Ravindra BagaleCourses & study guides मराठी

Chapter 3: Threat Modeling on Paper

3.3 PASTA in seven steps

In short: PASTA is a longer walk around the same idea.

PASTA is a longer walk around the same idea. Seven steps. Keep them vertical. This is a thinking order, not an attack plan.

  1. Define objectives. What must stay true? For a payment, the amount the user owes is the amount that moves, and card data stays private.
  2. Define the technical scope. What is inside the picture, and what is outside? Phone, payment API, and the balance database may be in. The card network may be a named neighbor, not a box you pretend to own.
  3. Decompose the app with data-flow diagrams. Draw external entities, processes, data stores, and data flows. Arrows are enough.
  4. Analyze threats. Use STRIDE on each arrow and each box. One sentence per threat.
  5. Vulnerability analysis. Where is the picture weak? Example: the API trusts the amount from the phone. Name the weakness. Do not turn it into instructions.
  6. Attack modeling. Describe, still in one or two sentences, how the weakness could be misused. Stop at the sentence. Do not write a procedure, a command, or a payload.
  7. Risk and impact, with countermeasures. Say how bad it is, then name the fix. A countermeasure is the thing you will actually do, such as re-check the amount on the server.

If step 6 starts to look like a how-to, you have left PASTA and left this course. Come back to one sentence.

Guru-ji makes Raju read step 1 again whenever step 6 gets exciting. Objectives keep the work honest. "Move money correctly" is an objective. "See if I can trick a gateway" is not an objective of this chapter.