Network & Storage (NS9)
Network & Storage
9
Martin can modify behavior or gain access to sensitive data by tampering with security-relevant data in shared preferences, user defaults, files, or databases because the app does not verify its integrity and authenticity before use
Scenario: Martin can modify behavior or gain access to sensitive data by tampering with security-relevant data in shared preferences, user defaults, files, or databases because the app does not verify its integrity and authenticity before use
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASWE: 0057
CAPEC™: 176
SAFECode™: -
MASVS: MASVS-RESILIENCE-2,MASVS-CODE-4
No attacks registered!