Applying a Reusable Election Threat Model at the County Level
Eric Lazarus, David L. Dill, Jeremy Epstein, Joseph Lorenzo Hall · 2012
We describe the first systematic, quantitative threat evaluation in a local election jurisdiction in the U.S., Marin County, California, in the November 2010 general election. We made use of a reusable threat model that we have developed over several years. The threat model is based on attack trees with several novel enhancements to promote model reuse and flexible metrics, implemented in a software tool, AttackDog. We assess the practicality of reusable threat models for local elections offices and analyze specific vulnerabilities in Marin County, using as our metric “attack team size ” (ATS) – the number of individuals who are knowingly involved in election fraud. 1