🏠 首页
基准测试
📊 所有基准测试 🦖 恐龙 v1 🦖 恐龙 v2 ✅ 待办事项应用 🎨 创意自由页面 🎯 FSACB - 终极展示 🌍 翻译基准测试
模型
🏆 前 10 名模型 🆓 免费模型 📋 所有模型 ⚙️ 🛠️ 千行代码模式
资源
💬 💬 提示库 📖 📖 AI 词汇表 🔗 🔗 有用链接
advanced

Comprehensive Threat Modeling

#security #threat-modeling #api #risk-analysis

Perform a threat model analysis on a hypothetical fintech API.

Act as a Security Architect. Perform a comprehensive threat model assessment for a new RESTful API for a peer-to-peer payment platform. Assume the API uses OAuth 2.0 and handles sensitive financial data. Identify potential threats across the STRIDE model (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). For each identified threat, propose a specific mitigation strategy involving cryptography, rate limiting, input validation, or infrastructure design. Prioritize the risks by severity.