Threat Modeling Way¶
Source: hooks/ways/softwaredev/architecture/threat-modeling/threat-modeling.md
Frontmatter
| Field | Value |
|---|---|
description |
threat modeling, STRIDE analysis, trust boundaries, attack surface assessment, security design review |
vocabulary |
threat model stride attack surface trust boundary mitigation adversary dread spoofing tampering repudiation elevation |
refire |
0.15 |
scope |
agent, subagent |
Threat modeling is security at design altitude. Where the Security Way catches code-level issues (injection, exposed secrets), this way maps adversaries, trust boundaries, and systemic risks.
When to Threat Model¶
- New service or component with external-facing surface
- Authentication/authorization redesign
- Data flow changes crossing trust boundaries
- Third-party integration adding new attack vectors
STRIDE Framework¶
Analyze each component interaction for:
| Threat | Question | Mitigation Pattern |
|---|---|---|
| Spoofing | Can an attacker impersonate a user or service? | Authentication, mutual TLS, signed tokens |
| Tampering | Can data be modified in transit or at rest? | Integrity checks, HMAC, immutable logs |
| Repudiation | Can actions be denied after the fact? | Audit trails, signed events, timestamps |
| Information Disclosure | Can sensitive data leak? | Encryption, access controls, data classification |
| Denial of Service | Can availability be degraded? | Rate limiting, circuit breakers, redundancy |
| Elevation of Privilege | Can an attacker gain higher access? | Least privilege, role separation, input validation |
Risk Register¶
Document accepted risks with expiration — risks don't stay accepted forever.
| Risk | Likelihood | Impact | Mitigation | Status | Expires |
|------|-----------|--------|------------|--------|---------|
| API rate limiting absent | Medium | High | Planned for Q2 | Accepted | 2026-06-01 |
Expired accepted risks must be re-evaluated or mitigated.
Trust Boundaries¶
Identify where data crosses trust levels: - Browser to API gateway (untrusted → semi-trusted) - API to internal service (semi-trusted → trusted) - Service to third-party API (trusted → external)
Each boundary crossing needs: authentication, input validation, output encoding.
Relationship to Security Way¶
- Threat modeling: "What could go wrong?" (design phase)
- Security Way: "Is this code safe?" (implementation phase)
Both may fire on security-related prompts. Threat modeling adds the systemic view.