THREAT MODELLING FOR ASP.NET
Rüdiger Grimm, Henrik Eichstädt · Kluwer Academic Publishers eBooks · 2005
This paper gives a security analysis of Microsoft's ASP.NET technology. The main part of the paper is a list of threats which is structured according to an architecture of Web services and attack points. We also give a reverse table of threats against security requirements as well as a summary of security guidelines for IT developers. This paper has been worked out in collaboration with five University teams each of which is focussing on a different security problem area. We use the same architecture for Web services and attack points.