{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/stride","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/stride/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/stride/"},"term":{"en":"STRIDE","da":"STRIDE"},"aka":{"en":["STRIDE model"],"da":["STRIDE-modellen"]},"domain":["security"],"cluster":"application-security","layer":"application","status":"current","era":1999,"summary":{"en":"A memory aid that sorts threats into six kinds, so a team checks every part of a design for each kind in turn.","da":"En huskeregel, der deler trusler op i seks slags, så et team tjekker hver del af et design for hver slags efter tur."},"body":{"formal":{"en":"A scheme for naming threats, created at Microsoft, whose six letters stand for six kinds of threat - faking an identity (the S), tampering, repudiation, information disclosure, denial of service and elevation of privilege - each the breaking of a property a system should keep, such as authentication, integrity or availability.","da":"En metode til at navngive trusler, udviklet hos Microsoft, hvor de seks bogstaver står for Spoofing, Tampering, Repudiation, Information disclosure, Denial of service og Elevation of privilege - hver især et brud på en egenskab, et system bør have, fx autentificering, integritet eller tilgængelighed."},"plain":{"en":"Like a pilot's pre-flight checklist - rather than trusting memory, you go down the same six questions every time so nothing obvious is skipped.","da":"Som en pilots tjekliste før afgang - i stedet for at stole på hukommelsen gennemgår man de samme seks spørgsmål hver gang, så intet oplagt bliver sprunget over."},"inPractice":{"en":"Reviewing the design of a new booking system for a regional hospital, a team asks all six questions about the login page and finds that nothing records failed logins, so a user could later deny what they did - a repudiation threat they fix by keeping a log.","da":"Da et team gennemgår designet af et nyt bookingsystem til et regionshospital, stiller det alle seks spørgsmål til login-siden og opdager, at mislykkede login ikke bliver registreret, så en bruger senere kan benægte, hvad vedkommende har gjort - en repudiation-trussel, som teamet løser ved at føre en log."},"whyItMatters":{"en":"Without a fixed list, teams tend to think only of the attacks they have heard about; six plain questions make threat work repeatable, even for people new to security.","da":"Uden en fast liste tænker teams gerne kun på de angreb, de har hørt om; seks enkle spørgsmål gør trusselsarbejdet gentageligt, også for folk, der er nye inden for sikkerhed."}},"deepDive":{"en":"STRIDE was introduced by Loren Kohnfelder and Praerit Garg in an internal Microsoft paper, \"The threats to our products\", in April 1999, and was later built into Microsoft's Security Development Lifecycle and its free Threat Modeling Tool. Each letter is the violation of a security property: Spoofing violates authentication, Tampering violates integrity, Repudiation violates non-repudiation, Information disclosure violates confidentiality, Denial of service violates availability, and Elevation of privilege violates authorization. That mapping is the practical value of the model, because each threat category points directly to a family of mitigations: strong authentication and certificate pinning for S, MACs, signatures and access control for T, tamper-evident audit logs for R, encryption and minimisation for I, quotas, rate limits and redundancy for D, and least privilege and input handling for E.\n\nSTRIDE is normally applied to a data flow diagram with five element types: external entities, processes, data stores, data flows and trust boundaries. In STRIDE-per-element, only the relevant letters are considered for each type. External entities are subject to S and R; processes to all six; data stores to T, I and D, plus R when the store is an audit log; and data flows to T, I and D. Trust boundaries carry no threats of their own but mark where flows need the most scrutiny. STRIDE-per-interaction instead analyses each flow as a tuple of source, destination and interaction, which produces fewer but more contextual findings, and is the approach the Threat Modeling Tool uses.\n\nThe model is a classification and elicitation aid, not a risk rating. Microsoft paired it for a time with DREAD for scoring, but DREAD was dropped because its ratings were too subjective, and teams now usually rate STRIDE findings with CVSS, a simple likelihood and impact matrix or their organisation's risk method. Common misuses are treating the six categories as a complete list, which misses business-logic and abuse cases, and applying STRIDE to a whole system as one box instead of decomposing it. Privacy threats such as linkability or identifiability fall outside STRIDE; LINDDUN was designed as its privacy counterpart, and attack trees or kill-chain models complement it for attacker-centric analysis. Adam Shostack's Elevation of Privilege card game turns the same categories into a structured team exercise.","da":"STRIDE blev introduceret af Loren Kohnfelder og Praerit Garg i et internt Microsoft-dokument, \"The threats to our products\", i april 1999 og blev senere bygget ind i Microsofts Security Development Lifecycle og det gratis Threat Modeling Tool. Hvert bogstav er brud på en sikkerhedsegenskab: Spoofing bryder autentificering, Tampering bryder integritet, Repudiation bryder uafviselighed, Information disclosure bryder fortrolighed, Denial of service bryder tilgængelighed, og Elevation of privilege bryder autorisation. Den kobling er modellens praktiske værdi, fordi hver trusselskategori peger direkte på en familie af modforanstaltninger: stærk autentificering og certifikat-pinning for S, MAC'er, signaturer og adgangskontrol for T, manipulationssikre auditlogs for R, kryptering og dataminimering for I, kvoter, rate limits og redundans for D og mindst mulige rettigheder og sikker inputhåndtering for E.\n\nSTRIDE anvendes normalt på et dataflowdiagram med fem elementtyper: eksterne entiteter, processer, datalagre, dataflows og tillidsgrænser. I STRIDE-per-element vurderes kun de relevante bogstaver for hver type. Eksterne entiteter er udsat for S og R; processer for alle seks; datalagre for T, I og D samt R, når lageret er en auditlog; og dataflows for T, I og D. Tillidsgrænser har ingen trusler i sig selv, men markerer, hvor dataflows kræver størst opmærksomhed. STRIDE-per-interaction analyserer i stedet hvert flow som en kombination af kilde, destination og interaktion, hvilket giver færre, men mere kontekstuelle fund, og det er den tilgang, Threat Modeling Tool bruger.\n\nModellen er et hjælpemiddel til at klassificere og finde trusler, ikke en risikovurdering. Microsoft parrede den en tid med DREAD til scoring, men DREAD blev opgivet, fordi vurderingerne var for subjektive, og i dag vurderes STRIDE-fund typisk med CVSS, en simpel matrix for sandsynlighed og konsekvens eller organisationens egen risikometode. Typiske fejl er at behandle de seks kategorier som en udtømmende liste, hvilket overser forretningslogik og misbrugsscenarier, og at anvende STRIDE på hele systemet som én kasse i stedet for at dele det op. Privatlivstrusler som sammenkædning eller identificerbarhed ligger uden for STRIDE; LINDDUN er udviklet som modstykket for privatliv, og angrebstræer eller kill chain-modeller supplerer den med en angriberorienteret analyse. Adam Shostacks kortspil Elevation of Privilege gør de samme kategorier til en struktureret teamøvelse."},"edges":[{"type":"requires","to":"security/threat","confidence":"high","strength":"normal"},{"type":"requires","to":"security/cia-triad","confidence":"high","strength":"normal"},{"type":"implements","to":"security/threat-modelling","confidence":"high","strength":"normal"}],"depth":1,"sources":[{"title":"Microsoft Learn - Threat Modeling Tool threats (STRIDE)","url":"https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats","tier":"official-doc","publisher":"Microsoft"},{"title":"Adam Shostack - 20 Years of STRIDE","url":"https://shostack.org/blog/20-years-of-stride-looking-back-looking-forward/","tier":"reference"}],"draft":true}