Future-Back Threat Modeling: A Foresight-Driven Security Framework
| Source: arXiv AI
Tags: threat modeling, cybersecurity, AI security, risk assessment, arXiv
Future-Back Threat Modeling (FBTM) inverts standard threat modeling: instead of cataloguing known TTPs, it starts from envisioned future threat states — including AI-enabled attacks and supply chain compromises — and works backward to identify assumptions and blind spots in current defense architectures.
Details
Traditional threat modeling is reactive: it focuses on known TTPs and past incident data. This creates a fundamental weakness — the most serious cyber threats often arise from what is assumed, overlooked, or not yet conceived, particularly from AI-enabled attacks, information warfare, and supply chain exploits. FBTM inverts this logic: begin with envisioned future threat states and reason backward to identify assumptions, gaps, and blind spots in current defense architectures. The methodology aims to surface both known unknowns and unknown unknowns — emerging attack vectors and anticipated TTPs that historical data cannot reveal. The framework is assumption-centered and evidence-informed rather than data-driven, helping security leaders make decisions today that shape more resilient postures for the future. A core application is enhancing adversary behavior predictability under future uncertainty. This is a conceptual and methodological paper at v3, substantially revised with explicit adversary/system contextualization. No empirical validation against actual threat data is described. The foresight-driven approach draws from futures studies applied to cybersecurity — a conceptual combination that is intellectually interesting but without quantified validation.