2025/02/10 by Kieron Ivy Turk, Turk, Kieron Ivy, Anna Talas +3
Computer Science · Engineering · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information and Cyber Security #Safety Systems Engineering in Autonomy #Smart Grid Security and Resilience
paper · pdf · doi:10.48550/arxiv.2502.07116
openalex publication_date 2025/02/10 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/30
Threat modelling is the process of identifying potential vulnerabilities in a system and prioritising them. Existing threat modelling tools focus primarily on technical systems and are not as well suited to interpersonal threats. In this paper, we discuss traditional threat modelling methods and their shortcomings, and propose a new threat modelling framework (HARMS) to identify non-technical and human factors harms. We also cover a case study of applying HARMS when it comes to IoT devices such as smart speakers with virtual assistants.