threat-modeling.sgit.ai / papers / Using Threat Modeling and Semantic Graphs to Secure the Digital Supply Chain

Using Threat Modeling and Semantic Graphs to Secure the Digital Supply Chain

Supply chain security taken as the hardest case for the graph approach: mandatory disclosure, semantic graphs as the foundation, then whole-supply-chain modelling with G³ for interoperability between organisations.

Published
2025-05-30, docs.diniscruz.ai
Role
the domain case
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/05/30/using-threat-modeling-and-semantic-graphs-to-secure-the-digital-supply-chain.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.