In Writing Secure Code, Michael Howard and David LeBlanc describe six threat types—spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege—known as STRIDE. Table 4.1 provides a short example of each threat type.

Table 4.1. The STRIDE security threats for software systems


STRIDE security threats