skip to content

Fundamentals and Scoping

The frame every model hangs on: Shostack's four questions, the assets and goals at stake, the actor you assume, and where scope stops. Skip it and the model finds the wrong things.

on this pageshow

explore

questions

29

In a threat model, how do integrity, authenticity and non-repudiation differ as goals?

level: juniorimportance: must knowfreq 66%

answer

  1. three properties, not one
  2. unchanged data versus genuine origin
  3. intact but forged is possible
  4. who has to be convinced
  5. proof that survives an outsider

basics

~20 s

Integrity means data has not been altered outside authorised change. Authenticity means the claimed origin of a message or request is genuine. Non-repudiation means the originator cannot later credibly deny it, with evidence that convinces a third party.

solid answer

~40 s

They are three separate properties, and a model that collapses them loses threats. Integrity is about the data itself: a stored payment instruction still says what it said when it was written. Authenticity is about origin: the instruction really came from the account it claims, not from an impostor — a message can be perfectly intact and completely forged. Non-repudiation is about proof to an outsider: the sender cannot later say `that wasn't me` and leave you with no way to show otherwise. It is strictly stronger than authenticity, because an adjudicator has to be convinced, not just the receiver. So you can have integrity without authenticity, and authenticity without non-repudiation, and you state whichever one the system actually needs, because they buy different controls.

go deeper

for a junior

Be ready to define each of the three in one sentence and name a system where each one dominates. Interviewers use this as a vocabulary check before letting you near a diagram.

for a middle

Expect to show how the three come apart: an intact forgery, or an origin you believe but cannot prove to an outsider. You should be able to say which property a given threat violates.

for a senior

Pick the property that actually drives the design under discussion and defend deprioritising the others, then name the threats that vanish from the model when a goal is left unstated.

for a principal

Own the goal vocabulary teams write with. If everyone only ever writes confidentiality goals, entire threat classes are structurally invisible across every model, and more modelling effort will not surface them.

## Why goals, not adjectives A threat model needs security **goals** — statements about the system that a concrete scenario could prove false. A **threat** is then a hypothesised way one of those goals comes out false. If your goal vocabulary is coarse, whole categories of threat have nowhere to land. Integrity, authenticity and non-repudiation are the three that get conflated most often, and each buys a different design. ## Integrity Integrity is a property of **the data or the computation**: it is what it was last legitimately made to be. A record that is byte-identical to what was written, a message that arrives as it was sent, a balance that only ever changed through an authorised operation. The violation is unauthorised modification — someone altered a stored filing, flipped a flag, reordered a queue, replayed a request so a transfer happened twice. Note what integrity says nothing about: **who** produced the data in the first place. An attacker who legitimately gets to write a record and writes something false has not broken integrity in this sense; the record faithfully holds what was submitted. That is a different problem, and it is why the next property exists. ## Authenticity Authenticity is a property of **origin**: the message, request or document really comes from the party it claims. The violation is impersonation — a forged instruction, a request that claims to be from the payments service and is not, a document that claims a signatory it never had. The two come apart in both directions, which is the point interviewers probe: - **Intact but forged.** A crafted instruction can be perfectly well-formed and unmodified in transit, and still originate from an impostor. Integrity holds; authenticity does not. - **Authentic but altered.** A message you know came from the right party, then modified downstream, has an authentic origin and broken integrity. In practice mechanisms often deliver both at once, which is exactly why people assume they are one property. In the model they must stay separate, because the threats and the assets differ: the loss from a forged instruction is not the loss from a corrupted archive. ## Non-repudiation Non-repudiation is about **evidence that persuades someone who was not there**. Authenticity asks: am I, the receiver, satisfied this came from you? Non-repudiation asks: could I convince a third party — an auditor, a court, an arbitration panel — that it came from you, over your denial? That extra requirement rules out whole classes of mechanism. If two parties share one secret and either could have produced the same evidence, the receiver is convinced but an outsider cannot tell which party acted. You have authenticity without non-repudiation. Non-repudiation needs evidence only one party could have created, and it needs the surrounding process — who held what, when, and how it was bound to an identity — to survive being questioned later. It is also the goal most often stated by accident. Teams write "we need an audit trail" — but an audit trail is a **control**, and stating it as the goal fixes the answer before you have asked the question. The goal is the outcome: the party who acted cannot credibly deny acting. Which mechanism achieves that is the next conversation, and keeping them separate is what lets you notice that the chosen mechanism does not. ## The neighbouring goals The same list normally carries three more properties: - **Confidentiality** — the data is not read by parties who should not read it. - **Availability** — the function is there when it is needed. For many systems this is the dominant goal, and a model that only writes confidentiality and integrity goals has structurally hidden it. - **Privacy** — whether collecting, linking, retaining or inferring about a person is legitimate at all. This is not a synonym for confidentiality: a system can keep data perfectly unread and still violate privacy by over-collecting or re-identifying, and its adversary is often a legitimate insider using legitimate access. Privacy as a full modelling discipline is its own method and its own topic. ## Using the distinction When you look at a design, name the property per asset rather than reciting the list. A public record system usually leads with authenticity and non-repudiation, because the content is meant to be readable and the loss is a fake or disowned entry. A commodity content service may lead with availability. A system holding trade secrets leads with confidentiality. The property you write down decides which threats survive triage, so getting the three apart is not vocabulary pedantry — it is what stops a whole class of threats from being invisible.

