skip to content

Six Threat Categories

Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege — each STRIDE letter names a security property under attack, not a named exploit.

on this pageshow

explore

questions

20

In STRIDE, which property does Denial of Service violate, and how does it appear on a process, a store and a flow?

level: juniorimportance: must knowfreq 72%

answer

  1. one of the classic security triad
  2. not secrecy, not correctness
  3. some finite resource runs out
  4. processes, stores and flows each differ
  5. the property quotas and redundancy defend

basics

~20 s

Denial of Service violates availability - legitimate users stop being served. On a process it exhausts CPU, memory or threads; on a store it fills or locks storage; on a flow it saturates or cuts the channel.

solid answer

~50 s

The D in STRIDE is the availability letter — the threat that a legitimate user cannot use the system when they need it. Each element type on a data-flow diagram fails differently. A **process** runs out of a finite resource: CPU, heap, threads, file handles, database connections, or its own dependency budget. A **data store** fills to capacity, has its writes blocked by a lock or a hot partition, or is left in a state that needs operator recovery. A **data flow** is saturated, dropped, or delayed past its useful deadline. External entities are not something you can harden, so in the classic STRIDE-per-element chart they carry only spoofing and repudiation — you deny an external user service by taking down the process or flow they depend on. The answering control family is bounding and duplicating: quotas, timeouts, caps on input-driven work, backpressure, and redundancy for anything on the critical path.

go deeper

for a junior

Be ready to name the property the D violates and give one concrete example on each of a process, a store and a flow. Knowing that availability is what is under attack is the recall that gets asked.

for a middle

Explain the mechanics: which finite resource each element type runs out of, why a slow dependency denies service as effectively as a crashed one, and why external entities carry no D in the per-element chart.

for a senior

Show you enumerate the unglamorous ones in real designs — the log store filling, the poison message, the expiring certificate, the unbounded retry — and that you separate temporary exhaustion from failures needing operator recovery.

for a principal

Own the framing that availability is a security property, not a separate reliability budget, so outage threats get modeled, rated and funded alongside the other five letters rather than deferred to another team.

## What the D in STRIDE actually claims STRIDE is a threat taxonomy: each letter names a **security property under attack**, not a named exploit. Spoofing attacks authentication, Tampering attacks integrity, Repudiation attacks non-repudiation, Information Disclosure attacks confidentiality, **Denial of Service attacks availability**, and Elevation of Privilege attacks authorization. So the question the D asks of every element in your design is one sentence long: *what would stop this from serving a legitimate request?* That framing matters, because Denial of Service is the letter people most often narrow too far. It is not a synonym for a network flood. It is any way the system stops being usable — including ways with no adversary at all, which is why a threat model treats reliability failures and hostile exhaustion under the same heading. The threat is the outcome (service denied); the flood, the poison message, the missing timeout and the single dependency are just different causes. ## How it lands on each element type A data-flow diagram has four element shapes, and the D reads differently on each. | Element | What denial of service looks like | |---|---| | Process | Exhaustion of a finite resource: CPU, heap, thread pool, connection pool, file handles, disk for temp files. Also a crash loop from a message it cannot parse. | | Data store | Capacity exhausted (disk full, quota hit, partition hot), writes blocked by long-held locks, or the store left needing manual recovery. | | Data flow | Bandwidth saturated, connection dropped, latency pushed past a deadline so callers time out even though the far end is alive. | | External entity | Not a target you can harden — in the classic STRIDE-per-element chart, external entities carry only S and R. You deny that user service by hitting the process or flow they depend on. | The chart is a prompt, not a law. Its value is that walking every element with only its applicable letters makes the D findings show up in places people skip — the batch job, the log store, the certificate that expires, the queue with no dead-letter path. ## The resource lens The practical way to enumerate D threats is to ask, per element: **which finite resource does this consume, who can make it consume more, and what happens when it runs out?** Finite resources are broader than CPU and bandwidth: memory, disk, inodes, sockets, database connections, locks, entropy, quota against a paid third party, licences, identifiers in a bounded key space, and the time budget of an upstream caller. The last one is often the sharpest: a slow dependency denies service just as thoroughly as a crashed one, because the callers holding threads waiting on it exhaust their own pools. ## Temporary versus permanent Distinguish the two, because they have different mitigation costs. - **Temporary**: the resource is consumed while the pressure lasts and recovers on its own — a saturated thread pool, a full queue, bandwidth contention. - **Permanent**: the system cannot recover without operator action — a filled disk, a poison message that crashes every consumer on redelivery, a corrupted config or cache written by the failure, a wedged lock, an exhausted identifier space. Permanent denial deserves disproportionate attention in a design review, because the recovery cost and the outage length are set by human response time, not by the attacker walking away. ## Who does it D threats span every attacker position, and naming the position sharpens the mitigation. An anonymous internet caller triggering expensive work; an authenticated low-privilege tenant consuming a shared pool; an insider issuing an unbounded query; a compromised dependency changing resource behaviour; a component with no adversary at all, retrying a failed call in a tight loop. If the position is *nobody* — a single dependency whose outage stops everything — that is still a legitimate D entry in the model. Threat modeling asks what could go wrong, not only who is trying. ## The answering control family Availability is defended by **bounding** and **duplicating**: - Bound the work: timeouts everywhere, caps on request and response size, limits on recursion, nesting and expansion, cost-based limits rather than count-based ones, bounded pools that reject fast rather than queue forever. - Bound the consumer: per-principal quotas and concurrency slots, fair scheduling between classes of work, load shedding by priority, backpressure that propagates instead of buffering. - Duplicate and degrade: redundancy for anything single on the critical path, caches and locally held state that let the system serve a reduced answer, circuit breakers, retry with backoff and jitter, a defined degraded mode. ## Boundary Volumetric flooding at the network layer is a real availability threat, but its attack classes and mitigations belong to network defence, not to this design-time analysis. Likewise, *rating* how bad an outage threat is comes later, in risk rating. What this step owns is the enumeration: for each process, store and flow, one written threat sentence naming the resource, the actor who can exhaust it, and the effect on legitimate users.

