Davindernain@portfolio:~$ homeprojectsoutside workcontact

$ cat threat-model.md

Threat model: a multi-branch public library network

self-studypublic sectorSTRIDENIST SP 800-53MITRE ATT&CK
Please read first. This is an illustrative reference model built from common patterns in public library networks. It is a learning exercise. It does not describe the environment of any real organization, including any employer of mine, and the ratings are judgment-based, not measured data. For background on the library whose public structure inspired the extra factors in section 3, see The Boston Public Library, explained.

Public libraries are an interesting security problem. They hold sensitive patron data, serve thousands of anonymous visitors on shared networks, run on small teams and tight budgets, and depend on outside vendors. This write-up walks through how I would approach a threat model for a system like that: what to protect, where the trust boundaries are, what is most likely to go wrong, and what I would do first.

1. Scope and assumptions

2. Architecture and trust boundaries

Data flow diagram of a multi-branch library network The internet connects to a public services zone. Branches have a public zone, a kiosk and device zone, and a staff zone. Staff reach core services with MFA and kiosks reach only the library system. The public zone can only reach the internet. Partner libraries and vendors connect through a separate controlled link. INTERNET Remote patronsand attackers PUBLIC SERVICES (DMZ) Website and catalogbehind a WAF Vendor integrationsdigital lending, payments BRANCH NETWORKS Public zonepatron Wi-Fi and public PCs(untrusted by design) Kiosk and device zoneself-checkout, print and pay,RFID, A/V equipment Staff zonestaff workstations,staff Wi-Fi (802.1X) CORE SERVICES Identity and MFAdirectory, SSO ILS and patrondatabase File and app servers Backupsoffline or immutable copy EXTERNAL PARTNERS Consortium librariesshared network and staff ILS and cloud vendorsremote support access public zone reaches the internet only DENY 1 2 3 4

Green arrows are allowed flows. The red dashed arrow is blocked on purpose. Numbered circles mark the four trust boundaries listed below.

  1. Boundary 1, Internet to public services: only the web and vendor ports are exposed, and a web application firewall sits in front of the site.
  2. Boundary 2, public zone to everything internal: default deny. Patron devices can reach the internet and nothing else.
  3. Boundary 3, branches to core services: staff reach the core with MFA, kiosks reach only the specific ILS functions they need, and the link is an encrypted WAN or VPN with monitoring.
  4. Boundary 4, partners and vendors: a narrow, logged connection with named accounts, MFA and no standing broad access.

3. The wider footprint: extra factors

The first diagram shows the network. A large urban library system is more than a network, though. Large systems like the Boston Public Library, whose structure is described on its own public website, also run special collections, a statewide digital archive, partner nonprofits, shared consortium services and youth programs. Each adds factors a basic model would miss. I added five threats (T11 to T15) for them. This still describes the shape of an organization like this, not any real organization's technology, controls or weaknesses.

Footprint of a large urban library system and the threats that apply to each part A central box for the city library system is connected to nine parts: the central library and branches, special collections, a statewide digital archive, a map center run by a nonprofit partner, a business library and makerspace, teen and children's spaces, statewide services, a shared library network, and fundraising affiliates. Each part is tagged with the threat numbers from the register that apply to it. City library systemdepartment of city government Central Library, 25 branchespublic Wi-Fi, PCs, programsT1 T2 T3 T6 T8Special Collectionsrare books, manuscripts, printsT11 T15Statewide digital archivehub for 200+ institutionsT11 T12Map center (nonprofit)200,000 maps, GIS dataT4 T11Business library, makerspaceco-working, media toolsT3 T7Teen and children's spacesminors' data, maker labsT13 T3Statewide servicese-card, databases, loansT4 T12Shared library networkpublic, school, college librariesT12 T4Fundraising affiliatesfund, friends, associatesT14 T15

Dashed boxes are separate organizations or networks that connect to the library with their own security maturity. The tags under each box point to threats in the register.

Part of the footprintExtra factorThreats
Special collections and digitizationIrreplaceable originals and their digital copies. If digital records are altered or deleted, trust in the collection suffers.T11
Statewide digital archiveOne platform holds other organizations' materials from many contributors, so integrity and availability matter well beyond the library itself.T11, T12
Shared network of public, school and college librariesMembers differ in staff, budgets and security maturity. One weak member can expose the shared catalog or shared accounts.T12, T4
Statewide services (e-card, databases, interlibrary loan)Accounts for residents across a whole state, plus licensed vendor platforms and proxy logins.T4, T12
Map center and other partner nonprofitsA separate organization with its own systems, data sets and web properties that carry the library's name.T4, T11
Business library and makerspacesCo-working, media tools and mentoring involve visitors' own devices and sensitive business information.T3, T7
Teen and children's spacesMinors' registrations, volunteer records and program data need stricter handling.T13
Fundraising affiliates (fund, friends, associates)Donor, event and payment data sit with separate nonprofits, and scammers can pose as them.T14, T15
High visibility and public programsA well-known civic institution draws attention, from phishing that uses its name to website defacement.T15, T1

4. What needs protecting

Highest value

  • Patron records and borrowing history (privacy-sensitive)
  • Staff identities and admin accounts

Must stay available

  • ILS and checkout at every branch
  • Public website and catalog
  • Internet access for patrons

Hard to rebuild

  • Configuration and directory data
  • Backups themselves
  • Public trust in the library

5. Threat register

I used STRIDE to look for threats at each trust boundary, then mapped each to a MITRE ATT&CK technique and to NIST SP 800-53 control families. Priority 1 means address first. Control IDs are pointers for follow-up, not a compliance claim.

