Learning path

Full curriculum

Full curriculum

Unit content

Threat models, assets and adversaries

A threat model states what must be protected, from whom, and under which assumptions.

The things worth protecting are assets: for example private data, money, computation, credentials or service availability.

An adversary is described by capabilities rather than by a vague label such as “attacker.” Relevant questions include whether the adversary can

  • send chosen inputs;
  • observe network traffic;
  • modify traffic;
  • run unprivileged code locally;
  • steal a device;
  • compromise one component but not another.

A security claim is meaningful only relative to these capabilities. A protocol secure against passive eavesdropping may fail completely if traffic can be modified.

Threat modeling also makes assumptions explicit. If security depends on a secret key remaining secret or on a hardware boundary remaining trustworthy, that assumption belongs in the model.

Security engineering begins by defining the adversary and desired properties before choosing defenses.