Application of security threat modeling and analysis methods, devices, equipment and media

By identifying modeling selection information, collecting and processing data, and creating application security threat models, the management challenges faced by enterprises in the face of complex security threats are solved, and rapid and accurate security requirements analysis is achieved.

CN120582896BActive Publication Date: 2026-01-06BILING (ZHUHAI HENGQIN) TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510910512.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2026-01-06
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

When faced with complex security threats, enterprises lack effective security management and threat modeling capabilities, which makes it impossible to quickly and accurately meet actual business needs.

Method used

By responding to user modeling and analysis commands, determining modeling selection information, collecting and processing data, generating key modeling data, creating application security threat models, and conducting security analysis.

Benefits of technology

It enables rapid and accurate security requirements analysis based on actual business needs, improving the efficiency and accuracy of security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582896B_ABST
    Figure CN120582896B_ABST
Patent Text Reader

Abstract

The application relates to an application security threat modeling analysis method and device, equipment and medium, and belongs to the technical field of security modeling analysis. The method comprises the following steps: in response to a modeling analysis instruction of a target user, determining modeling selection information of the target user based on the modeling analysis instruction; determining a modeling analysis mode of the target user based on the modeling selection information; collecting modeling use data based on the modeling analysis mode, and generating modeling requirement information; performing key content analysis processing on the modeling requirement information to obtain modeling key data; obtaining a model page requirement of the target user; and creating an application security threat model based on the model page requirement and the modeling key data. The application has the effect of quickly and accurately analyzing security requirements according to actual business.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security modeling and analysis, and in particular to a method, apparatus, device and medium for applying security threat modeling and analysis. Background Technology

[0002] With the rapid development of the internet and the increasing openness of enterprise information systems, businesses are facing increasingly severe security threats. Attackers utilize widespread attack tools to continuously discover and exploit security vulnerabilities and business logic flaws in enterprise information systems. Consequently, enterprises face higher compliance and regulatory requirements. However, most security managers within enterprises lack a sufficient understanding of privacy compliance and data compliance requirements, making it impossible for them to provide accurate security guidance. Furthermore, due to a shortage of security personnel, insufficient capabilities of security developers, and the overly complex nature of threat modeling and analysis, most enterprises are unable to quickly and effectively articulate security requirements that align with their actual business needs. Summary of the Invention

[0003] To enable rapid and accurate security requirements analysis based on actual business needs, this application provides a method, apparatus, device, and medium for applying security threat modeling and analysis.

[0004] Firstly, this application provides a method for applying security threat modeling and analysis, employing the following technical solution:

[0005] An application security threat modeling and analysis method includes:

[0006] In response to the modeling and analysis instructions of the target user, the modeling selection information of the target user is determined based on the modeling and analysis instructions;

[0007] The modeling and analysis method for the target user is determined based on the modeling selection information.

[0008] Based on the aforementioned modeling and analysis method, data used for modeling is collected to generate modeling requirement information;

[0009] The modeling requirements information is analyzed and processed to obtain key modeling data;

[0010] Obtain the model page requirements of the target user;

[0011] An application security threat model is created based on the model page requirements and the key modeling data.

[0012] By adopting the above technical solution, after receiving the modeling and analysis instructions from the target user, the modeling selection information contained in the instructions is extracted. Based on the modeling selection information, the modeling and analysis method that the target user wants to use is determined. The modeling analysis method is then used to collect the necessary modeling data to obtain modeling requirement data. This modeling requirement data is further analyzed and processed to remove useless data, resulting in key modeling data used for model creation. Simultaneously, to facilitate operation and use by the target user, the target user's model page requirements are collected to obtain the target user's requirements for the model's appearance. Then, the application security threat model is created by combining the model page requirements and the key modeling data. This application security threat model is then used for security analysis, enabling rapid and accurate security requirement analysis based on actual business needs.

[0013] Optionally, the modeling analysis method for determining the target user based on the modeling selection information includes:

[0014] The modeling selection information is labeled to determine the modeling analysis labels;

[0015] Obtain the tag processing scheme corresponding to the modeling and analysis tags and the user identity of the target user;

[0016] Based on the user's identity, determine whether the modeling and analysis tags are applicable to the target user;

[0017] If the modeling analysis label is applicable to the target user, then the modeling analysis label and the modeling selection information are classified based on the label processing scheme to obtain the label category;

[0018] The modeling and analysis method for the target user is determined based on the modeling and analysis tags and the tag types.

[0019] If the modeling analysis tags are not applicable to the target user, then a recommendation analysis tag is generated based on the preset recommendation scheme and the user's identity, and the recommendation analysis tag is sent to the target user's client.

[0020] In response to the confirmation information from the target user, the modeling and analysis method for the target user is determined based on the confirmation information and the modeling and analysis label.

[0021] Optionally, the step of collecting data for modeling based on the modeling analysis method and generating modeling requirement information includes:

[0022] The data collection page is determined based on the aforementioned modeling and analysis method;

[0023] The data collection page is sent to the target user's client.

[0024] Real-time acquisition of modeling usage data sent by the target user;

[0025] Based on the data acquisition page, the data used for modeling is aggregated to generate modeling requirement information.

[0026] Optionally, the key content analysis and processing of the modeling requirement information to obtain key modeling data includes:

[0027] Obtain the content analysis engine and the data processing structure of the content analysis engine for the modeling and analysis method described above;

[0028] The modeling requirement information is cleaned of interference to generate modeling requirement data;

[0029] The modeling requirement data is compared with the data processing structure to generate a structure comparison result.

[0030] Based on the structural comparison results and the data processing structure, the modeling requirement data is adjusted to generate data to be analyzed;

[0031] Based on the content analysis engine, key content analysis is performed on the data to be analyzed to obtain key data for modeling.

[0032] Optionally, creating the application security threat model based on the model page requirements and the key modeling data includes:

[0033] Based on the requirements of the model page, determine the scenario and create tags;

[0034] Based on the scenario, tags are created, and a display scenario is selected from a preset scenario library to generate a model display result.

[0035] Obtain the model security database;

[0036] Based on the key modeling data, tools are selected from the model security database to generate the model usage tools.

[0037] Based on the results shown in the model, a security threat model is created using the tools described in the model.

[0038] Optionally, after creating the application security threat model based on the model page requirements and the key modeling data, the method further includes:

[0039] Generate model introduction tags based on the model page requirements and the key modeling data;

[0040] Generate applicable labels for the model based on the key modeling data;

[0041] Model recommendation information is generated based on the model introduction tags and the model applicable tags;

[0042] The model recommendation information is bound to the application security threat model to generate a model binding result;

[0043] The model binding results are stored in a preset storage database.

[0044] Optionally, after storing the model binding result to a preset storage database, the method further includes:

[0045] Obtain user demand information;

[0046] The user demand information is analyzed to obtain user demand tags;

[0047] The user demand tags are matched with the model binding results in the preset storage database to generate matching results;

[0048] Based on the matching results, existing models are selected to obtain the security threat models to be used.

[0049] Secondly, this application provides an application security threat modeling and analysis device, which adopts the following technical solution:

[0050] An application security threat modeling and analysis device, comprising:

[0051] The modeling information determination module is used to determine the modeling selection information of the target user based on the modeling analysis command in response to the modeling analysis command.

[0052] The analysis method determination module is used to determine the modeling analysis method for the target user based on the modeling selection information.

[0053] The requirement information generation module is used to collect data used in modeling based on the modeling analysis method and generate modeling requirement information.

[0054] The key data analysis module is used to perform key content analysis and processing on the modeling requirement information to obtain key modeling data.

[0055] The page requirement acquisition module is used to acquire the model page requirements of the target user;

[0056] The security model creation module is used to create an application security threat model based on the model page requirements and the key modeling data.

[0057] By adopting the above technical solution, after receiving the modeling and analysis instructions from the target user, the modeling selection information contained in the instructions is extracted. Based on the modeling selection information, the modeling and analysis method that the target user wants to use is determined. The modeling analysis method is then used to collect the necessary modeling data to obtain modeling requirement data. This modeling requirement data is further analyzed and processed to remove useless data, resulting in key modeling data used for model creation. Simultaneously, to facilitate operation and use by the target user, the target user's model page requirements are collected to obtain the target user's requirements for the model's appearance. Then, the application security threat model is created by combining the model page requirements and the key modeling data. This application security threat model is then used for security analysis, enabling rapid and accurate security requirement analysis based on actual business needs.

[0058] Thirdly, this application provides an electronic device that adopts the following technical solution:

[0059] An electronic device includes a processor coupled to a memory;

[0060] The processor is configured to execute a computer program stored in the memory, such that the electronic device executes the computer program of the application security threat modeling and analysis method as described in any of the first aspects.

[0061] Fourthly, this application provides a computer-readable storage medium, which adopts the following technical solution:

[0062] A computer-readable storage medium storing a computer program capable of being loaded by a processor and executing the application security threat modeling and analysis method described in any one of the first aspects. Attached Figure Description

[0063] Figure 1 This is a flowchart illustrating an application security threat modeling and analysis method provided in an embodiment of this application.

[0064] Figure 2 This is a structural block diagram of an application security threat modeling and analysis device provided in an embodiment of this application.

[0065] Figure 3 This is a structural block diagram of the electronic device provided in the embodiments of this application. Detailed Implementation

[0066] The present application will be further described in detail below with reference to the accompanying drawings.

[0067] This application provides an application security threat modeling and analysis method, which can be executed by an electronic device, which can be a server or a terminal device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, tablet computer, desktop computer, etc., but is not limited to these.

[0068] Figure 1 This is a flowchart illustrating an application security threat modeling and analysis method provided in an embodiment of this application.

[0069] like Figure 1 As shown, the main process of this method is described below (steps S101 to S106):

[0070] Step S101: In response to the modeling and analysis instructions of the target user, determine the modeling selection information of the target user based on the modeling and analysis instructions.

[0071] In this embodiment, after the target user triggers the modeling analysis command, the system collects the modeling analysis command and performs command analysis to trace the source of the command selection, thereby determining the target user's modeling selection information. The modeling selection information includes the selected tag, modeling selection time, modeling urgency, etc. The specific modeling selection information needs to be set according to actual needs, and is not specifically limited here.

[0072] Step S102: Determine the modeling and analysis method for the target user based on the modeling selection information.

[0073] For step S102, the modeling selection information is labeled to determine the modeling analysis label; the label processing scheme corresponding to the modeling analysis label and the user identity of the target user are obtained; based on the user identity, it is determined whether the modeling analysis label is applicable to the target user; if the modeling analysis label is applicable to the target user, the label processing scheme is used to identify the type of the modeling analysis label and the modeling selection information to obtain the label type; the modeling analysis method of the target user is determined based on the modeling analysis label and the label type; if the modeling analysis label is not applicable to the target user, a recommended analysis label is generated based on the preset recommendation scheme and the user identity, and the recommended analysis label is sent to the target user's client; in response to the target user's confirmation information, the modeling analysis method of the target user is determined based on the confirmation information and the modeling analysis label.

[0074] In this embodiment, when the target user makes a selection, they will click the corresponding function button. During tag recognition, the source of the modeling selection information is traced to determine the selected function button. Based on the data function of the function button, the modeling analysis tag is determined. The modeling analysis tag includes tag filtering tag, scenario question and answer tag, original text analysis tag, and summary analysis tag. Among them, the tag filtering tag is mainly suitable for personnel with certain basic knowledge of security development. Through a shopping-like user experience, they can more quickly filter out suitable security needs. The other three options are suitable for various types of personnel. Therefore, in order to improve the accuracy of subsequent model creation, it is necessary to determine the modeling analysis method of the target user at the beginning to reduce the possibility of incorrect modeling.

[0075] The process involves collecting data on the tag processing scheme and the target user's identity. After obtaining the user's identity, it's determined whether the user possesses basic security development knowledge. If the target user does, the modeling and analysis tags are deemed applicable. If the target user does not possess basic security development knowledge, and the modeling and analysis tags are tag filtering tags, the modeling and analysis tags are deemed unsuitable. Following this determination, further analysis is performed based on the results.

[0076] When the modeling analysis label is applicable to the target user, a label processing scheme is used to identify the specific type of the modeling analysis label and the modeling selection information. That is, the modeling analysis label is selected from the label processing scheme to determine the processing scheme applicable to the modeling analysis label. Then, the processing scheme is used to analyze the modeling selection information to extract the key security analysis directions in the modeling selection information. The security analysis directions are matched and compared with the preset security database to determine the label type. The label type is the main analysis function used when modeling. The modeling analysis label and label type are integrated to obtain the final modeling analysis method.

[0077] When the modeling analysis tags are not applicable to the target user, a preset recommendation scheme is used to analyze the user's identity and generate recommended analysis tags. This involves determining the user's software proficiency based on their identity information and generating recommended analysis tags based on that proficiency. The preset recommendation scheme sets different software proficiency levels corresponding to different identity information, as well as corresponding analysis tags for each proficiency level. The resulting analysis tags are used as the recommended analysis tags. After obtaining the recommended analysis tags, they are sent to the target user's client. Upon user confirmation, the system checks whether the user confirms the use of the recommended analysis tags or continues using the modeling analysis tags. Then, [further action is taken]. The modeling and analysis method is determined in the same way that the modeling and analysis tags are applicable to the target users. That is, the tag processing scheme is used to identify the specific types of modeling and analysis tags and modeling selection information. Specifically, the modeling and analysis tags are selected from the tag processing scheme to determine the processing scheme applicable to the modeling and analysis tags. Then, the processing scheme is used to analyze and process the modeling selection information, extract the key security analysis directions in the modeling selection information, and match and compare the security analysis directions with the preset security database to determine the tag type. The tag type is the main analysis function used when modeling. The modeling and analysis tags and tag types are integrated to obtain the final modeling and analysis method.

