Elektrine lite

← Feed

@adamshostack@infosec.exchange

2026-09-24 21:50 UTC

Diagrams versus Models (Threat Model Thursday) (New blog post: https://shostack.org/blog/diagrams-versus-models, this is post 1/9) Diagrams are the most recognizable tools and deliverables of threat modeling. (Both functions are important: the working tool of a diagram which helps us ask what can go wrong and the deliverable or record which we keep.)

Replies (1)

  • In the first edition, I used the terms “diagram” and “model” nearly interchangeably. In the second, I get more specific about the differences. The dotted line in a diagram is showing a boundary, or the controls, or where there are different principals. And that’s what it is: A bunch of pixels which show the information. In a model, those properties can be specified and acted on. Or even derived: If each element in a model has an attribute about what account it runs with, then you can locate boundaries automatically. You may even be able to infer things about what enforces the boundary. (Unix kernels, AWS IAM, hope, etc.) (2/9)

    Open ##4840624