IDThreatSTRIDEATT&CKPriorityMain controls (800-53)
T1Phishing steals a staff or admin passwordSpoofingT1566, T10781Phishing-resistant MFA such as passkeys (IA-2), email filtering (SI-8), awareness and simulations (AT-2)
T2Ransomware spreads from one staff PC to file servers and the ILSTampering, Denial of serviceT1486, T10211Segmentation (SC-7, AC-4), endpoint protection (SI-3), least privilege (AC-6), tested offline backups (CP-9, CP-10)
T3A compromised public device moves sideways into internal networksElevation of privilegeT1046, T10211Default-deny public zone and client isolation (SC-7, AC-4), locked-down kiosk images (CM-7), reimage after each session
T4A vendor or consortium connection is abused to reach core systemsSpoofing, TamperingT11992Vendor risk review before purchase (SA-9), narrow information exchange agreements (CA-3), named accounts with MFA and logging
T5An internet-facing website or vendor portal is exploitedTampering, Elevation of privilegeT11902WAF and DMZ isolation (SC-7), patch deadlines by severity (SI-2), regular scans and a yearly penetration test (RA-5)
T6Staff or patron traffic is intercepted on shared Wi-FiInformation disclosureT15572Separate staff network with 802.1X (AC-18), encrypted sessions (SC-8), no staff traffic on public Wi-Fi
T7An insider looks up patron records without a reasonInformation disclosure, RepudiationT10782Role-based access (AC-2, AC-6), logging and review of record access (AU-2, AU-6), privacy training (AT-2), data retention limits
T8A rogue device is plugged into a branch network portSpoofing, TamperingT12003Network access control and 802.1X (IA-3), disabled unused ports, asset inventory (CM-8)
T9A denial-of-service attack or link failure takes services offlineDenial of serviceT14983DDoS protection for the public site (SC-5), redundant links for large branches (CP-8), an offline checkout mode (CP-2)
T10Weak logging means an attack goes unnoticed for weeksRepudiationnone (a gap)1Central logging and alerts on admin logins and mass downloads (AU-6, SI-4), tested response plan (IR-4, IR-8)
T11Digitized collections or repository records are altered, corrupted or deletedTampering, RepudiationT1565, T14852Integrity checks on stored files (SI-7), an offline or immutable preservation copy (CP-9), restricted and logged edit rights (AC-6, AU-2)
T12A weak member of a shared library network exposes the shared catalog or accountsSpoofing, Elevation of privilegeT1199, T10781Minimum security baseline for every member (SA-9), separation between members (AC-4), named admin accounts with MFA (IA-2), logging per member (AU-6)
T13Minors' and teens' registration, volunteer or program data is exposedInformation disclosureT12132Collect only what is needed, retention limits (SI-12), role-based access (AC-6), staff privacy training (AT-2)
T14Donor, event or payment data held by an affiliated nonprofit is stolen, or scammers impersonate itInformation disclosure, SpoofingT1566, T16572Review how affiliates handle data (SA-9), written data-sharing terms (CA-3), payments through a certified processor, email authentication against spoofing (SI-8)
T15A high-profile institution is targeted for defacement, hacktivism or brand impersonationDenial of service, SpoofingT14913WAF and DDoS protection (SC-5, SC-7), lookalike-domain monitoring, a tested communications and response plan (IR-4, IR-8)

Priority is my judgment for a typical environment, based on likelihood and impact. In a real review I would replace it with local incident history and asset values.

6. What I would do first

First 30 days

  • Roll out phishing-resistant MFA to admins, then all staff (T1)
  • Prove a backup restore works end to end (T2)
  • Test from a public device that nothing internal is reachable (T3)
  • Alert on admin logins and new accounts (T10)
  • Set a minimum security baseline for shared-network members (T12)

Days 30 to 90

  • Separate kiosks and devices from staff networks (T2, T3)
  • Review all vendor and consortium access (T4)
  • Set patch deadlines and a scan schedule (T5)
  • 802.1X on wired staff ports (T8)
  • Add integrity checks and an offline copy for digital collections (T11)
  • Review how affiliates handle donor and payment data (T14)

Later

  • Run a ransomware tabletop exercise (T2)
  • Review DDoS protection and link redundancy (T9)
  • Write data retention rules for patron records (T7)
  • Repeat this model yearly
  • Set handling rules for minors' data (T13)
  • Prepare a response plan for defacement and brand impersonation (T15)

7. Residual risk and what I would test

This model rests on assumptions that I would check before trusting it:

Even with all of these controls, some risk remains: a determined attacker, a zero-day flaw, or a mistake by a tired person. The goal is to make attacks hard, limit the damage when one succeeds, and notice quickly.

8. Method

back to projects