Threat modeling wata tsarin tsari ne don gano abubuwan barazana da suka iya kasuwa ga tsarin da kuma tsara kariya — tunani cikin tsari game da abin da zai iya faruwa, wane zai iya kai hari, da kuma yadda. Gida ce don tsarin tsaron, wanda ake yi lokacin tsarawa.
Abin da threat modeling ne
Threat modeling = systematically analyzing a system to find SECURITY THREATS and decide
how to mitigate them — BEFORE building (or as a review):
→ understand the system (data flows, components, trust boundaries, assets)
→ identify THREATS (what could an attacker do? where are the weak points?)
→ assess and prioritize risks; plan MITIGATIONS
→ proactive security: design defenses by thinking like an attacker, early.
