Threat Models over Space and Time: A Case Study of E2EE Messaging Applications

01/13/2023
by   Partha Das Chowdhury, et al.
0

Threat modelling is foundational to secure systems engineering and should be done in consideration of the context within which systems operate. On the other hand, the continuous evolution of both the technical sophistication of threats and the system attack surface is an inescapable reality. In this work, we explore the extent to which real-world systems engineering reflects the changing threat context. To this end we examine the desktop clients of six widely used end-to-end-encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short-lived adversarial access against these desktop clients and analyzed the results with respect to two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to both recognise the threats in the evolving context within which systems operate and, more importantly, to mitigate them by rescoping trust boundaries in a manner that those within the administrative boundary cannot violate security and privacy properties. Such a nuanced understanding of trust boundary scopes and their relationship with administrative boundaries allows for better administration of shared components, including securing them with safe defaults.

READ FULL TEXT
research
07/20/2022

Fair Context-Aware Privacy Threat Modelling

Given the progressive nature of the world today, fairness is a very impo...
research
10/19/2020

The Impact of DNS Insecurity on Time

We demonstrate the first practical off-path time shifting attacks agains...
research
06/07/2023

A GDPR-compliant Risk Management Approach based on Threat Modelling and ISO 27005

Computer systems process, store and transfer sensitive information which...
research
11/12/2018

SD-WAN Threat Landscape

Software Defined Wide Area Network (SD-WAN or SDWAN) is a modern concept...
research
05/12/2021

Security for Emerging Miniaturized Wireless Biomedical Devices: Threat Modeling with Application to Case Studies

The landscape of miniaturized wireless biomedical devices (MWBDs) is rap...
research
01/31/2021

A Trust-Based Approach for Volunteer-Based Distributed Computing in the Context of Biological Simulation

As simulating complex biological processes become more important for mod...
research
01/30/2023

Threat Modelling in Virtual Assistant Hub Devices Compared With User Risk Perceptions (2021)

Despite increasing uptake, there are still many concerns as to the secur...

Please sign up or login with your details

Forgot password? Click here to reset