Chapter 3: Threat Modeling on Paper
3.3 PASTA in seven steps
In short: PASTA is a longer walk around the same idea.
PASTA is a longer walk around the same idea. Seven steps. Keep them vertical. This is a thinking order, not an attack plan.
- Define objectives. What must stay true? For a payment, the amount the user owes is the amount that moves, and card data stays private.
- Define the technical scope. What is inside the picture, and what is outside? Phone, payment API, and the balance database may be in. The card network may be a named neighbor, not a box you pretend to own.
- Decompose the app with data-flow diagrams. Draw external entities, processes, data stores, and data flows. Arrows are enough.
- Analyze threats. Use STRIDE on each arrow and each box. One sentence per threat.
- Vulnerability analysis. Where is the picture weak? Example: the API trusts the amount from the phone. Name the weakness. Do not turn it into instructions.
- Attack modeling. Describe, still in one or two sentences, how the weakness could be misused. Stop at the sentence. Do not write a procedure, a command, or a payload.
- Risk and impact, with countermeasures. Say how bad it is, then name the fix. A countermeasure is the thing you will actually do, such as re-check the amount on the server.
If step 6 starts to look like a how-to, you have left PASTA and left this course. Come back to one sentence.
Guru-ji makes Raju read step 1 again whenever step 6 gets exciting. Objectives keep the work honest. "Move money correctly" is an objective. "See if I can trick a gateway" is not an objective of this chapter.