STRIDE
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege
STRIDE is Microsoft's threat modeling methodology that categorizes threats into six types. Each category maps to a specific security property: authentication, integrity, non-repudiation, confidentiality, availability, and authorization.
Como é usado em cibersegurança
Security architects apply STRIDE during design reviews to identify threats against new systems and applications. Penetration testers use STRIDE categories to structure their attack narratives and findings reports. Threat modeling with STRIDE is a standard practice in secure software development lifecycles.
Termo relacionado no glossário: stride
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.