[0078] Step S103: Collect data for modeling based on modeling analysis methods to generate modeling requirement information.

[0079] For step S103, the data collection page is determined based on the modeling analysis method; the data collection page is sent to the target user's client; the modeling usage data sent by the target user is acquired in real time; the modeling usage data is summarized based on the data collection page to generate modeling requirement information.

[0080] In this embodiment, after obtaining the modeling and analysis method, the data collection page is selected according to the modeling and analysis method. That is, the collection page format is determined according to the modeling and analysis tags, and the collection page content is determined according to the tag type. Then, the collection page content is filled into the collection page format to obtain the data collection page. The generated data collection page is then sent to the target user's client. While the target user is filling in the data, the data sent by the user is collected in real time to obtain the modeling usage data. All the modeling usage data sent by the user is arranged and summarized according to the setting order of the collection page content in the collection page format to obtain the modeling and analysis information.

[0081] Step S104: Perform key content analysis and processing on the modeling requirement information to obtain key modeling data.

[0082] For step S104, the content analysis engine and data processing structure of the modeling analysis method are obtained; interference content is cleaned from the modeling requirement information to generate modeling requirement data; the modeling requirement data is compared with the data processing structure to generate a structure comparison result; the modeling requirement data is adjusted based on the structure comparison result and the data processing structure to generate data to be analyzed; key content analysis is performed on the data to be analyzed based on the content analysis engine to obtain key modeling data.

[0083] In this embodiment, after obtaining the modeling requirement information, interference content is cleaned to remove influencing factors such as interjections, punctuation marks, and conjunctions, resulting in modeling requirement data. This data is then compared with the data processing structure to check if the data structure is consistent with the data structure that can be analyzed by the content analysis engine. The comparison result is used as the structure comparison result. If the structure comparison result shows that the modeling requirement data and the data processing structure are consistent, the modeling requirement data is used as the data to be analyzed, and the content analysis engine directly performs key content analysis on the data to be analyzed to obtain key modeling data. If the structure comparison result shows that the modeling requirement data and the data processing structure are inconsistent, the inconsistent content is extracted, and the inconsistent content is restructured according to the data processing structure. After adjustment, the consistent parts are combined and used as the data to be analyzed. The content analysis engine then performs key content analysis on the data to be analyzed to obtain key modeling data.

[0084] Step S105: Obtain the model page requirements of the target user.

[0085] In this embodiment, different target users have different usage habits and different display needs, thus enabling the model creation function. Users can propose corresponding page requirements based on their actual usage needs. All page requirements are summarized to obtain model page requirements. When creating a model, the model page requirements are used to create an application security threat model with the required content.

[0086] Step S106: Create an application security threat model based on model page requirements and key modeling data.

[0087] For step S106, determine the scene creation tags based on the model page requirements; select display scenes from the preset scene library based on the scene creation tags to generate model display results; obtain the model security database; select tools from the model security database based on the key modeling data to generate model usage tools; and create a security threat model based on the model display results and model usage tools.

[0088] In this embodiment, key content is extracted from the model page requirements. The extracted key content is then standardized and adjusted according to the data storage format in the preset scenario library to obtain scenario creation tags. These tags are then used to search and match within the preset scenario library to select a display scenario. The selection results are then integrated to obtain the model display result. Subsequently, the key modeling data is used to search and match within the model security database to select the tools used in the model. After the selection is complete, the model display result combines the tools used in the model to create an application security threat model. This ensures that the created application security threat model is consistent with the target user's needs in terms of both page functionality and actual security protection. Based on application security threat analysis and protection, it facilitates use and operation by the target user.

[0089] In this embodiment, model introduction tags are generated based on model page requirements and key modeling data; model application tags are generated based on key modeling data; model recommendation information is generated based on model introduction tags and model application tags; the model recommendation information is bound to the application security threat model to generate model binding results; and the model binding results are stored in a preset storage database.

