A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures

Abstract
Threat-score rankings produced by STRIDE models depend on system decomposition, trust labels, and numerical coding. This study audits a published ranking of correspondent banking, closed-loop, infrastructure, and peer-to-peer cross-border payment architectures. The analysis first reweights aggregate rows labeled Outside and derives exact rank-crossover points, defined as the weight values at which the priority ranking of two architectures changes. It then normalizes scores by the number of listed interaction expressions and perturbs the total weight between Inside and Outside labels by up to 10 percentage points. A seeded 100,000-run Monte Carlo experiment samples the multiplier log-uniformly on [1/3, 3] and samples feasible label shifts uniformly. In raw totals, correspondent banking ranks first with probability 0.6905, peer-to-peer with 0.2296, and infrastructure with 0.0799. After normalization, first place is restricted to correspondent banking (0.7189) or closed-loop (0.2811). Transferability is checked using an independent e-payment STRIDE dataset: the leading category changes from information disclosure under summed likelihood-impact products to elevation of privilege after per-scenario normalization. The combined findings indicate that the scoring formula is not the only factor shaping priority rankings. Aggregation choices and model granularity can also influence the rankings to a comparable extent. Since the inputs are ordinal and the simulation distributions are specified rather than empirically calibrated, the resulting outputs should be interpreted as robustness diagnostics, not as incident probabilities or operational risk estimates.
How to Cite

Susila Windarta & Muhammad Yusuf Bambang Setiadji (2026). A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures. JITEK: Jurnal Informatika dan Teknologi Komputer, 6(2), 348-355. https://doi.org/10.55606/jitek.v6i2.12215

Susila Windarta; Muhammad Yusuf Bambang Setiadji, "A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures," JITEK: Jurnal Informatika dan Teknologi Komputer, vol. 6, no. 2, pp. 348-355, 2026.

Susila Windarta; Muhammad Yusuf Bambang Setiadji. "A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures." JITEK: Jurnal Informatika dan Teknologi Komputer, vol. 6, no. 2, 2026, pp. 348-355.

Susila Windarta; Muhammad Yusuf Bambang Setiadji. "A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures." JITEK: Jurnal Informatika dan Teknologi Komputer 6, no. 2 (2026): 348-355.

Susila Windarta & Muhammad Yusuf Bambang Setiadji (2026) 'A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures', JITEK: Jurnal Informatika dan Teknologi Komputer, 6(2), pp. 348-355. doi: 10.55606/jitek.v6i2.12215.

Susila Windarta; Muhammad Yusuf Bambang Setiadji. A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures. JITEK: Jurnal Informatika dan Teknologi Komputer. 2026;6(2):348-355.

Artikel Terkait
Tren Sitasi Jurnal