Elektrine lite

← Feed

@adamshostack@infosec.exchange

2026-09-09 22:52 UTC

Threat Modeling • In Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design (https://arxiv.org/abs/2607.01711), Doyeon Kim, Jin-Young Choi, Junghee Lee propose a set of analyses modules, including Identity, Spatial, Temporal, and Interpretation. The work is thought provoking. (I would have liked for them to have stayed away from the math long enough to distinguish the types of artifacts they mention, including software packages which are not like inputs, messages or tokens, none of which are expected to be executed.) • In An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling (https://www.semanticscholar.org/paper/An-Empirical-Evaluation-of-Generative-AI-in-and-Martins-Venson/6346903d3a9e236bedb9f060bd57e75625746cb7), F. Martins and Elaine Venson discuss how to use generative AI to support requirements engineering. (3/10)

Replies (1)

  • Appsec • Google released a blog post How we’re making Chrome and the web safer in the AI Era (https://blog.google/security/chrome-stronger-with-every-update/), which includes, but isn’t limited to threat modeling, still done by humans and recorded in security.md files. • In Overhead of Recording Feature Locations with Embedded Annotations (https://se.rub.de/wp-content/uploads/2026/07/2026-variability-overhead.pdf), Johan Martinson, Kevin Hermann, and Thorsten Berger show that lightweight annotations that define where features are help find feature-related code. (There’s security relevance in knowing where your security features show up in the code.) (4/10)

    Open ##4673163