[0090] For each application security threat model created, model description tags and model applicability tags are created to facilitate storage and direct reuse of the application security threat model. First, the model page requirements and key modeling data are filtered to obtain keywords that concisely describe the application security threat model. These keywords are used as model description tags. Next, requirement keywords are extracted from the key model data and used as model applicability tags. The obtained model description tags and model applicability tags are summarized to obtain model recommendation information. The obtained model recommendation information is bound to the application security threat model. When searching, the corresponding application security threat model can be quickly found through the model recommendation information, and the corresponding model recommendation information can be quickly viewed through the application security threat model. After binding, the model binding result is obtained and directly stored in a preset storage database for easy access and reuse by target users or personnel with relevant permissions.

[0091] In this embodiment, user demand information is obtained; the user demand information is analyzed to obtain user demand tags; the user demand tags are matched with the model binding results in the preset storage database to generate matching results; and existing models are selected based on the matching results to obtain a security threat model to be used.

[0092] To facilitate the rapid acquisition of the required security threat models, after storing the model binding results in a preset storage database, and upon receiving a new target user's creation instruction, the information contained in the creation instruction is extracted to obtain user requirement information. This user requirement information is then analyzed and extracted, selecting the main information related to application security. The obtained information is tagged to generate user requirement tags. These user requirement tags are then directly matched with the model binding results in the preset storage database. The matching percentage is calculated based on the number of user requirement tags and the number of tags successfully matched with tags in a single model binding result. The matching percentage and the number of successfully matched tags are used as the matching result. Data with a matching percentage greater than or equal to a percentage threshold and a number of tags in the model binding result greater than the number of user requirement tags are selected. This data is used to select existing models to obtain the usable security threat model. It should be noted that when the number of tags in the model binding result is greater than the number of user requirement tags and the matching percentage in the matching result is greater than or equal to the percentage threshold, the functionality of the existing model can cover the user's needs, thereby achieving a better security protection effect.

[0093] Figure 2 This is a structural block diagram of an application security threat modeling and analysis device 200 provided in the embodiments of the application.

[0094] like Figure 2 As shown, the application security threat modeling and analysis device 200 mainly includes:

[0095] The modeling information determination module 201 is used to determine the modeling selection information of the target user based on the modeling analysis command in response to the target user's modeling analysis command;

[0096] The analysis method determination module 202 is used to determine the modeling analysis method for the target user based on the modeling selection information.

[0097] The requirement information generation module 203 is used to collect data used in modeling based on modeling analysis methods and generate modeling requirement information.

[0098] The key data analysis module 204 is used to perform key content analysis and processing on the modeling requirement information to obtain key modeling data.

[0099] Page requirement acquisition module 205 is used to acquire the model page requirements of the target user;

[0100] Security model creation module 206 is used to create application security threat models based on model page requirements and key modeling data.

[0101] As an optional implementation of this embodiment, the analysis method determination module 202 is specifically used to perform label recognition on the modeling selection information to determine the modeling analysis label; obtain the label processing scheme corresponding to the modeling analysis label and the user identity of the target user; determine whether the modeling analysis label is applicable to the target user based on the user identity; if the modeling analysis label is applicable to the target user, then perform category recognition on the modeling analysis label and modeling selection information based on the label processing scheme to obtain the label category; determine the modeling analysis method of the target user based on the modeling analysis label and the label category; if the modeling analysis label is not applicable to the target user, then generate a recommended analysis label based on the preset recommendation scheme and the user identity, and send the recommended analysis label to the target user's client; respond to the target user's confirmation information, determine the target user's modeling analysis method based on the confirmation information and the modeling analysis label.

[0102] As an optional implementation of this embodiment, the requirement information generation module 203 is specifically used to determine the data collection page based on the modeling analysis method; send the data collection page to the target user's client; acquire the modeling usage data sent by the target user in real time; and summarize the modeling usage data based on the data collection page to generate modeling requirement information.

[0103] As an optional implementation of this embodiment, the key data analysis module 204 is specifically used to acquire the content analysis engine and the data processing structure of the modeling analysis method; to clean up the interference content of the modeling requirement information and generate modeling requirement data; to perform a structural comparison between the modeling requirement data and the data processing structure and generate a structural comparison result; to adjust the modeling requirement data based on the structural comparison result and the data processing structure and generate data to be analyzed; and to perform key content analysis on the data to be analyzed based on the content analysis engine to obtain key modeling data.

