The purpose of this Letter is to formalize an approach to threat model design that provides the model builder with criteria for selecting, from the universal set of all possible threat models, a limited subset of models that are realistic, usable, and useful. It is believed that this approach will contribute to the elimination to a large degree of the arbitrariness that often accompanies the
... [Show full abstract] design of the more complex threat models. It is realized, however, that consciously or subconsciously many a threat model designer is likely to have used in his work some or all of the principles discussed in this letter.