  • Can an external entity on a data-flow diagram be the target of a Denial of Service threat?
    In the classic STRIDE-per-element chart external entities carry only spoofing and repudiation, because they sit outside your design and you cannot harden them. You deny that user service by exhausting or breaking the process, store or flow they depend on, so the D entries belong on the elements you own and operate.
  • What is the difference between a temporary and a permanent denial of service, and why track it?
    Temporary means the resource is consumed while the pressure lasts and recovers on its own — a saturated pool, contended bandwidth. Permanent means the system cannot recover without a human: a filled disk, a wedged lock, a poison message that crashes every consumer on redelivery. Permanent ones deserve more design effort because outage length is set by response time, not by the attacker stopping.
  • Give a Denial of Service threat that has no attacker in it at all.
    A single dependency on the critical path with no fallback: when it is unavailable, every request fails. Or a retry loop with no backoff that turns a brief blip into a self-sustaining storm. Threat modeling asks what could go wrong, so these belong in the model as D entries even though nobody is attacking.

saying these in an interview costs you the question

  • Says denial of service only means flooding a server with traffic
  • Maps the D in STRIDE to confidentiality or integrity
  • Believes a denial-of-service threat requires an external attacker
  • Looks only at the web tier and never at stores or batch jobs
  • Assumes every denial of service recovers by itself

context

open as a page

In STRIDE, what does the Elevation of Privilege category cover and which property does it violate?

level: juniorimportance: must knowfreq 76%

basics

~20 s

Elevation of Privilege is STRIDE's category for an actor gaining rights it was never granted - doing something it is not permitted to do. It violates authorization, and the answering controls are authorization decisions plus least privilege.

open as a page

A production API returns unhandled stack traces and still routes /debug/env — why is this an information-disclosure threat?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Both hand an unauthenticated stranger internal detail for free: stack traces expose paths, versions and sometimes a connection string; a debug route dumps environment variables including keys. Return generic errors, keep the route out of production builds, and rotate anything exposed.

open as a page

What is the Repudiation threat in STRIDE, and which security property does it violate?

level: juniorimportance: must knowfreq 75%

basics

~20 s

Repudiation is an actor plausibly denying an action they took, or falsely claiming one they did not, because the system kept no trustworthy evidence. It violates non-repudiation, and the answering control family is identity plus auditing.

open as a page

In STRIDE, which security property does Tampering violate, and which diagram elements can carry it?

level: juniorimportance: must knowfreq 82%

basics

~20 s

Tampering violates integrity: someone modifies data or code they are not authorized to change. On a data-flow diagram it applies to processes, data flows and data stores, but not to external entities, which get spoofed instead.

open as a page

In a Denial of Service review, why does unauthenticated expensive work dominate the findings?

level: middleimportance: must knowfreq 58%

basics

~20 s

One cheap request forces the server to spend seconds of CPU or gigabytes of memory, and any anonymous caller can send it. Fix the ordering - identity and cheap checks first - and cap what the expensive step may consume.

open as a page

In STRIDE, what is the Information Disclosure category and which security property does it violate?

