Uppsats
Server-Side Threat Modeling in Client-Server Architecture : Threat-Model-Driven Backend Hardening in Resource-Constrained Client-Server Systems
Kandidat-uppsats
Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
Publicerad: 2026
Språk: Engelska
Sammanfattning
This thesis investigates how threat modeling can be used as an architectural decision tool when designing secure backend systems for resource-constrained client-server environments. In such environments, the security controls cannot be selected only according to the general best practices: each control added will increase service complexity and potentially affect the overall system performance. The central problem then, becomes not only system hardening, but the selection of the appropriate measures to apply within the computational limits of the hardware infrastructure. This study applies the STRIDE methodology to identify and classify relevant threats, and the resulting threat model is used to reason about the actual implementation architecture. OWASP security references are used as supporting material for mapping identified threats to common web and mobile application risks. To evaluate this process, a proof-of-concept client-server system is implemented, treating the backend technology stack as a variable rather than a fixed requirement, to allow the thesis to examine if a lighter architecture can provide adequate security properties while keeping the operational overhead low. The selected security mechanisms are implemented both at deployment level and in the application code. The system implementation is then reviewed by comparing its performance and operational behavior before and after the controls are introduced. This assessment focuses on the relationship between security hardening and resource consumption rather than on proving complete security. This thesis aims to contribute by providing a structured account of how a threat model-driven approach can support architectural decision-making in constrained client-server systems, where security requirements must be balanced against performance, deployment complexity, and operational cost. The evaluation showed that the hardened configuration preserved service availability and completed all benchmark requests successfully. The aggregate average request time increased from 7.140 ms to 7.312 ms, corresponding to an increase of approximately 0.172 ms, or 2.41%. The results indicate that the selected controls were feasible in the tested constrained environment and introduced only a small latency overhead for the implemented proof-of-concept.
Information
- Författare
- Rodrigo Verdu, Juan
- Lärosäte / institution
- Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
- Publiceringsdatum
- 2026
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Yrkesexamen på avancerad nivå, Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
Hassan, Nour Al Dine
Publicerad: 2026
Kandidat-uppsats, Linköpings universitet/Institutionen för datavetenskap
Alvarsson, Jacob, Billenius, Love, Ericsäter, Jonas
Publicerad: 2026
Kandidat-uppsats, Mälardalens universitet/Institutionen för datavetenskap och datateknik
Falk, Henrik
Publicerad: 2026
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Farmaki, Athanasia
Publicerad: 2026
Yrkesexamen på avancerad nivå, Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Gustafsson, William, Hedin, Christoffer
Publicerad: 2026
Kandidat-uppsats, Högskolan i Skövde/Institutionen för informationsteknologi
Bukaric, Ismail
Publicerad: 2026