  • Can a system have authenticity but not non-repudiation? Give an example.
    Yes. When two parties share one secret and both can produce the same evidence on a message, the receiver is convinced of the origin because only those two hold the secret. But an outsider cannot tell which of them produced it, so neither can be held to it later. That is origin confidence without third-party proof, which is why non-repudiation goals demand evidence only one party could create.
  • Where does privacy sit relative to confidentiality in a goal list?
    Confidentiality is about data being read by the wrong party. Privacy is about whether collecting, linking, retaining or inferring is legitimate for the person the data describes. A system can maintain perfect confidentiality and still violate privacy by over-collecting or re-identifying, and the actor is usually someone with legitimate access. Write them as separate goals or the privacy threats never appear.
  • Why does availability belong in the same goal list?
    Because for many systems the loss that matters is the function not working, not any record being read or altered. If a model only carries confidentiality and integrity goals, every denial threat has nowhere to land and quietly drops out of triage. An availability goal has to name a scale and a window to be usable, otherwise it cannot be violated on paper.

saying these in an interview costs you the question

  • Treats integrity and authenticity as the same property
  • Reduces non-repudiation to 'we keep logs'
  • Claims a forged message must also be corrupted
  • Lists only confidentiality, integrity and availability as possible goals
  • Uses confidentiality and privacy interchangeably

context

open as a page

What are the four questions in Shostack's four-question threat modeling frame?

level: juniorimportance: must knowfreq 80%

basics

~20 s

What are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job? They run in that order and repeat as a loop, not a one-off checklist.

open as a page

In threat modeling, what is an actor assumption and how does it bound the threats you keep?

level: middleimportance: must knowfreq 62%

basics

~20 s

An actor assumption is a written statement of the adversary you defend against: their capability, resources and access. It bounds the model, because a threat stays in scope only if that assumed actor could reach and carry it out.

open as a page

For a stadium ticketing on-sale, which assets must the threat model protect?

level: middleimportance: must knowfreq 58%

basics

~20 s

The assets are the ability to complete a purchase during the on-sale window, fair allocation of the inventory, the revenue, and fan trust. Seat-map confidentiality carries almost no loss — here availability and functionality are the assets, not stored data.

open as a page

In a threat model, what does a recorded assumption need to contain to be useful?

level: middleimportance: must knowfreq 55%

basics

~20 s

A usable assumption states the claim in a form that could be proved false, names the team that owns it, says which threats come back if it is wrong, and gives an event or date that forces a recheck.

open as a page

Why does threat modeling aim to raise attacker cost above expected gain rather than eliminate a threat?

level: middleimportance: must knowfreq 66%

basics

~20 s

Most threats follow from the functionality existing, so they can be priced but not removed. A control succeeds when an attempt costs the attacker more than a success is worth, so a rational attacker stops or goes elsewhere.

open as a page

What concrete artifacts should a threat modeling session hand back when it ends?

level: middleimportance: must knowfreq 66%

basics

~20 s

Findings that each name a person who owns them, security requirements written into the work being built, abuse test cases for the threats worth exercising, and a diagram corrected to match how the system actually works.

open as a page

In a threat modeling session, what is the system boundary and how do you decide what falls inside it?

level: middleimportance: must knowfreq 68%

basics

~20 s

The system boundary is the explicit line naming which components, dependencies and people a threat model reasons about. Draw it around what your team can act on, and record everything else on a written out-of-scope list.

open as a page

What is missing from the threat statement "there is no rate limiting on the OTP endpoint"?

level: middleimportance: must knowfreq 62%

basics

~20 s

That sentence names a missing control, not something that could go wrong. A threat statement has to name an actor, the entry point they reach, the action they take, the asset affected, and the concrete impact.

open as a page

Which Threat Modeling Manifesto anti-pattern does one engineer authoring every team's model create, and how do you break it?

level: principalimportance: must knowfreq 64%

basics

~20 s

The Hero Threat Modeler anti-pattern. The Manifesto holds that threat modeling needs no innate gift, so the fix is moving the specialist from authoring models to reviewing what teams author, not hiring a second hero.

open as a page

What are the Threat Modeling Manifesto's five value pairs, and what does valuing one side over the other commit you to?

level: middleimportance: should knowfreq 48%

basics

~20 s

The Threat Modeling Manifesto values finding and fixing design issues over checkbox compliance, people over process and tools, understanding as a journey over a snapshot, doing over talking, and continuous refinement over one delivery. Right-hand items are lesser goods, not worthless.

open as a page

Your ballot-tabulation threat model assumed operators are always supervised; that assumption drops. What changes?

level: seniorimportance: should knowfreq 52%

basics

~20 s

The design is unchanged, so only threats whose reachability rested on supervision change status. Tampering and repudiation now dominate because the asset is the truth of the count, and every control whose strength came from supervision is unsupported.

