Skip to main navigation Skip to search Skip to main content

Evaluating the Effectiveness of Stride for Threat Modeling in Healthcare Internet-Of-Things: A Case Study

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The rapid adoption of IoT has introduced novel security challenges. Although IoT testing is effective in uncovering vulnerabilities, it typically occurs late in the development lifecycle. Thus, threat modeling is a good option to for identifying and mitigating risks early on. Although the potential for danger in IoT is high, conventional security models cannot fully capture the risks specific to such ecosystems. To address this challenge, our paper presents a case study to assess the effectiveness of threat modeling frameworks in identifying IoTspecific security threats. This is done by applying the OWASP threat modeling methodology with STRIDE to systematically identify potential threats in a healthcare IoT ecosystem. We then compare the results with real-life examples of IoT vulnerabilities to derive actionable recommendations for strengthening threat-modeling. Our results offer valuable insights to practitioners to understand the capabilities, strengths, and limitations of using STRIDE for identifying IoT-specific threats.

Original languageEnglish
Title of host publicationProceedings - 2025 13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025
EditorsReyes Juarez-Ramirez, Carlos Fernandez y Fernandez, Samantha Jimenez, Alan Ramirez-Noriega, Cesar Guerra-Garcia, Guillermo Licea Sandoval, Jorge Octavio Hernandez-Ocharan, Elvia Aispuro-Felix, Abhishek Kumar, Manuel Alejandro Pastrana Pardo
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages139-148
Number of pages10
ISBN (Electronic)9798331567286
DOIs
Publication statusPublished - 2025
Event13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025 - La Paz, Mexico
Duration: 27 Oct 202531 Oct 2025

Publication series

NameProceedings - 2025 13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025

Conference

Conference13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025
Country/TerritoryMexico
CityLa Paz
Period27/10/2531/10/25

Keywords

  • IoT
  • Secure Software Engineering
  • STRIDE
  • Threat Modeling

Fingerprint

Dive into the research topics of 'Evaluating the Effectiveness of Stride for Threat Modeling in Healthcare Internet-Of-Things: A Case Study'. Together they form a unique fingerprint.

Cite this