Threat Model

Noun · Verb · Security & Infosec

Definitions

  1. A structured analysis of what you're protecting, who might attack it, how they'd do it, and what's most likely to go wrong — ideally performed before you write the first line of code.

    In plain English: Thinking through who might want to break in, what they'd be after, and how they'd try — so you can plan defenses before building the system.

Etymology

1994
Edward Amoroso introduces the concept in 'Fundamentals of Computer Security Technology,' formalizing how to think about attackers
1999
Microsoft develops STRIDE (Spoofing, Tampering, etc.) as a structured threat modeling methodology
2014
Adam Shostack publishes 'Threat Modeling: Designing for Security,' making the practice accessible to developers

Related Terms