Model / threat-modeling

Threat modeling and data flows

Trust boundaries, flows that cross them, STRIDE and the threat report.

Create a model or view with the Security / data flow notation. Draw trust boundaries as containers and set each one's zone type (public, DMZ, internal or restricted). Elements drawn inside a boundary are in that zone, and so are the parts of a system inside it and whatever a node inside it hosts.

Data flows

Connect elements with flows to and give the flow a payload, a classification and a protocol. On the canvas a flow shows what it carries and its classification.

Boundary crossings

The Threats tab of a model lists every flow whose ends sit in different zones. A crossing with no control that protects either end is flagged, in that tab and in Validation, and so is a crossing without a classification.

STRIDE

Each crossing suggests STRIDE threats: tampering and denial of service always; spoofing, elevation of privilege and, without a control, repudiation when data enters a more trusted zone; information disclosure when the data is sensitive or unclassified. Suggestions are not added until you choose Add threat, which records a threat the element exposes. Link a control that mitigates it to close it.

Controls

Each threat in the Threats tab offers controls from a curated set of NIST SP 800-53 Rev. 5 controls suited to its STRIDE category, such as IA-2 for spoofing or SC-8 for tampering in transit. Choosing one adds the control once (it is reused across threats), records that it mitigates the threat and protects the element that exposes it, so the crossing counts as protected.

Threat report

Download threat report writes a Markdown report of zones, crossings, threats and their mitigations, open candidates and findings, for a review or a ticket.