The STRIDE Framework
STRIDE is the most widely-used threat categorization framework in the world. Developed at Microsoft, it gives you a structured checklist to ensure you never miss a category of threat.
๐ฏ Learning Objectives
- Name all six STRIDE categories and their definitions
- Map each STRIDE category to the CIA property it violates
- Identify the corresponding security property (mitigator) for each threat type
- Apply STRIDE to a simple system component to generate a threat list
- Recognize real-world attacks within each STRIDE category
1What is STRIDE?
STRIDE is a mnemonic โ each letter is a category of threat. It was created by Microsoft engineers Loren Kohnfelder and Praerit Garg in 1999 and is still the industry standard today.
2STRIDE โ CIA Mapping & Mitigators
Each STRIDE category maps to a security property that, when present, prevents or limits that type of threat. Think of the mitigator as the antidote.
| STRIDE Category | CIA Property Violated | Security Mitigator | Real-World Controls |
|---|---|---|---|
| S โ Spoofing | Authentication | Authentication | MFA, certificate pinning, OAuth, strong passwords |
| T โ Tampering | Integrity | Integrity Controls | Digital signatures, HTTPS/TLS, checksums, input validation |
| R โ Repudiation | Non-repudiation | Audit Logging | Immutable logs, digital signatures, SIEM, timestamps |
| I โ Info Disclosure | Confidentiality | Confidentiality Controls | Encryption at rest/transit, access control, data masking |
| D โ Denial of Service | Availability | Availability Controls | Rate limiting, auto-scaling, CDN, DDoS protection |
| E โ Elevation of Privilege | Authorization | Authorization Controls | RBAC, least privilege, input validation, sandboxing |
3Applying STRIDE to a Component
The real power of STRIDE is how methodically you apply it. For each element in your Data Flow Diagram, you ask: "Is this element vulnerable to each STRIDE threat?"
Let's walk through a login endpoint as our example component:
role field. If that field is set client-side or trusted without server-side verification, an attacker modifies their token payload to claim admin role.4STRIDE by Element Type
Not every STRIDE threat applies equally to every element type in a DFD. This shorthand table โ STRIDE per Element โ helps you focus:
| Element Type | S | T | R | I | D | E |
|---|---|---|---|---|---|---|
| External Entity (user, 3rd-party) | โ | โ | โ | โ | โ | โ |
| Process (API, service, function) | โ | โ | โ | โ | โ | โ |
| Data Store (DB, file, cache) | โ | โ | โ | โ | โ | โ |
| Data Flow (network, IPC) | โ | โ | โ | โ | โ | โ |
5Knowledge Check
6Module Summary
- STRIDE = Spoofing ยท Tampering ยท Repudiation ยท Information Disclosure ยท Denial of Service ยท Elevation of Privilege
- Each category maps to a security mitigator: Auth โ Integrity โ Audit โ Confidentiality โ Availability โ Authorization
- Apply STRIDE per element in your DFD โ processes need all six, data stores skip Spoofing and EoP
- The framework's power is its completeness โ it ensures you don't forget entire threat categories
- STRIDE generates the threat list; risk scoring then decides what to fix first