level: middleimportance: must knowfreq 78%

basics

~20 s

Information Disclosure is STRIDE's category for data being exposed to someone not authorised to see it. It violates confidentiality. It is modelled on data flows, data stores and processes, wherever data can be read, copied or inferred.

open as a page

In STRIDE, which security property does Spoofing violate, and which DFD element types can be spoofed?

level: middleimportance: must knowfreq 78%

basics

~20 s

Spoofing violates authentication: something claims an identity that is not its own. On a data-flow diagram it attaches to external entities and to processes, including the machines they answer on, and never to data flows or data stores.

open as a page

A PDF renderer fetches whatever URL a user's render job names, including the instance metadata endpoint. What threat do you raise?

level: seniorimportance: must knowfreq 58%

basics

~10 s

Elevation of Privilege by confused deputy: the renderer holds a network position and credentials the requesting user lacks, and acts on that user's input without checking on whose behalf. The user borrows its authority.

open as a page

How does an append-only, tamper-evident store answer repudiation, and why is it not tamper-proof?

level: middleimportance: should knowfreq 38%

basics

~20 s

Append-only storage keeps every version instead of overwriting, so history cannot be quietly rewritten; chaining each entry's hash over the previous one makes any later alteration detectable. Together they preserve and prove history - but detection is not prevention.

open as a page

In STRIDE, how do you model Tampering against a process's own configuration and code?

level: middleimportance: should knowfreq 55%

basics

~20 s

Treat configuration as an input crossing a trust boundary. Feature flags, rule tables and loaded code decide what a process does, so anyone who can write them changes behaviour without touching any user record — that is Tampering.

open as a page

One tenant's export monopolises a shared analytics query pool — which denial-of-service controls answer this threat?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Authentication cannot help: the offender is a legitimate tenant. Answer with cost-based quotas and isolation - per-tenant concurrency slots, query timeouts and result ceilings, separate lanes for batch and interactive work, and shedding by priority.

open as a page

A password-reset endpoint answers with different wording and latency for known versus unknown addresses — what is the threat?

level: seniorimportance: should knowfreq 48%

basics

~20 s

The endpoint is an information-disclosure oracle: it reveals whether an address has an account while returning no account data. Make the wording identical and the work equivalent, since timing alone still answers the question, then rate-limit and monitor bulk probing.

open as a page

A trader denies placing an order and the order log holds only a timestamp - what must an audit entry contain to settle the dispute?

level: seniorimportance: should knowfreq 52%

basics

~20 s

An entry settles a dispute only if it names an authenticated principal, the exact action and its parameters, trustworthy time, the source, and the authority used - and is held where the disputing party cannot forge or erase it.

open as a page

Where does spoofing sit on a flow where a ward terminal reaches its formulary service by hostname alone, and what closes it?

level: seniorimportance: should knowfreq 56%

basics

~20 s

The threat is a spoofed server: anything on the hospital network that answers to that hostname can feed the terminal dosing data. A resolved name is not an identity, so the terminal must verify a credential cryptographically bound to the expected name against a trust anchor it carries.

open as a page

In a payments back office, which Tampering control stops an operator authorized to edit the settlement file between extract and load?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Protect the artifact end to end, not the hops: the extract job signs the file with a key operators cannot reach, and the loader refuses an unverified one. Then narrow write access and reconcile totals.

open as a page

A transit gate denies all travel when the entitlement service is down — how do you weigh fail-open against fail-closed?

level: principalimportance: should knowfreq 38%

basics

~20 s

Fail-closed turns one dependency's outage into total denial of service; fail-open opens a window of fraudulent travel. Remove the single point first, decide per action in advance, and bound the fallback in time, scope and audit.

open as a page

A migration sidecar keeps database schema-change rights for the pod's whole life. How do you contain that elevation threat?

level: principalimportance: should knowfreq 38%

basics

~10 s

Separate the principal and shorten the grant: run schema changes under a distinct identity in a short-lived step, narrow the rights, alarm on unexpected changes, and keep what remains as accepted residual risk.

open as a page

A support console lets any agent open any customer's full record — how do you model and answer that disclosure risk?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

This is Information Disclosure where the reader is authorised, so identity-based controls never fire. Answer with narrower reads — lookups scoped to an open case, only the fields needed — plus per-agent volume detection, and record what remains as accepted risk.

open as a page

Mutual authentication with one shared client certificate across a vehicle fleet — what does it actually buy?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

It buys fleet membership, not device identity: the backend learns only that the caller holds the fleet key. Anyone who extracts that key from a single unit they own can pose as any unit, and revocation is all-or-nothing across the whole fleet.

open as a page