An Automated Approach to Constructing STRIDE Threat Rule Model and Updating Rule Base

Changlan Fu, He Zhang, Xingzheng Guan · ACM Transactions on Software Engineering and Methodology · 2025

Threat modeling is a structured method for identifying and responding to threats, and the STRIDE method has become the de facto mainstream threat identification technology in practice. At present, the analysis of STRIDE threats and the construction of the rules for threat identification largely rely on human expertise, resulting in incomplete rules for threat identification and data volume of threat modeling as well as insufficient analysis accuracy and efficiency. Along with the rapid emergence of new threats to Internet software every year, there is an urgent need to automatically construct and update a relatively complete rule base to leverage the effectiveness and automation of threat analysis. In this article, we propose a threat identification rule model based on the STRIDE method, providing comprehensive rule base data. Then, we propose an automated approach for classifying STRIDE threats and further propose an automated approach for constructing the rule base. In addition, we design an automatic update mechanism for the rule base to ensure its effectiveness. The proposed approach is evaluated by conducting comparative experiments, and the results show that the precision of the STRIDE threat automatic classification on the CNNVD dataset reaches 92.5%, the recall at 87.6%, and the F1-score at 89.3%. Compared with the baseline method, our classification approach significantly improves precision, recall, and F1-score by 11.2%, 8.2%, and 9.2%, respectively. The accuracy of the automatically constructed rules reached 89.5%. Compared with manual construction approach, our approach improves the automation level and efficiency of rule construction.

Read the paper · More papers on PaperTik