Loading...

Messages

Proposals

Stuck in your homework and missing deadline? Get urgent help in $10/Page with 24 hours deadline

Get Urgent Writing Help In Your Essays, Assignments, Homeworks, Dissertation, Thesis Or Coursework & Achieve A+ Grades.

Privacy Guaranteed - 100% Plagiarism Free Writing - Free Turnitin Report - Professional And Experienced Writers - 24/7 Online Support

What is stride threat model

28/10/2021 Client: muhammad11 Deadline: 2 Day

Threat Modeling Using STRIDE

Project: Threat Modeling with STRIDE

Purpose

This project provides an opportunity to apply the concepts of using a Threat Modeling methodology, STRIDE, against a fictitious Healthcare organization’s application.

Learning Objectives and Outcomes

You will gain an overall understanding of risk management, its importance, and critical processes required when developing a threat model as a part of risk management for an organization.

Required Source Information and Tools

Web References: https://www.webtrends.com/blog/2015/04/threat-modeling-with-stride/

Deliverables

As discussed in this course, risk management is an important process for all organizations. This is particularly true in information systems, which provides critical support for organizational missions. The project activities described in this document allow you to fulfill the role of an employee participating in the risk management process in a specific business situation, identifying the threats and vulnerabilities facing your organization.

Submission Requirements

All project submissions should follow this format:

· Format: Microsoft Word or compatible

· Font: Arial, 10-point, double-space

· Citation Style: APA style. Any work copied from Internet or other sources will automatically receive a 0.

Scenario

You are an information technology (IT) intern working for Health Network, Inc. (Health Network), a fictitious health services organization headquartered in Minneapolis, Minnesota. Health Network has over 600 employees throughout the organization and generates $500 million USD in annual revenue. The company has two additional locations in Portland, Oregon and Arlington, Virginia, which support a mix of corporate operations. Each corporate facility is located near a co-location data center, where production systems are located and managed by third-party data center hosting vendors.

Company Products

Health Network has three main products: HNetExchange, HNetPay, and HNetConnect.

HNetExchange is the primary source of revenue for the company. The service handles secure electronic medical messages that originate from its customers, such as large hospitals, which are then routed to receiving customers such as clinics over the Internet. Information transmitted over this network include patient health information, xrays, bloodwork, and diagnoses.

HNetPay is a Web portal used by many of the company’s HNetExchange customers to support the management of secure payments and billing. The HNetPay Web portal, hosted at Health Network production sites, accepts various forms of payments and interacts with credit-card processing organizations much like a Web commerce shopping cart. The Web portal is hosted on a Windows IIS Web server. Data from the portal is stored in an Oracle database on a Unix server.

HNetConnect is an online directory that lists doctors, clinics, and other medical facilities to allow Health Network customers to find the right type of care at the right locations. It contains doctors’ personal information, work addresses, medical certifications, and types of services that the doctors and clinics offer. Doctors are given credentials and are able to update the information in their profile. Health Network customers, which are the hospitals and clinics, connect to all three of the company’s products using HTTPS connections. Doctors and potential patients are able to make payments and update their profiles using Internet-accessible HTTPS Web sites. You have already run a Nessus scan and used nmap to determine vulnerabilities.

Information Technology Infrastructure Overview

Health Network operates in a production data center that provide high availability across the company’s products. The data center host about 1,000 production servers, and Health Network maintains 650 corporate laptops and company-issued mobile devices for its employees. Employees are allowed to work from home, using their company-issued laptops. There is also a wireless network available at work.

Project

For the project, you must create a threat model, using STRIDE (remember to use the information in the article at the Web link, to understand these sections). To do so, you must analyze the data and create a threat model document that contains the following sections:

1. A section titled Attacker Viewpoint discussing framing the threat from the mindset of the perceived attacker. Address the following questions: 5 points.

a. Who is likely to attack the system?

b. What are they likely to attack to accomplish their goal?

