USENIX Security2024Top-tier venue
"There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical Devices
Ronald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel Votipka
Abstract
Threat modeling is considered an essential first step for "secure by design" development. Significant prior work and industry efforts have created novel methods for this type of threat modeling, and evaluated them in various simulated settings. Because threat modeling is context-specific, we focused on medical device security experts as regulators require it, and "secure by design" medical devices are seen as a critical step to securing healthcare. We conducted 12 semi-structured interviews with medical device security experts, having participants brainstorm threats and mitigations for two medical devices. We saw these experts do not sequentially work through a list of threats or mitigations according to the rigorous processes described in existing methods and, instead, regularly switch strategies. Our work consists of three major contributions. The first is a two-part process model that describes how security experts 1) determine threats and mitigations for a particular component and 2) move between components. Second, we observed participants leveraging use cases, a strategy not addressed in prior work for threat modeling. Third, we found that integrating safety into threat modeling is critical, albeit unclear. We also provide recommendations for future work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Teaching Data Science Students to Sketch Privacy Designs Through HeuristicsJinhe Wen, Yingxi Zhao, Wenqian Xu, Yaxing Yao et al.S&P 2025
- "Your imaging may be stone-cold normal, but if they look sick, they’re going to get admitted": An Investigation of Clinicians’ Perceptions of Impact & Likelihood of Security FailuresRonald E. Thompson III, Hamza Khalid, Hilary Fisher, Rhea Votipka et al.USENIX Security 2026
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- A limited technical background is sufficient for attack-defense tree acceptabilityNathan Daniel Schiele, Olga GadyatskayaUSENIX Security 2025
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
Builds on9
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Build It, Break It, Fix It: Contesting Secure DevelopmentAndrew Ruef, Michael W. Hicks, James Parker, Dave Levin et al.CCS 2016 · 80 citations
- Computer Security, Privacy, and DNA Sequencing: Compromising Computers with Synthesized DNA, Privacy Leaks, and MorePeter Ney, Karl Koscher, Lee Organick, Luis Ceze et al.USENIX Security 2017 · 70 citations
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné et al.S&P 2022 · 54 citations
Related papers
- SoK: A Framework and Guide for Human-Centered Threat Modeling in Security and Privacy ResearchWarda Usman, Daniel ZappalaS&P 2025
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Human-Centered Threat Modeling in Practice: Lessons, Challenges, and Paths ForwardWarda Usman, Yixin Zou, Daniel ZappalaS&P 2026
- Models of Applied Privacy (MAP): A Persona Based Approach to Threat ModelingJayati Dev, Bahman Rashidi, Vaibhav GargCHI 2023 · 7 citations
- Eliciting Security & Privacy-Informed Sharing Techniques for Multi-User Augmented RealityShwetha Rajaram, Chen Chen, Franziska Roesner, Michael NebelingCHI 2023 · 36 citations
