[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83609-en":3,"doc-seo-83609-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83609,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for Security-by-Design","Modern systems validate artifacts at trust boundaries using format, protocol, and signature mechanisms to ensure well-formedness, compliance, and authentication. These steps, however, do not prove the semantic security properties expected by the receiving domain, so a correctly validated artifact can still enable compromise. This work defines Trust Boundary Semantic Gaps (TBSG) as residual semantic meaning not established by successful syntactic validation. From 75 incidents (2014–2025), it proposes a four-dimensional MDTBSG model and a design-time TBSAM framework that prioritizes and maps gaps to architectural controls. Applied to SolarWinds/SUNBURST, the approach clarifies assumptions and interrupts compromised paths.","Trust Boundary Semantic Gaps: A Multi-dimensional Analysis and Mitigation for  \nSecurity-by-Design  \nDoyeon Kim, Jin-Young Choi, and Junghee Lee*  \nKorea University  \nSeoul, Republic of Korea  \n* Corresponding author  \narXiv :2607 .0 17 1 1v 1 [ cs .CR] 2 Jul 2026  \nAbstract—Modern systems use format-, protocol-, and signature-based mechanisms before accepting artifacts across trust boundaries. These mechanisms are necessary: they show that an artifact is well formed, protocol-compliant, or properly authenticated. They do not, however, show that the artifact satisfies the semantic security properties required by the receiving domain. A signed update or an authenticated token may therefore be accepted yet enable compromise. We call this condition a Trust Boundary Semantic Gap (TBSG): an artifact crosses a trust boundary and passes correctly implemented syntactic validation, but the assertions established by that pass are insufficient to satisfy the receiving domain’s security requirements. TBSG concerns what remains unestablished after a syntactic pass, not absent checks or implementation bugs. Analyzing 75 publicly reported security incidents (2014– 2025) at the boundary level, we organize semantic misalignment into a four-dimensional analysis model: Identity, Spatial, Temporal, and Interpretation (MDTBSG). Building on it, we develop Trust Boundary Semantic Analysis and Mitigation (TBSAM), a design-time framework that identifies TBSGs from design specifications, prioritizes them, traces propagated gaps to their originating boundary, and maps each to candidate architectural controls. We apply TBSAM to a retrospective reconstruction of the SolarWinds/SUNBURST supply-chain attack, showing how it makes receiving-domain assumptions explicit, separates locally originating from propagated gaps, and identifies controls that interrupt the path. These results suggest that syntactic validation, while necessary, is not sufficient at trust boundaries, and that making trust-boundary assumptions explicit can complement Security-by-Design.  \n1. Introduction  \nModern systems rarely accept artifacts without validation. When a message, token, software package, API request, or update crosses a trust boundary, the receiving domain commonly applies syntactic validation: signatures and hashes for software updates, schema and protocol checks for API requests, and tokens or credentials for sessions. These checks are necessary. They reject malformed artifacts, enforce protocol rules, and establish limited assertions such as integrity under an accepted key, format conformance, or credential validity. They do not, however, establish every  \nsecurity property that the receiving domain may rely on when it processes the artifact.  \nMajor incidents show this gap. In SolarWinds/SUNBURST, a valid SolarWinds signature did not establish that the build process produced the binary from the intended source. In Log4Shell, syntactically valid input did not establish that logged data would remain inert. In the Capital One breach, protocol-compliant requests did not establish that the request should reach the cloud metadata service or that the resulting authority should be usable. These incidents differ in mechanism, but share the same boundary-level structure: an artifact passed syntactic validation at a trust boundary, and the receiving domain processed it under a security assumption that the validation step had not established.  \nWe define this condition as a Trust Boundary Semantic Gap (TBSG): an artifact crosses a trust boundary and passes correctly implemented syntactic validation, but the assertions established by that pass do not satisfy the security properties the receiving domain requires. A TBSG is not an absent validation step, a parser bug, or a failed signature check. It captures a semantic gap between the assertions established by syntactic validation and the security meaning that the receiving domain later relies on.  \nExisting approaches explain import","cbCaibviWs8liih1","https://ap.wps.com/l/cbCaibviWs8liih1","pdf",395400,3,1,16,"English","en",105,"# Abstract\n# 1. Introduction\n## Trust boundary validation vs semantic security\n## Definition of Trust Boundary Semantic Gap (TBSG)\n## Analysis model: MDTBSG\n## Framework: Trust Boundary Semantic Analysis and Mitigation (TBSAM)","[{\"question\":\"What is a Trust Boundary Semantic Gap (TBSG)?\",\"answer\":\"A TBSG occurs when an artifact crosses a trust boundary and passes correctly implemented syntactic validation, but the assertions established by that validation do not satisfy the security properties required by the receiving domain.\"},{\"question\":\"How does the paper analyze real security incidents?\",\"answer\":\"It analyzes 75 publicly reported security incidents from 2014 to 2025 at the trust-boundary crossing level, recording the artifact, the syntactic validation applied, the assertion established, and the property left unestablished.\"},{\"question\":\"What is TBSAM and how does it help mitigation?\",\"answer\":\"TBSAM is a design-time framework with a four-stage procedure that builds boundary records from design specifications, identifies and prioritizes TBSGs, maps them to candidate architectural controls, and traces propagated gaps back to their originating boundary.\"}]",1784189242,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"trust-boundary-semantic-gaps-a-multi-dimensional-analysis-and-mitigation-for-security-by-design","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/trust-boundary-semantic-gaps-a-multi-dimensional-analysis-and-mitigation-for-security-by-design/83609/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is a Trust Boundary Semantic Gap (TBSG)?","Question",{"text":75,"@type":76},"A TBSG occurs when an artifact crosses a trust boundary and passes correctly implemented syntactic validation, but the assertions established by that validation do not satisfy the security properties required by the receiving domain.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper analyze real security incidents?",{"text":80,"@type":76},"It analyzes 75 publicly reported security incidents from 2014 to 2025 at the trust-boundary crossing level, recording the artifact, the syntactic validation applied, the assertion established, and the property left unestablished.",{"name":82,"@type":73,"acceptedAnswer":83},"What is TBSAM and how does it help mitigation?",{"text":84,"@type":76},"TBSAM is a design-time framework with a four-stage procedure that builds boundary records from design specifications, identifies and prioritizes TBSGs, maps them to candidate architectural controls, and traces propagated gaps back to their originating boundary.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]