threat-modeling.sgit.ai / papers / Graphs of Graphs of Graphs (G³) in Threat Modeling
Graphs of Graphs of Graphs (G³) in Threat Modeling
The reference architecture behind the mechanism: multi-view, multi-graph modelling, organic file-based evolution of the threat graph over time, and ontologies/taxonomies/standards linked in as semantic layers rather than baked into one schema.
What it argues
- Multi-view architecture: the same underlying graph read as a STRIDE view, an ATT&CK view, a business-impact view — without duplicating the data per view.
- File-based organic evolution: the graph grows the way a codebase does, in diffable files, rather than as a single opaque database blob.
- Ontology linking: STRIDE, MITRE ATT&CK, CAPEC, OWASP ASVS attach as layers over the graph, referenced and linked rather than reproduced.
- A worked supply-chain case study, and a closing section on personalisation, traceability and automation as the benefits that follow from the architecture.
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.