Network & Storage (NSJ)
Network & Storage
J
Nihel can expose or modify data in transit because the app permits cleartext traffic or allows downgrade to deprecated TLS protocol versions
Scenario: Nihel can expose or modify data in transit because the app permits cleartext traffic or allows downgrade to deprecated TLS protocol versions
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG: 0217,0218,0233,0235,0236,0295,0321,0322,0323,0342,0343,0344,0345,0348
MASTG Know: 0014,0011,0010,0071,0073
CAPEC™: 57,94,156,220,459,465,466
MASVS: MASVS-NETWORK-1
No attacks registered!