threat-modeling.sgit.ai / papers / Graphs of Graphs of Graphs (G³) in Threat Modeling

Graphs of Graphs of Graphs (G³) in Threat Modeling

The reference architecture behind the mechanism: multi-view, multi-graph modelling, organic file-based evolution of the threat graph over time, and ontologies/taxonomies/standards linked in as semantic layers rather than baked into one schema.

Published
2025-05-30, docs.diniscruz.ai
Role
the architecture
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/05/30/graphs-of-graphs-of-graphs-g3-in-threat-modeling.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.