Abuse cases beside intended use cases
Derive negative scenarios from each trust boundary before selecting controls.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
A URL importer accepts a user address and downloads server-side. Assets include internal services, credentials and resources. Users control URLs and remote responses control redirects; one public HTTPS success does not cover these boundaries.
Mechanism
Map caller→import service→resolution/redirect/download→storage, naming writers and protected assets. Pair normal use with unauthorized callers, redirects to prohibited destinations and oversized/nonterminating responses. Choose authorization, destination validation and size/time budgets for those paths, testing rejection before effects in controlled fixtures. Record unresolved addressing/network conditions.
Bad example
Test one successful public HTTPS import and declare it secure without checking rights, redirects or resource limits.
Good example
Test a valid fixture, an unauthorized caller, a redirect to a prohibited destination and a response exceeding a teaching size limit. For each name writer, boundary, control and rejection point. Use controlled services rather than probing arbitrary real internal networks.
Why the change matters
Boundary-derived abuse cases tie controls to actual paths. Rejection points and effect assertions test whether protection precedes unwanted access or consumption rather than merely existing in configuration.
Observable expectation
Teaching unauthorized requests reject before downloads; prohibited redirect targets receive no access; oversized input stops without publishing artifacts; valid input still imports. Record requests and storage effects rather than assuming a final error means no prior access.
Limits
Cases are not a complete security proof. DNS changes, parsing, proxies, redirects and network isolation need actual architectural controls. Test only authorized targets; this defensive design example authorizes no probing of third parties or unknown systems.