Microsoft Corporation
May 2005
Home Page for Threat Modeling Web Applications
Summary: Use this cheat sheet to help create threat models for Web applications. The Web Application Security Frame uses categories to organize common security vulnerabilities. If you use these categories when you review your application design to create a threat model, you can systematically reveal the threats and vulnerabilities specific to your application architecture.
Web Application Security Frame Vulnerabilities Organized by Web Application Security Frame Threats and Attacks Organized by Web Application Security Frame Countermeasures Organized by Web Application Security Frame
The Web Application Security Frame uses categories to organize common security vulnerabilities. If you use these categories when you review your application design to create a threat model, you can systematically reveal the threats and vulnerabilities specific to your application architecture.
Table 1 lists and explains the categories for the Web Application Security Frame.
Table 1: Web Application Security Frame Categories
Table 2 lists vulnerabilities for each Web Application Security Frame category.
Table 2: Web Application Security Frame Vulnerabilities
Table 3 lists threats and attacks for each Web Application Security Frame category.
Table 3: Web Application Security Frame Threats and Attacks
Table 4 lists the countermeasures for each Web Application Security Frame category.
Table 4: Web Application Security Frame Countermeasures
Start | Previous | Next