Ravindra BagaleCourses & study guides मराठी

Chapter 3: Threat Modeling on Paper

3.7 Takeaways

  1. This chapter is for learning only, and only inside a system you are allowed to test.
  2. A threat model is a picture, a one-sentence threat, and a fix.
  3. STRIDE: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
  4. PASTA is seven steps, from objectives to countermeasures, and step 6 stays a sentence.
  5. The payment picture has a mobile user, a payment API, a Postgres store of balances, and an HTTPS request.
  6. Worked threat: the amount changes from 5000 to 1.
  7. Fixes: enforce TLS, sign payloads with HMAC, re-check the amount on the server.
  8. OWASP Top 10 fixes, SAST with SonarQube and Semgrep, and SCA and SBOM with CycloneDX and SPDX are names for later. They are not chapters of this volume.

In one breath

Draw the phone, the API, the database, and the HTTPS arrow. Say "5000 became 1." Answer with TLS, HMAC, and a server that knows the real amount. Then stop.

If you remember a trick but not the three fixes, you studied the wrong thing. Read 3.5 again. Samajla ka? अगर तीन सुधार याद नहीं हैं, तो 3.5 फिर से पढ़ो.