THINK FIRST·CODE LATER

← All labs

Threat model StudyBuddy with STRIDE

Problem

Build a threat model for StudyBuddy's core system.

  1. Draw a data-flow diagram (in text) with external entities (students, TAs/instructors, university SSO, AI provider), processes (REST API, tutor module, moderation), data stores (MySQL, course-file index, logs) and data flows. Mark the trust boundaries.
  2. Identify at least eight threats — at least one per STRIDE category — each with: the element attacked, a concrete attack, likelihood (1–3), impact (1–3), risk (L × I), and a mitigation.
  3. Sort the threats by risk and choose the top three to address in the next Sprint; turn each into a testable security requirement (EARS) and a security test.
  4. List two assumptions your model depends on (e.g., "the SSO is secure").

Work it out on paper, in a document or here, then compare with the model answer. Your answer stays in your browser — it is never sent to or stored on the server.