy: the renderer holds a network position and credentials the requesting user lacks, and acts on that user's input without checking on whose behalf. The user borrows its authority.

open as a page

What does a group STRIDE card session surface that one engineer's solo sweep misses?

level: seniorimportance: must knowfreq 50%

basics

~20 s

A group pools facts no single modeler holds — how the queue really behaves under retries, what a support agent can approve — and a dealt card forces categories and components the solo analyst had quietly scoped out.

open as a page

Why does a threat model's mitigation entry name a control family rather than a specific security product?

level: juniorimportance: should knowfreq 40%

basics

~20 s

A control family names what the countermeasure must do - rate limiting, per-request authorization, message signing - so the entry stays checkable when the tool is replaced. A product name asserts a purchase, not that the threat is answered.

open as a page

How do OWASP ASVS and the OWASP Proactive Controls differ in what they give a team?

level: middleimportance: should knowfreq 45%

basics

~20 s

The Proactive Controls are a short, ordered list of defensive techniques written for developers to apply while building. ASVS is a graded catalog of testable "verify that" requirements used to check a design or build against a chosen level.

open as a page

In a STRIDE threat model, how do you find the threats that were left with no control at all?

level: middleimportance: should knowfreq 45%

basics

~20 s

Treat the mapping as a table, not prose: every enumerated threat is a row, and before the session closes you filter for blank mitigation cells and for one control claiming many rows. Gaps cluster where no familiar control family applies.

open as a page

In a STRIDE per-interaction sweep, what is the unit you enumerate, and how does per-element differ?

level: middleimportance: should knowfreq 56%

basics

~20 s

A per-interaction sweep enumerates triples: a source element, a destination element, and the flow between them, then asks which of the six STRIDE categories apply to that crossing. A per-element sweep visits each node once instead.

open as a page

How does an append-only, tamper-evident store answer repudiation, and why is it not tamper-proof?

level: middleimportance: should knowfreq 38%

basics

~20 s

Append-only storage keeps every version instead of overwriting, so history cannot be quietly rewritten; chaining each entry's hash over the previous one makes any later alteration detectable. Together they preserve and prove history - but detection is not prevention.

open as a page

In STRIDE, how do you model Tampering against a process's own configuration and code?

level: middleimportance: should knowfreq 55%

basics

~20 s

Treat configuration as an input crossing a trust boundary. Feature flags, rule tables and loaded code decide what a process does, so anyone who can write them changes behaviour without touching any user record — that is Tampering.

open as a page

How does the Elevation of Privilege card deck structure a group STRIDE session?

level: middleimportance: should knowfreq 42%

basics

~20 s

Elevation of Privilege deals a six-suit deck — one suit per STRIDE category — over a diagram of the system. Players follow suit in tricks, and score by naming a threat the played card actually finds in that design.

open as a page

One tenant's export monopolises a shared analytics query pool — which denial-of-service controls answer this threat?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Authentication cannot help: the offender is a legitimate tenant. Answer with cost-based quotas and isolation - per-tenant concurrency slots, query timeouts and result ceilings, separate lanes for batch and interactive work, and shedding by priority.

open as a page

A password-reset endpoint answers with different wording and latency for known versus unknown addresses — what is the threat?

level: seniorimportance: should knowfreq 48%

basics

~20 s

The endpoint is an information-disclosure oracle: it reveals whether an address has an account while returning no account data. Make the wording identical and the work equivalent, since timing alone still answers the question, then rate-limit and monitor bulk probing.

open as a page

Your STRIDE per-element sheet covers every element on the diagram - what threats can it still miss?

level: seniorimportance: should knowfreq 52%

basics

~20 s

A per-element sweep only asks what each element can suffer on its own. Threats that live in the relationship between elements, in the trust one component places in another, and in elements nobody drew, produce no row at all.

open as a page

In a per-interaction STRIDE sweep, why can the same data flow rate differently at each crossing?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Because the applicable STRIDE categories follow the two endpoints of a crossing, not the payload. Identical bytes moving from an untrusted device, then between internal services, then into a widely-read analytics estate raise different threats at each hop.

open as a page

A trader denies placing an order and the order log holds only a timestamp - what must an audit entry contain to settle the dispute?

level: seniorimportance: should knowfreq 52%

basics

~20 s

An entry settles a dispute only if it names an authenticated principal, the exact action and its parameters, trustworthy time, the source, and the authority used - and is held where the disputing party cannot forge or erase it.

open as a page

Where does spoofing sit on a flow where a ward terminal reaches its formulary service by hostname alone, and what closes it?

level: seniorimportance: should knowfreq 56%

basics

~20 s

The threat is a spoofed server: anything on the hospital network that answers to that hostname can feed the terminal dosing data. A resolved name is not an identity, so the terminal must verify a credential cryptographically bound to the expected name against a trust anchor it carries.

open as a page

In a payments back office, which Tampering control stops an operator authorized to edit the settlement file between extract and load?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Protect the artifact end to end, not the hops: the extract job signs the file with a key operators cannot reach, and the loader refuses an unverified one. Then narrow write access and reconcile totals.

open as a page

Which ASVS verification level do you set for a payment-initiation API versus a marketing microsite?

level: principalimportance: should knowfreq 36%

basics

~20 s

Set the level per component by asset and exposure, not company-wide. Payment initiation moves money, so the standard level is the floor with selected top-level requirements on money-moving flows; the microsite takes the baseline unless it shares a session scope.

open as a page

A transit gate denies all travel when the entitlement service is down — how do you weigh fail-open against fail-closed?

level: principalimportance: should knowfreq 38%

basics

~20 s

Fail-closed turns one dependency's outage into total denial of service; fail-open opens a window of fraudulent travel. Remove the single point first, decide per action in advance, and bound the fallback in time, scope and audit.

open as a page

A migration sidecar keeps database schema-change rights for the pod's whole life. How do you contain that elevation threat?

level: principalimportance: should knowfreq 38%

basics

~10 s

Separate the principal and shorten the grant: run schema changes under a distinct identity in a short-lived step, narrow the rights, alarm on unexpected changes, and keep what remains as accepted residual risk.

open as a page

showing 1–30 of 35