Integrated Security Assessment of WebRTC Video Conferencing Systems: A Complementary Approach Using STRIDE and OWASP ZAP
Abstract
The rapid expansion of remote collaboration has made video conferencing systems complex web services that combine authentication, session management, media streaming, recording repositories, and external integrations. These systems include not only general web application vulnerabilities, but also structural threats such as meeting-room authorization, WebRTC media paths, IP exposure through ICE candidates, and group-key renewal. This study evaluates an integrated security assessment framework combining design-phase STRIDE threat modeling and runtime OWASP ZAP Baseline Scan for a WebRTC-based video conferencing architecture. While unauthenticated passive dynamic scanning without active attack payloads efficiently identifies deployment misconfigurations and browser-policy weaknesses such as A05 Security Misconfiguration, STRIDE addresses structural and access-control risks such as A01 Broken Access Control and A07 Identification and Authentication Failures. In Experiment A, 9 STRIDE threat elements and DREAD risk-prioritization results derived from Microsoft Threat Modeling Tool analysis were used as design-stage evidence. In Experiment B, the same web interface with security headers applied was reassessed with Docker-based OWASP ZAP Baseline Scan, collecting 4 alerts and 8 instances as runtime evidence. The two results were mapped according to OWASP Top 10:2021 to explain detection scope rather than tool superiority. The analysis showed that STRIDE is useful for identifying logical risks, trust boundaries, and authorization relationships that are difficult to observe from HTTP responses alone, whereas ZAP Baseline Scan is effective for verifying configuration errors in deployed web interfaces. This study interprets the two methods as complementary processes combining design-stage threat-scope definition with implementation-stage configuration verification.