Muhammad Yusuf Bambang Setiadji
Unknown Affiliation

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

A Robustness Audit of STRIDE-Based Threat-Score Rankings in Cross-Border Payment Architectures Susila Windarta; Muhammad Yusuf Bambang Setiadji
Jurnal Informatika Dan Tekonologi Komputer (JITEK) Vol. 6 No. 2 (2026): Juli : Jurnal Informatika dan Tekonologi Komputer
Publisher : Pusat Riset dan Inovasi Nasional

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.55606/jitek.v6i2.12215

Abstract

Threat-score rankings produced by STRIDE models depend on system decomposition, trust labels, and numerical coding. This study audits a published ranking of correspondent banking, closed-loop, infrastructure, and peer-to-peer cross-border payment architectures. The analysis first reweights aggregate rows labeled Outside and derives exact rank-crossover points, defined as the weight values at which the priority ranking of two architectures changes. It then normalizes scores by the number of listed interaction expressions and perturbs the total weight between Inside and Outside labels by up to 10 percentage points. A seeded 100,000-run Monte Carlo experiment samples the multiplier log-uniformly on [1/3, 3] and samples feasible label shifts uniformly. In raw totals, correspondent banking ranks first with probability 0.6905, peer-to-peer with 0.2296, and infrastructure with 0.0799. After normalization, first place is restricted to correspondent banking (0.7189) or closed-loop (0.2811). Transferability is checked using an independent e-payment STRIDE dataset: the leading category changes from information disclosure under summed likelihood-impact products to elevation of privilege after per-scenario normalization. The combined findings indicate that the scoring formula is not the only factor shaping priority rankings. Aggregation choices and model granularity can also influence the rankings to a comparable extent. Since the inputs are ordinal and the simulation distributions are specified rather than empirically calibrated, the resulting outputs should be interpreted as robustness diagnostics, not as incident probabilities or operational risk estimates.