Skip to main content

Threat, Vulnerability, and Attack

Distinguish a possible harmful event, a weakness, an attempted exploit, exposure, consequence, and impact.

Keep the terms separate

A threat is a circumstance or event that can cause harm. A threat source is the actor or condition that can cause it. A vulnerability is a weakness or condition that the threat can exploit. An attack is an intentional attempt to exploit a weakness or violate a property. Exposure describes contact with a condition that can lead to loss. Consequence describes what happens; impact describes its effect on stakeholders.

Write a complete threat statement

Name the source, precondition, action or event, affected asset, violated property, and consequence. For example: "A user with a valid session reaches the administration service through a direct upstream address, bypasses route policy, changes configuration, and causes unauthorized loss of integrity."

Find control points

Trace the path from source to consequence. A preventive control can remove a precondition or block the action. A detective control can create evidence. A response control can limit the consequence. Do not call a product name the mitigation. Name the enforced behavior and where it acts.

Failure and residual risk

A vulnerability scan does not enumerate all threats. A threat can exploit valid functionality, stolen authority, design assumptions, or dependency failure without a software defect. Controls can introduce new dependencies and failure modes.

Pomerium boundary

Pomerium can mediate configured routes and record route decisions. A direct upstream path, application permission error, compromised endpoint, or false identity attribute can remain outside that control. State which threat step Pomerium changes and which steps need other controls.

Evaluation checklist

  • Does the threat statement name a source, path, asset, property, and consequence?
  • Is the vulnerability distinct from the attack that uses it?
  • Can the threat occur through valid functionality or stolen authority?
  • Is each mitigation described as an enforced behavior at a control point?
  • What consequence remains if the preventive control fails?

Sources and further reading

Keep learning

Security Engineering FoundationsSecurity Operations and Risk

Adversary Model

State who can attack the system, what they want, what they can do, where they start, and what constrains them.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Security Risk

Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.

Learn this term
Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo