An Approach To Web Application Threat Modeling
Akash Shrivastava · 2008
In present internet computing environment one or the other form of security has become a requirement for all web applications. Importance of Confidentiality, Integrity and Privacy is increasing day by day and security has become vital in internet technology. To design a secure web application, it is very important to analyze and model the potential threats. Threat modeling is a procedure for optimizing Network / Application / Internet Security by identifying objectives and vulnerabilities, and then defining countermeasures to prevent, or mitigate the effects of, threats to the system. [5] A threat is a potential or actual undesirable event that may be malicious (such as DoS attack) or incidental (Information Disclosure). Threat modeling is a planned activity for identifying and assessing application threats and vulnerabilities. Threat Modeling is an ongoing process so a framework should be developed and implemented by the companies for threats mitigation. The aim of this paper is to identify relevant threats and vulnerabilities in the Web Application and build a Security Framework to help in designing a secure Web Application. 2. Practical Utilities of Threat Modeling