arXiv:2511.16088cs.CRcs.AI2025-11

从未来威胁倒推当前防御漏洞,提前发现未知风险

Future-Back Threat Modeling: A Foresight-Driven Security Framework

  • 反向思维:先设想未来威胁场景,再回溯现有架构弱点
  • 识别隐藏盲点,包括新兴和潜在的攻击手段
  • 适合安全决策者用于构建面向未来的韧性体系

传统威胁建模侧重已知攻击手法和历史事件,而威胁预测框架常与实际系统架构脱节。这导致最严重的网络威胁往往源于未知、被忽视或尚未构想的领域,如人工智能、信息战和供应链攻击。为此,本文提出未来倒推威胁建模(FBTM)方法,从设想的未来威胁状态出发,逆向分析当前防御体系中的假设、缺口与盲点,揭示已知未知与未知未知,识别正在出现、可预见且合理的新型攻击手法。该方法提升在不确定性下的对手行为预测能力,帮助安全管理者基于前瞻性判断,采取当下行动以塑造更韧性的未来安全态势。

原文摘要 · Abstract (English)

Traditional threat modeling remains reactive-focused on known TTPs and past incident data, while threat prediction and forecasting frameworks are often disconnected from operational or architectural artifacts. This creates a fundamental weakness: the most serious cyber threats often do not arise from what is known, but from what is assumed, overlooked, or not yet conceived, and frequently originate from the future, such as artificial intelligence, information warfare, and supply chain attacks, where adversaries continuously develop new exploits that can bypass defenses built on current knowledge. To address this mental gap, this paper introduces the theory and methodology of Future-Back Threat Modeling (FBTM). This predictive approach begins with envisioned future threat states and works backward to identify assumptions, gaps, blind spots, and vulnerabilities in the current defense architecture, providing a clearer and more accurate view of impending threats so that we can anticipate their emergence and shape the future we want through actions taken now. The proposed methodology further aims to reveal known unknowns and unknown unknowns, including tactics, techniques, and procedures that are emerging, anticipated, and plausible. This enhances the predictability of adversary behavior, particularly under future uncertainty, helping security leaders make informed decisions today that shape more resilient security postures for the future.

威胁建模前瞻性安全攻防对抗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。