Threat Model
Noun · Verb · Security & Infosec
Definitions
A structured analysis of what you're protecting, who might attack it, how they'd do it, and what's most likely to go wrong — ideally performed before you write the first line of code.
In plain English: Thinking through who might want to break in, what they'd be after, and how they'd try — so you can plan defenses before building the system.
Etymology
- 1994
- Edward Amoroso introduces the concept in 'Fundamentals of Computer Security Technology,' formalizing how to think about attackers
- 1999
- Microsoft develops STRIDE (Spoofing, Tampering, etc.) as a structured threat modeling methodology
- 2014
- Adam Shostack publishes 'Threat Modeling: Designing for Security,' making the practice accessible to developers