2. A section titled Asset Viewpoint discussing the organization’s assets from the information provided in the scenario, above. Be sure to also address the following questions (I recommend placing this in a table). 15 points

a. What is the asset?

b. What value does the asset have to the organization?

c. How might that asset be exploited by an attacker?

3. A section, titled STRIDE, that will identify the following security threats for six different categories, as discussed in the article in the Web reference you were asked to read, as they apply to this scenario. Include the following: 60 points

a. Spoofing – address any spoofing threats that might be present in the applications or systems. Include the ramifications (impact) of a spoofing attack.

b. Tampering – address any data or databases that might be subject to data tampering (applications, for instance, that might be vulnerable to cross site scripting attacks or SQL injection in the healthcare organization scenario, above).

c. Repudiation – address where repudiation attacks might be possible in the organization.

d. Information disclosure – address where there may be the likelihood for a data breach in the organization’s assets listed in the scenario that would allow the attacker to access private information (or, worse, patient health information). Discuss the laws and regulations that would be impacted and the ramifications (impact and penalities) that would be incurred by this organization in that event.

e. Denial of Service – discuss the potential for service interruptions for those systems or applications connected to the Internet. Which systems are vulnerable? What would be the impact to the organization for each connected system, if it were to be unavailable?

f. Elevation of Privilege – discuss the systems and applications that might be subject to an attacker elevating his privilege levels (think of a patient database - what would happen if the attacker was able to gain Administrator access to the database?).

4. A section, titled Risk Mitigation Plan, that summarizes your findings for the boss and discusses the security controls that you recommend for each of the potential attacks that you have identified. This can be summarized using the table I’ve provided for you below for each of your threats. Remember to assign the implementation of the recommended security control to a role within the organization (you can use a generic role, such as System Administrator, Database Admin, Security Officer, etc. – your textbook and other supplemental readings listed different organizational roles responsible for managing risk) 20 points.

Risk Mitigation Plan:

Asset

Threat

Impact

Recommended Security Control

Responsible Role

© 2015 by Jones & Bartlett Learning, LLC, an Ascend Learning Company. All rights reserved.

www.jblearning.com Page 3

Homework is Completed By:

Writer Writer Name Amount Client Comments & Rating
Instant Homework Helper

ONLINE

Instant Homework Helper

$36

She helped me in last minute in a very reasonable price. She is a lifesaver, I got A+ grade in my homework, I will surely hire her again for my next assignments, Thumbs Up!

Order & Get This Solution Within 3 Hours in $25/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 3 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 6 Hours in $20/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 6 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

Order & Get This Solution Within 12 Hours in $15/Page

Custom Original Solution And Get A+ Grades

  • 100% Plagiarism Free
  • Proper APA/MLA/Harvard Referencing
  • Delivery in 12 Hours After Placing Order
  • Free Turnitin Report
  • Unlimited Revisions
  • Privacy Guaranteed

6 writers have sent their proposals to do this homework:

Isabella K.
Engineering Exam Guru
Financial Analyst
Top Rated Expert
WRITING LAND
Instant Assignment Writer
Writer Writer Name Offer Chat
Isabella K.

ONLINE

Isabella K.

Being a Ph.D. in the Business field, I have been doing academic writing for the past 7 years and have a good command over writing research papers, essay, dissertations and all kinds of academic writing and proofreading.

$16 Chat With Writer
Engineering Exam Guru

ONLINE

Engineering Exam Guru

I have written research reports, assignments, thesis, research proposals, and dissertations for different level students and on different subjects.

$18 Chat With Writer
Financial Analyst

ONLINE

Financial Analyst

As an experienced writer, I have extensive experience in business writing, report writing, business profile writing, writing business reports and business plans for my clients.

