open-telemetry / sig-security

Apache License 2.0
7 stars 10 forks source link

Threat modeling for OTel components #56

Open codeboten opened 3 months ago

codeboten commented 3 months ago

As part of the fuzzing discussion, it would be helpful to have threat modeling done for the various OTel components. This issue is to track any work that could be done to progress this.

codeboten commented 3 months ago

Some examples of this in kubernetes: https://github.com/kubernetes/sig-security/blob/main/sig-security-assessments/vsphere-csi-driver/self-assessment.md

codeboten commented 3 months ago

Example diagram https://app.excalidraw.com/l/9S6CWzRu7GT/2ZxWPy93XiV

krol3 commented 3 months ago

Some documentation about threat modeling: https://github.com/controlplaneio/threat-modelling-labs