# Zero-Day Threat Model **Entity class:** Adversarial-systems analogy ## Definition A **zero-day threat model** treats an attack path as functionally zero-day-like when the defensive architecture has not converted the possibility into controls, training, sensing, or response, even if fragments of the idea have appeared before. It extends zero-day reasoning from software vulnerabilities to institutional assumptions while preserving the difference between analogy and literal software exploitation. ## Relevance to this collection September 11 is a strong case: suicide hijacking had been contemplated, but the threat had not been operationalized throughout aviation security and response. The attack sat between pure novelty and an unpatched known weakness. ## Relationships - **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. - **convergence:** [[wiki/Counterterrorism-Cybersecurity Convergence|Counterterrorism–Cybersecurity Convergence]]. ## Sources / Provenance - [National Commission on Terrorist Attacks Upon the United States, *The 9/11 Commission Report*, July 22, 2004](https://www.9-11commission.gov/report/911Report_Ch11.htm). **As of:** 2026-09-23