Threat modelling is foundational to secure systems engineering and should be done in consideration of the context within which systems operate. On the other hand, the continuous evolution of both the technical sophistication of threats and the system attack surface is an inescapable reality. In this work, we explore the extent to which real-world systems engineering reflects the changing threat context. To this end we examine the desktop clients of six widely used end-to-end-encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short-lived adversarial access against these desktop clients and analyzed the results with respect to two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to both recognise the threats in the evolving context within which systems operate and, more importantly, to mitigate them by rescoping trust boundaries in a manner that those within the administrative boundary cannot violate security and privacy properties. Such a nuanced understanding of trust boundary scopes and their relationship with administrative boundaries allows for better administration of shared components, including securing them with safe defaults.
翻译:威胁建模是安全系统工程的基础,必须结合系统运行环境进行。然而,威胁技术复杂性和系统攻击面的持续演进是不可避免的现实。本研究探讨了真实系统工程实践对不断变化的威胁环境的反映程度。为此,我们考察了六款广泛使用的端到端加密移动通信应用的桌面客户端,探究其在空间维度(启用新平台客户端,如桌面客户端时)和时间维度(新威胁出现时)对威胁模型的调整程度。我们针对这些桌面客户端开展了短期对抗性访问实验,并采用STRIDE和LINDDUN两种主流威胁启发框架对结果进行分析。结果表明,系统设计者不仅需要认知系统运行环境中不断演化的威胁,更关键的是应通过重新界定信任边界来缓解威胁,确保行政边界内的实体无法破坏安全与隐私属性。这种对信任边界范围及其与行政边界关系的深刻理解,有助于更有效地管理共享组件,包括通过安全默认配置加以保护。