open-telemetry / sig-security

Apache License 2.0
7 stars 9 forks source link

Threat modeling for OTel components #56

Open codeboten opened 1 month ago

codeboten commented 1 month ago

As part of the fuzzing discussion, it would be helpful to have threat modeling done for the various OTel components. This issue is to track any work that could be done to progress this.

codeboten commented 1 month ago

Some examples of this in kubernetes: https://github.com/kubernetes/sig-security/blob/main/sig-security-assessments/vsphere-csi-driver/self-assessment.md

codeboten commented 1 month ago

Example diagram https://app.excalidraw.com/l/9S6CWzRu7GT/2ZxWPy93XiV

krol3 commented 1 month ago

Some documentation about threat modeling: https://github.com/controlplaneio/threat-modelling-labs