flâneur — a map of the web's best reading

Security Principles | Computer Security

textbook.cs161.org · 4,133 words · saved by 1 readers

A threat model is a model of who your attacker is and what resources they have. Attackers target systems for various reasons, be it money, politics, fun, etc. Some aren’t looking for anything logical–some attackers just want to watch the world burn. Take, for example your own personal security. Understanding your threat model has to do with understanding who and why might someone attack you; criminals, for example, could attack you for money, teenagers could attack you for laughs (or to win a dare), governments might spy on you to collect intelligence (but you probably are not important enough for that just yet), or intimate partners could spy on you. Once you understand who your attacker is and what resources they might possess, there are some common assumptions that we take into account for attackers: Finally, be extremely vigilant when dealing with old code as the assumptions that were originally made might no longer be valid and the threat model might have changed. When the Interne

Security Principles | Computer Security Skip to main content Menu Expand (external link) Document Search Copy Copied Computer Security 1. Security Principles 1.1. Know your threat model A threat model is a model of who your attacker is and what resources they have. Attackers target systems for various reasons, be it money, politics, fun, etc. Some aren’t looking for anything logical—some attackers just want to watch the world burn. Take, for example, your own personal security. Understanding your threat model has to do with understanding who and why might someone attack you; criminals, for exa

Explore this link on the map →

related reading