20–30 min Updated

Insecure Design

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Security begins before you start writing code.

Prevalence
Common
Exploitability
Easy
Impact
Devastating

What is insecure design?

Insecure design is a class of security weakness that comes from missing or flawed security controls in the architecture of an application, rather than from bugs in its code. It occurs when threats are not considered before development begins. Attackers exploit gaps such as missing rate limits or unsafe business logic, which no correct implementation can fix.

What you'll learn

  • How to model threats with data-flow diagrams and STRIDE
  • Why least privilege, trust boundaries and failing securely belong in the design
  • How to build security into each stage of the development life cycle

Where this lesson counts

OWASP Top 10

  • Insecure Design lab

    Work through the habits that make software secure before any code is written: threat modeling with data-flow diagrams and STRIDE, data classification, a disciplined development life cycle, least privilege, input validation, failing securely, trust boundaries and post-mortems that look for process failures.

  • How to prevent Insecure Design

    The prevention guide covers six approaches:

    • Model Your Threats
    • Secure the Development Lifecycle
    • Apply Security Principles
    • Maintain Security
    • Learn from Your Mistakes
    • Keep It Usable
  • Insecure Design quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Toxic Dependencies

    Third-party libraries could be introducing vulnerabilities or malicious code into your system.

  • Lax Security Settings

    Improper security settings are a common cause of vulnerabilities.

  • Logging and Monitoring

    Comprehensive logging and monitoring will tell you what your site is doing at runtime, which is key to spotting security events.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.