Integration of STRIDE and MITRE ATT&CK Frameworks for Enhanced Cyber Threat Modeling: A Case Study of Digital Merchant Banking Application

Muhamad Akdzan Angganegara, Iqbal Yulizar Mukti, Muhammad Fathinnuddin · 2025

Mobile banking applications are very vulnerable to sophisticated cyber threats in this digital era. The security architecture should be strong enough to identify and mitigate the potential risks. This paper discusses an integrated approach to cyber threat modeling using the STRIDE methodology and the MITRE ATT&CK framework, taking Digital Merchant Point of Sale (POS) Platform from a leading Indonesian state-owned bank as a case study. It carries out deep analysis and mapping of possible attack vectors and mitigation strategies for each kind of attack within the four security zones: Public, DMZ, Trusted, and Restricted. By doing systematic threat modeling, one should pinpoint the most critical vulnerabilities in payment service authentication mechanisms and data storage. Thereafter, it comes up with a new security control matrix from the general standards such as the PCI DSS, ISO/IEC 27001:2022, and OWASP guidelines. The results of this research demonstrate that the integration of STRIDE and MITRE ATT&CK is more effective for threat identification and mitigation than using any of these methodologies separately. Indeed, the proposed security architecture copes with different attack scenarios, starting from credential harvesting and ending with configuration tampering, while not compromising compliance with regulatory requirements. This research helps add to the ever-increasing knowledge base in mobile banking security architecture and provides practical insights into the implementation of multilayered security controls in financial applications.

Read the paper · More papers on PaperTik