$21 Chat With Writer
Top Rated Expert

ONLINE

Top Rated Expert

I am an experienced researcher here with master education. After reading your posting, I feel, you need an expert research writer to complete your project.Thank You

$48 Chat With Writer
WRITING LAND

ONLINE

WRITING LAND

I am a PhD writer with 10 years of experience. I will be delivering high-quality, plagiarism-free work to you in the minimum amount of time. Waiting for your message.

$20 Chat With Writer
Instant Assignment Writer

ONLINE

Instant Assignment Writer

I have written research reports, assignments, thesis, research proposals, and dissertations for different level students and on different subjects.

$45 Chat With Writer

Let our expert academic writers to help you in achieving a+ grades in your homework, assignment, quiz or exam.

Similar Homework Questions

Multiple choice questions on is lm model - Openstax psychology pdf - How to do reverse polish notation - Discussion question - Organ and Delivery Research Paper 5 - CC-5 - Squatty potty campaign - P - Peoplesoft uct ac za - Stress - What is a factor pair - The zaf radiator company uses a normal costing system - Assignment 1 -1Edu - First solar module datasheet - Leccion 8 en el restaurante - Lorenzo maria raimondo de medici in campitelli di calabria - Kia 7 year warranty - Quantitative nursing research articles on diabetes - Twin tattoo artists salem - Connectivity and its discontents by sherry turkle essay - Identifying and Interpreting Descriptive Statistics - Preparation of adipic acid from cyclohexene using kmno4 - Power point - Precast half round channel - Identifying and Operationalizing variables - Is 20 a composite number - How to calculate standard deviation in casio fx-991ex - Conquering schizophrenia a father his son and a medical breakthrough - Sample marketing plan of cement company - Romeo and juliet short answer questions - Bronfenbrenner defined human development as - Psychotherapy With group - Who sings greensleeves on sons of anarchy - BUS CONT Week 9 Written Assignment - Medicare levy variation declaration - At price p1 the firm in figure 11.1 would produce - Abstract noun examples with pictures - Freedom ride 1965 diary entry - Mkt 571 researching marketing questions - Difference between rococo and neoclassical - Valentine carol ann duffy annotated - Walton is retelling a story he heard from Frankenstein. - Bt margin loan interest rate - Aided self help housing trinidad - What is the difference between excretion and egestion - Under what circumstances might fair trade actually cause harm - Case Study - Couple paragraph each question due on Sunday - BUSINESS ENTITY CASE ANALYSIS - The grave katherine anne porter analysis - The extraordinary science of addictive junk food summary - Possible conflict management and negotiation techniques - Bio Ethics PHI324 - Hr discussion - Annie dillard living like weasels - World Civilization before 1650. Gibby - Components of scheme of work - Case Study: The Ministry of Health’s Strategy for Quality Assurance and Patient Safety - Cvp graph - One steel span tables - Hard drawn steel wire specification - Angular speed to linear speed calculator - Aesop tacit reddit - General equation for combustion - 4.3 3 connect network devices - Anatomy and physiology lab - Advantages and disadvantages of back titration - Positive response due 08/07/20 at 3Pm - Photopills search for location - Personal philosophy of success essay examples - Innatist theory in the classroom - A voltaic cell is constructed with an ag ag+ - Standards - Isotopes and average atomic mass worksheet answers - Collingwood english language school craigieburn - Merck and co case study - A bag of cement of weight 325 n - Homework - The financial detective 2016 case study solution - Coat of arms project ideas - 3d trigonometry gcse exam question practice - Fine for supplying liquor to an intoxicated person - Nursing - Does water conduct electricity - First normal form definition - Cics transaction gateway information center - How to find the multiplicity of a zero - Public Choice and Rent Seeking - Access chapter 6 grader project - Discussion deliver in 12 hours. - Air conditioning license qld - Floating leaf disk photosynthesis lab answers - Social media swot analysis of nike - How to use excel qm - The armada brian patten analysis - Minadex multivitamin liquid boots - How many milliliters in a liter - A capacitor of 10 microfarad is charged - Mkt 571 price and channel strategy - Absorption costing vs direct costing