Publish Your Threat Models! The benefits far outweigh the dangers

📅 2025-11-11
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Current technology vendors commonly lack granular security disclosures, issuing only vague “security statements,” thereby impeding visibility and assurance across the software supply chain. Method: This paper introduces the Public Threat Model (PTM) paradigm—a systematic approach to enhance cross-organizational security transparency and collaborative defense. We design a PTM construction framework applicable to both open-source and commercial components, incorporating threat modeling, sensitive information anonymization, versioned updates, and regulatory compliance alignment. We further provide actionable publication guidelines and review procedures. Contribution/Results: Our work enables the transformation of proprietary internal threat models into standardized, verifiable, and integrable public assets. This empowers procuring organizations to rigorously assess security posture and allows vendors to differentiate through demonstrable security capabilities—establishing a novel, practice-grounded paradigm for building trustworthy software supply chains.

Technology Category

Application Category

📝 Abstract
Threat modeling has long guided software development work, and we consider how Public Threat Models (PTM) can convey useful security information to others. We list some early adopter precedents, explain the many benefits, address potential objections, and cite regulatory drivers. Internal threat models may not be directly suitable for disclosure so we provide guidance for redaction and review, as well as when to update models (published or not). In a concluding call to action, we encourage the technology community to openly share their PTMs so the security properties of each component are known up and down the supply chain. Technology providers proud of their security efforts can show their work for competitive advantage, and customers can ask for and evaluate PTMs rather than be told"it's secure"but little more. Many great products already have fine threat models, and turning those into PTMs is a relatively minor task, so we argue this should (and easily could) become the new norm.
Problem

Research questions and friction points this paper is trying to address.

Promoting public disclosure of threat models for security transparency
Addressing objections and providing guidance for threat model publication
Enabling supply chain security evaluation through shared threat models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Publishing Public Threat Models openly
Providing redaction and review guidance
Encouraging PTM sharing across supply chain
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Shostack + Associates