Online Banking Security Analysis based on STRIDE Threat Model

Tong Xin, Ban Xiaofang
2014 International Journal of Security and Its Applications  
This paper refers important issues regarding how to evaluate the security threats of the online banking effectively, a system threat analysis method combining STRIDE threat model and threat tree analysis is proposed, which improves the efficiency of the threat analysis greatly and also has good practicability. By applying this method to the online banking system threat analysis, we construct STRIDE threat model on the analysis of the key business data, and then we construct threat tree on the
more » ... hreat tree on the security threat by layer-by-layer decomposition. Thus it gives a detailed threat analysis of the online banking system. This security threat analysis has important significance for the online banking system security analysis and for revealing the threats that the online banking facing. This paper is organized as follows. Section 2, we decompose the data flow of the online banking system by using the data flow diagram. In Section 3 we analyze the online banking threat based on STRIDE model. And then the method of constructing a threat tree is shown in Section 4. The last section concludes the paper.
doi:10.14257/ijsia.2014.8.2.28 fatcat:aefhnpowqbbovcc7e2c5hfb764