threat-modeling.sgit.ai / papers / Advancing Threat Modeling with Semantic Knowledge Graphs

Advancing Threat Modeling with Semantic Knowledge Graphs

Threats, assets, mitigations and incidents as nodes in a semantic knowledge graph, with MGraph-DB as the memory-first store — so overlaying STRIDE, MITRE ATT&CK and the OWASP Top 10 on one system becomes a query, not a workshop.

Published
2025-05-29, docs.diniscruz.ai
Role
the foundation
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/05/29/advancing-threat-modeling-with-semantic-knowledge-graphs.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.