'Threat modeling is very formal, it’s very technical, and also very hard to do correctly': Investigating Threat Modeling Practices in Open-Source Software Projects

Publication
USENIX Security Symposium
Security Professionals Secure Development Vulnerability Discovery