open as a page

Which assets are a drug-discovery startup's crown jewels, and how do you defend that ranking?

level: seniorimportance: should knowfreq 47%

basics

~20 s

The crown jewels are the molecule-screening model weights and the accumulated wet-lab result set: losing either hands a competitor the company's entire scientific lead. The sales CRM holds more records but the company survives losing it. Rank by which loss is unrecoverable.

open as a page

For a court e-filing system, how do you write security goals that can be falsified?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Write each goal so a single concrete scenario could prove it false: 'a filing cannot be attributed to a bar member who did not submit it.' Name the asset, the property and the condition. 'Filings shall be secure' is untestable.

open as a page

Your threat model assumes another team tokenises PII upstream — how should you treat that inherited control?

level: seniorimportance: should knowfreq 46%

basics

~10 s

Treat it as an assumption rather than a mitigation: name the owning team, confirm exactly which fields and which paths are covered, and keep the threat open with residual risk until that confirmation lands.

open as a page

Where does threat modeling's rational cost-versus-gain assumption about attackers break down?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Cost-versus-gain reasoning only describes an attacker spending their own budget for profit. It fails when the payoff is personal, when a third party funds the attack to impose loss on you, and when per-target cost is near zero.

open as a page

How do you answer Shostack's fourth question — did we do a good enough job?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Check three things about the modeling work: that the model matched the system actually built, that enumeration reached every part of that model, and that each decision from question three has evidence it exists in the running system.

open as a page

Which Threat Modeling Manifesto anti-patterns explain a session spending ninety minutes on one exotic threat, and how do you steer it back?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Admiration for the Problem, analysis that never reaches a practical solution, plus Tendency to Overfocus, where one threat eats the attention the rest of the model needed. Force every threat to a decision, and sweep the whole system before deepening any part.

open as a page

Your threat model flagged an unauthenticated firmware-push path; a pentest did not exploit it. Is the finding closed?

level: seniorimportance: should knowfreq 48%

basics

~10 s

No. A pentest tests one build, from the positions a tester could reach, in a limited window, so failing to exploit something is not evidence the design constrains an attacker.

open as a page

How do you scope a threat model to a new caseload-export feature on a twelve-year-old case-management monolith?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Model the change, not the monolith. Scope covers the new behaviour, the data the change newly exposes, and every existing control the change leans on or alters. Pre-existing weaknesses in untouched code go to a backlog, not into this session.

open as a page

How do you split a threat statement that bundles four separate threats in a refund flow?

level: seniorimportance: should knowfreq 45%

basics

~10 s

Split wherever two clauses could get different answers — a different owner, a different mitigation, or a different accept-versus-fix decision. Each resulting sentence keeps its own actor, entry point, action, asset and impact.

open as a page

How does attacker-defender cost asymmetry shape defending 400 legacy sites with one engineer?

level: principalimportance: should knowfreq 34%

basics

~20 s

An attacker develops a technique once and replays it across every site, so their cost scales with techniques and the defender's with sites times techniques. Winning means buying that shape: shrink the estate, share the controls.

open as a page

Your organisation starts treating threat models as both audit evidence and its risk register. How do you respond?

level: principalimportance: should knowfreq 36%

basics

~20 s

Push back on both. A threat model asserts intent about one design at a point in time; an audit needs evidence a control operated over a period, and a register is a maintained, organisation-wide list.

open as a page

Which Threat Modeling Manifesto anti-pattern is a six-week, 200-element diagram with no threats enumerated yet?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

Perfect Representation. The Manifesto's answer is that no single ideal view of a system exists, so several partial representations that each illuminate different problems beat one supposedly complete model — and the analysis should have started weeks ago.

open as a page

How do you defend writing 'a nation-state adversary is out of assumed capability' into a threat model?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Defend it as a bound, not a shrug: justify it from the assets rather than from team size, state which threats it leaves untreated, get agreement from whoever owns the consequence, and record the triggers that would force a revisit.

open as a page

How do you stop a threat model's recorded assumptions from silently going stale as the system changes?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Make the assumptions list, not the diagram, the thing under review: give each assumption an owner, an event trigger or expiry, and a hook in design review so change authors are asked whether their change invalidates one.

open as a page

You inherit a service whose four threat-modeling questions were answered in a wiki page two years ago - how do you restart the loop?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Treat the old answers as claims, not as current state. Re-answer question one against the system as it runs today, keep the recorded decisions and the reasons behind them, and verify which of those mitigations actually exist.

open as a page

You have five days to threat-model an acquired company's entire estate. How do you bound it?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Bound by the decision the model must support, not by inventory completeness. Slice by asset, time-box each slice, and ship the explicit list of what you did not examine as a first-class deliverable alongside what you found.

open as a page

"A hacker breaches the plant historian, causing a security breach" — what standard do you set for threat statements?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Require a bounded actor described by the access they already hold and an impact stated as an operational loss. A statement nobody can dispute, test or close is not a finding — it is a mood.

open as a page