The Runtime Theory
Threat Modeling and Trust Boundaries

Threat Modeling Starts With Assets and Boundaries

Threat modeling is a structured way to ask how a system could be misused or attacked.

The Runtime Theory Team5 min read#threat-modeling#trust-boundaries#attack-surface
▸ On this page

The model

Threat modeling is a structured way to ask how a system could be misused or attacked. Begin with assets worth protecting, actors, data flows, and trust boundaries. A boundary marks where assumptions change, such as browser to server, service to database, or tenant to tenant.

A concrete walk-through

A diagram of a file upload can show the browser, API, object store, and image-processing worker. Each crossing raises specific questions: who authenticates the request, how type and size are checked, whether the object name is attacker-controlled, and what privileges the worker receives.

Costs and failure cases

A threat list without mitigations or owners becomes paperwork. Threats depend on the system’s actual deployment and adversaries; generic checklists may miss a risky data flow. Revisit the model when architecture, external exposure, or sensitive data changes.

Check your understanding

Draw the trust boundaries for a password-reset flow and identify one abuse case at each boundary, including the email provider callback.

Further reading

OWASP: Threat Modeling

Not started

Sign in to save your learning progress.

Sign in to save