STRIDE Threat Modeling: Categories, Examples, and Defenses
STRIDE is a threat categorization model used across the Security Champion and Threat Modeling Professional courses. The STRIDE mnemonic appears in video lessons and hands-on exercises including the password reset workflow lab and the StrideGPT exercise. This article consolidates the STRIDE categories with practical examples and defense mappings.
Table of Contents
- What Is STRIDE?
- Spoofing (S)
- Tampering (T)
- Repudiation (R)
- Information Disclosure (I)
- Denial of Service (D)
- Elevation of Privilege (E)
- STRIDE Defenses Mapping
- STRIDE in the Password Reset Exercise
- Common Questions
What Is STRIDE?
STRIDE is a threat modeling methodology created by Microsoft that helps identify security threats by categorizing them into six types. The name is a mnemonic:
| Letter | Threat Category | Security Property |
|---|---|---|
| S | Spoofing | Authentication |
| T | Tampering | Integrity |
| R | Repudiation | Non-Repudiation |
| I | Information Disclosure | Confidentiality |
| D | Denial of Service | Availability |
| E | Elevation of Privilege | Authorization |
Key concept: STRIDE is not primarily a classification system — it's a threat modeling methodology that ensures you consider all types of threats when analyzing a system.
Spoofing (S)
Pretend to Be Someone or Something Else
Spoofing threats involve an attacker impersonating a legitimate user, system, or device.
Examples from the exercises:
- Attacker resets another user's password by spoofing their email address
- Fake authentication tokens that impersonate valid users
- Host header tampering to bypass domain-based access controls
Defense: Authentication mechanisms — multi-factor authentication, certificate-based auth, strong password policies.
Tampering (T)
Modify Something You Shouldn't
Tampering threats involve unauthorized modification of data, code, or system parameters.
Examples from the exercises:
- Parameter tampering to escalate privileges (changing
user_id=5touser_id=1) - Command injection through unsanitized input fields
- Weak or predictable password reset tokens that can be guessed
- Modifying request parameters to bypass business logic
Defense: Integrity controls — input validation, cryptographic signatures, hashed tokens, parameterized queries.
Repudiation (R)
Deny That You Did Something
Repudiation threats involve users denying they performed an action, making it impossible to prove who did what.
Examples from the exercises:
- User denies making a password reset request
- Actions performed without audit logging
- Transactions without non-repudiation mechanisms
Defense: Non-repudiation controls — audit logging, digital signatures, transaction receipts, immutable logs.
Information Disclosure (I)
Access Information You Shouldn't See
Information disclosure threats involve unauthorized exposure of sensitive data.
Examples from the exercises:
- Password reset tokens leaked via HTTP Referrer headers
- User enumeration through different error messages for valid/invalid usernames
- SQL error messages exposing database structure
- Server version information in HTTP response headers
Defense: Confidentiality controls — encryption, access controls, error message sanitization, secure headers.
Denial of Service (D)
Consume All System Resources
DoS threats involve making a service unavailable by overwhelming its resources.
Examples from the exercises:
- Overloading the password reset page with excessive requests
- Long password inputs causing regex exhaustion (ReDoS)
- Resource exhaustion through unbounded operations
Defense: Availability controls — rate limiting, request throttling, failover mechanisms, resource quotas.
Elevation of Privilege (E)
Do Something You're Not Authorized To Do
Elevation of privilege (EoP) threats involve gaining access or permissions beyond what was intended.
Examples from the exercises:
- SQL injection to access the database as an administrator
- Broken access control allowing a regular user to access admin functions
- Parameter tampering leading to privilege escalation
Defense: Authorization controls — role-based access control (RBAC), principle of least privilege, proper access checks on every request.
STRIDE Defenses Mapping
Each STRIDE category maps to a specific security property and corresponding defense:
| STRIDE Category | Security Property | Technical Controls |
|---|---|---|
| Spoofing | Authentication | MFA, certificates, OAuth, strong passwords |
| Tampering | Integrity | Hashes, signatures, input validation, WAF |
| Repudiation | Non-Repudiation | Audit logs, digital signatures, blockchain |
| Information Disclosure | Confidentiality | Encryption (TLS, AES), access controls |
| Denial of Service | Availability | Rate limiting, failover, load balancing |
| Elevation of Privilege | Authorization | RBAC, ABAC, least privilege |
Practical guidance: A single control may defend against multiple STRIDE categories. For example, digital signatures provide Authentication, Integrity, and Non-Repudiation simultaneously.
STRIDE in the Password Reset Exercise
The Password Reset Workflow Lab
The Threat Modeling a Password Reset Workflow exercise (available in both Security Champion and Threat Modeling Professional) walks through identifying 14 STRIDE threats against a Django password reset application:
Spoofing (2 threats):
- Attacker resets password for other users via email manipulation
- One token can reset other users' passwords
Denial of Service (2 threats):
- Overload password reset page
- Long password input causing regex exhaustion
Information Disclosure (2 threats):
- Tokens leaked via referrer headers
- User enumeration through error messages
Tampering (4 threats):
- Parameter tampering for privilege escalation
- Command injection via input fields
- Weak reset tokens
- Host header tampering
Elevation of Privilege (2 threats):
- SQL injection
- Broken access control
Repudiation (2 threats):
- User denies password reset request
- Actions without audit trail
Fix: When working through this exercise, the terminal is not needed — it's a conceptual exercise. Use the OWASP Risk Rating Methodology (covered in the companion article) to score each threat.
Common Questions
| Question | Answer |
|---|---|
| Is STRIDE a threat classification system? | No. STRIDE is a threat modeling methodology. Its purpose is to help you systematically identify threats, not just classify them. |
| Does it matter how I categorize a threat if it spans multiple STRIDE categories? | Not really. There's more value in identifying defenses than in the exact classification. If tampering leads to spoofing leads to EoP, focus on the chain of defenses. |
| What's the difference between Spoofing and Elevation of Privilege? | Spoofing is pretending to be someone else (authentication). EoP is doing something you're not authorized to do (authorization). |
| Can one control defend against multiple STRIDE categories? | Yes. Digital signatures, for example, provide Authentication, Integrity, and Non-Repudiation. |
| How do I apply STRIDE to a system? | Draw a Data Flow Diagram (DFD), identify trust boundaries, then apply each STRIDE category to every element and data flow crossing a boundary. |
Wrap-Up
STRIDE provides a systematic way to think about threats across six categories. Key takeaways:
- Spoofing → defend with Authentication
- Tampering → defend with Integrity controls
- Repudiation → defend with Non-Repudiation (audit logs, signatures)
- Information Disclosure → defend with Confidentiality (encryption)
- Denial of Service → defend with Availability (rate limiting, failover)
- Elevation of Privilege → defend with Authorization (RBAC, least privilege)
The password reset workflow exercise identifies 14 specific threats across all STRIDE categories. Focus on defenses rather than exact categorization — a single threat may span multiple STRIDE types.