Home
World Journal of Advanced Research and Reviews
International Journal with High Impact Factor for fast publication of Research and Review articles

Main navigation

  • Home
    • Journal Information
    • Editorial Board Members
    • Reviewer Panel
    • Abstracting and Indexing
    • Journal Policies
    • Our CrossMark Policy
    • Publication Ethics
    • Issue in Progress
    • Current Issue
    • Past Issues
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Join Editorial Board
    • Join Reviewer Panel
  • Contact us
  • Downloads

eISSN: 2581-9615 || CODEN: WJARAI || Impact Factor 8.2 ||  CrossRef DOI

Research and review articles are invited for publication in March 2026 (Volume 29, Issue 3) Submit manuscript

Threat Modeling for APIs in microservices architectures: A practical framework

Breadcrumb

  • Home
  • Threat Modeling for APIs in microservices architectures: A practical framework

Ishva Jitendrakumar Kanani 1, * and Rashi Nimesh Kumar Dhenia 2

1 Department of Computer Science Engineering, Kent State University, Kent, Ohio, USA.
2 Department of Computer Engineering, Purdue University, Indianapolis, Indiana, USA.
 
Review Article
World Journal of Advanced Research and Reviews, 2022, 14(03), 853-856
Article DOI: 10.30574/wjarr.2022.14.3.0458
DOI url: https://doi.org/10.30574/wjarr.2022.14.3.0458
 
Received on 16 April 2022; revised on 26 June 2022; accepted on 29 June 2022
 
The rapid evolution of microservices and cloud-native architectures has made Application Programming Interfaces (APIs) a critical backbone for modern software systems. However, this shift also introduces complex security risks due to decentralized ownership, ephemeral service interactions, and increased external exposure. Threat modeling provides a structured and proactive approach to identifying and mitigating these risks before they manifest. This paper proposes a practical and adaptable framework for conducting API-centric threat modeling within microservices environments. It synthesizes established methodologies such as STRIDE and data flow diagrams (DFDs), integrates them with modern DevSecOps and Zero Trust principles, and aligns the framework with agile delivery processes. A real-world case study illustrates the application of this methodology to a Kubernetes-based retail platform, highlighting common risks and corresponding mitigations. The paper concludes with a call for continuous threat modeling, emphasizing its role as a living activity essential to securing distributed systems in 2022 and beyond.
 
Threat Modeling; API Security; Microservices; Cloud-Native; STRIDE; OWASP; Zero Trust; Security Architecture; DevSecOps; Kubernetes
 
https://wjarr.com/sites/default/files/fulltext_pdf/WJARR-2022-0458.pdf

Preview Article PDF

Ishva Jitendrakumar Kanani and Rashi Nimesh Kumar Dhenia. Threat Modeling for APIs in microservices architectures: A practical framework. World Journal of Advanced Research and Reviews, 2022, 14(3), 853-856. Article DOI: https://doi.org/10.30574/wjarr.2022.14.3.0458

Copyright © Author(s). All rights reserved. This article is published under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, sharing, adaptation, distribution, and reproduction in any medium or format, as long as appropriate credit is given to the original author(s) and source, a link to the license is provided, and any changes made are indicated.


All statements, opinions, and data contained in this publication are solely those of the individual author(s) and contributor(s). The journal, editors, reviewers, and publisher disclaim any responsibility or liability for the content, including accuracy, completeness, or any consequences arising from its use.

Get Certificates

Get Publication Certificate

Download LoA

Check Corssref DOI details

Issue details

Issue Cover Page

Editorial Board

Table of content

Copyright © 2026 World Journal of Advanced Research and Reviews - All rights reserved

Developed & Designed by VS Infosolution