Threat Modelling for ASP.NET - Designing Secure Applications.
Rüidiger Grimm, Henrik Eichstädt · Communications and Multimedia Security · 2004
This paper gives a security analysis of Microsoft's ASP.NET technology. The main part of the paper is a list of threats which is structured according to an architecture of Web services and attack points. We also give a reverse table of threats against security requirements as well as a summary of security guidelines for IT developers. This paper has been worked out in collaboration with five University teams each of which is focussing on a different security problem area. We use the same architecture for Web services and attack points.