Threat Modeling¶
Shostack, A. (2014). Threat Modeling: Designing for Security. Wiley.
Cited by¶
5 citations across 5 artifacts.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Authentication
- Authentication enables a family of structural reasoning moves. Threat-model reasoning: for any procedure, the questions are which impostors it stops and which it lets through, which forces enumeration of attack classes — replay, phishing, forgery, side-channel — and a defence matrix against them.
This sourceDevelops systematic threat-model reasoning via STRIDE — enumerating attacker classes (spoofing, replay, tampering) a procedure must stop — central to authentication design.
- Authentication enables a family of structural reasoning moves. Threat-model reasoning: for any procedure, the questions are which impostors it stops and which it lets through, which forces enumeration of attack classes — replay, phishing, forgery, side-channel — and a defence matrix against them.
- Center Of Gravity
- Cybersecurity and resilience engineering: the single service — identity provider, certificate authority, key resolver — whose compromise cascades into systemic failure; threat modelling asks for the COG and defensive design duplicates or compartmentalises it.
This sourceStandard reference on STRIDE and attack trees and the crown-jewel/critical-asset framing — what single compromise (an identity provider or certificate authority) ends the game — with duplicate/distribute/harden/compartmentalize defenses.
- Cybersecurity and resilience engineering: the single service — identity provider, certificate authority, key resolver — whose compromise cascades into systemic failure; threat modelling asks for the COG and defensive design duplicates or compartmentalises it.
- Persona
- Pedagogy. Learner personas — the novice with no background, the second-career learner with rusty prerequisites, the heritage speaker with high oral comprehension but low literacy — surface scaffolds that an "average learner" assumption hides. Public-service design. Citizen personas (the rural elderly user, the recent immigrant, the shift worker) surface access friction that a median-citizen assumption conceals. Security engineering. Threat-actor personas — the script-kid, the financially motivated criminal, the nation-state actor, the malicious insider — let defenders reason concretely about attacker capability, motivation, and likely attack paths.
This sourceDevelops threat-actor archetypes (script-kiddie, organized criminal, nation-state, malicious insider) by motivation and capability to drive defensive design.
- Pedagogy. Learner personas — the novice with no background, the second-career learner with rusty prerequisites, the heritage speaker with high oral comprehension but low literacy — surface scaffolds that an "average learner" assumption hides. Public-service design. Citizen personas (the rural elderly user, the recent immigrant, the shift worker) surface access friction that a median-citizen assumption conceals. Security engineering. Threat-actor personas — the script-kid, the financially motivated criminal, the nation-state actor, the malicious insider — let defenders reason concretely about attacker capability, motivation, and likely attack paths.
- Red Teaming In Strategy
- The penetration-testing insight that an adversary willing to spend X will find vulnerabilities normal-use testing for 100X will not ports to AI capability evaluations, where red-team probing finds elicitation paths benchmark suites miss, and the vocabulary of kill chains and attack surfaces ports with it.
This sourceCodifies kill-chain and attack-surface analysis, the adversarial vocabulary that ports from penetration testing into other capability evaluations.
- The penetration-testing insight that an adversary willing to spend X will find vulnerabilities normal-use testing for 100X will not ports to AI capability evaluations, where red-team probing finds elicitation paths benchmark suites miss, and the vocabulary of kill chains and attack surfaces ports with it.
Domain-specific¶
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Links previously used in the corpus¶
Before the registry existed this work was also linked 2 other ways.
- https://www.wiley.com/en-us/Threat+Modeling:+Designing+for+Security-p-9781118809990 ×1
- https://www.worldcat.org/oclc/855043351 ×1
Registry ID ref:060927ebddea · see in the full table