Unit content
Threat models, assets and adversaries
A threat model states what must be protected, from whom, and under which assumptions.
The things worth protecting are assets: for example private data, money, computation, credentials or service availability.
An adversary is described by capabilities rather than by a vague label such as “attacker.” Relevant questions include whether the adversary can
- send chosen inputs;
- observe network traffic;
- modify traffic;
- run unprivileged code locally;
- steal a device;
- compromise one component but not another.
A security claim is meaningful only relative to these capabilities. A protocol secure against passive eavesdropping may fail completely if traffic can be modified.
Threat modeling also makes assumptions explicit. If security depends on a secret key remaining secret or on a hardware boundary remaining trustworthy, that assumption belongs in the model.
Security engineering begins by defining the adversary and desired properties before choosing defenses.