@adamshostack@infosec.exchange
2026-09-09 22:52 UTC
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-09 22:52
Threat Modeling • In Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design (https://arxiv.org/abs/2607.01711), Doyeon Kim, Jin-Young Choi, Junghee Lee propose a set of analyses modules, including Identity, Spatial, Temporal, and Interpretation. The work is thought provoking. (I would have liked for them to have stayed away from the math long enough to distinguish the types of artifacts they mention, including software packages which are not like inputs, messages or tokens, none of which are expected to be executed.) • In An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling (https://www.semanticscholar.org/paper/An-Empirical-Evaluation-of-Generative-AI-in-and-Martins-Venson/6346903d3a9e236bedb9f060bd57e75625746cb7), F. Martins and Elaine Venson discuss how to use generative AI to support requirements engineering. (3/10)