threat modelling
process by which potential threats, such as structural vulnerabilities can be identified, enumerated, and prioritized – all from a hypothetical attacker’s point of view
Common Vulnerability Scoring System
standard for assessing computer system vulnerabilities
Attack tree
conceptual diagrams showing how an asset, or target, might be attacked, often used to describe threats on computer systems and possible attacks to realize those threats
Attack tree
conceptual diagrams showing how an asset, or target, might be attacked, often used to describe threats on computer systems and possible attacks to realize those threats
STRIDE
Process for modelling software security threats, standing for Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege
STRIDE
Process for modelling software security threats, standing for Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege