threat-modeling.sgit.ai / papers / Using Threat Modeling and Semantic Graphs to Secure the Digital Supply Chain
Using Threat Modeling and Semantic Graphs to Secure the Digital Supply Chain
Supply chain security taken as the hardest case for the graph approach: mandatory disclosure, semantic graphs as the foundation, then whole-supply-chain modelling with G³ for interoperability between organisations.
What it argues
- Why supply chain is the hard case: no single party can see the whole chain, and a document-based threat model cannot be handed between organisations without losing structure.
- Framework integration via graph links rather than a rewritten methodology per vendor.
- Continuous, automated risk monitoring as the target state, rather than a point-in-time assessment.
- The first of two supply-chain papers; its partner (below) adds the Wardley-map visualisation layer.
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.