Future-Back Threat Modeling: A Foresight-Driven Security Framework
By: Vu Van Than
Potential Business Impact:
Predicts future cyber attacks before they happen.
Traditional threat modeling remains reactive-focused on known TTPs and past incident data, while threat prediction and forecasting frameworks are often disconnected from operational or architectural artifacts. This creates a fundamental weakness: the most serious cyber threats often do not arise from what is known, but from what is assumed, overlooked, or not yet conceived, and frequently originate from the future, such as artificial intelligence, information warfare, and supply chain attacks, where adversaries continuously develop new exploits that can bypass defenses built on current knowledge. To address this mental gap, this paper introduces the theory and methodology of Future-Back Threat Modeling (FBTM). This predictive approach begins with envisioned future threat states and works backward to identify assumptions, gaps, blind spots, and vulnerabilities in the current defense architecture, providing a clearer and more accurate view of impending threats so that we can anticipate their emergence and shape the future we want through actions taken now. The proposed methodology further aims to reveal known unknowns and unknown unknowns, including tactics, techniques, and procedures that are emerging, anticipated, and plausible. This enhances the predictability of adversary behavior, particularly under future uncertainty, helping security leaders make informed decisions today that shape more resilient security postures for the future.
Similar Papers
Future-Back Threat Modeling: A Foresight-Driven Security Framework
Cryptography and Security
Predicts future cyberattacks before they happen.
Publish Your Threat Models! The benefits far outweigh the dangers
Cryptography and Security
Lets companies show how safe their tech is.
Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths Forward
Cryptography and Security
Helps people understand online dangers better.