[0104] As an optional implementation of this embodiment, the security model creation module 206 is specifically used to determine scene creation tags based on model page requirements; select display scenes from a preset scene library based on scene creation tags to generate model display results; obtain a model security database; select tools from the model security database based on key modeling data to generate model usage tools; and create a security threat model based on the model display results and model usage tools.

[0105] As an optional implementation of this embodiment, the application security threat modeling and analysis device 200 further includes:

[0106] The tag generation module is used to generate model introduction tags based on model page requirements and key modeling data.

[0107] The applicable label generation module is used to generate applicable labels for the model based on key modeling data.

[0108] The recommendation information generation module is used to generate model recommendation information based on model introduction tags and model applicable tags;

[0109] The binding result generation module is used to bind model recommendation information with application security threat models and generate model binding results;

[0110] The binding result storage module is used to store the model binding results to a preset storage database.

[0111] As an optional implementation of this embodiment, the application security threat modeling and analysis device 200 further includes:

[0112] The requirement information acquisition module is used to acquire user requirement information;

[0113] The user needs analysis module is used to analyze user needs information and obtain user needs tags;

[0114] The matching result generation module is used to match user demand tags with model binding results in a preset stored database to generate matching results;

[0115] The candidate model selection module is used to select existing models based on the matching results to obtain candidate security threat models.

[0116] In one example, the module in any of the above devices may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.

[0117] For example, when modules in a device can be implemented via a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling programs. Alternatively, these modules can be integrated together as a system-on-a-chip (SOC).

[0118] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device and module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0119] Figure 3 This is a structural block diagram of the electronic device 300 provided in an embodiment of this application.

[0120] like Figure 3 As shown, the electronic device 300 includes a processor 301 and a memory 302, and may further include one or more of an information input / output (I / O) interface 303, a communication component 304, and a communication bus 305.

[0121] The processor 301 controls the overall operation of the electronic device 300 to complete all or part of the steps of the application security threat modeling and analysis method described above. The memory 302 stores various types of data to support the operation of the electronic device 300. This data may include, for example, instructions for any application or method operating on the electronic device 300, as well as application-related data. The memory 302 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as one or more of Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0122] I / O interface 303 provides an interface between processor 301 and other interface modules, such as keyboards, mice, and buttons. These buttons can be virtual or physical. Communication component 304 is used for wired or wireless communication between electronic device 300 and other devices. Wireless communication includes Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, or 4G, or a combination thereof. Therefore, the corresponding communication component 104 may include a Wi-Fi component, a Bluetooth component, and an NFC component.

[0123] The electronic device 300 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to execute the application security threat modeling and analysis method given in the above embodiments.

[0124] The communication bus 305 may include a path for transmitting information between the aforementioned components. The communication bus 305 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The communication bus 305 may be divided into an address bus, a data bus, a control bus, etc.

[0125] Electronic device 300 may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers, and may also be servers.

[0126] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described application security threat modeling and analysis method.

[0127] The computer-readable storage medium may include various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0128] The terms “comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0129] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing application concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions claimed in this application.

Claims

1. A method for application security threat modeling analysis, the method comprising: The method comprises the following steps: in response to a modeling analysis instruction of a target user, determining modeling selection information of the target user based on the modeling analysis instruction; determining a modeling analysis mode of the target user based on the modeling selection information; collecting modeling use data based on the modeling analysis mode, and generating modeling requirement information; performing key content analysis processing on the modeling requirement information to obtain modeling key data; obtaining a model page requirement of the target user; creating an application security threat model based on the model page requirement and the modeling key data; the step of determining the modeling analysis mode of the target user based on the modeling selection information comprises: performing label identification on the modeling selection information to determine a modeling analysis label; obtaining a label processing scheme corresponding to the modeling analysis label and a user identity of the target user; determining whether the modeling analysis label is applicable to the target user based on the user identity; if the modeling analysis label is applicable to the target user, performing category identification on the modeling analysis label and the modeling selection information based on the label processing scheme to obtain a label category; determining the modeling analysis mode of the target user based on the modeling analysis label and the label category; if the modeling analysis label is not applicable to the target user, generating a recommended analysis label based on a preset recommendation scheme and the user identity, and sending the recommended analysis label to a client of the target user; in response to confirmation information of the target user, determining the modeling analysis mode of the target user based on the confirmation information and the modeling analysis label.

2. The method of claim 1, wherein, the step of collecting modeling use data based on the modeling analysis mode to generate modeling requirement information comprises: determining a data collection page based on the modeling analysis mode; sending the data collection page to a client of the target user; real-time obtaining modeling use data sent by the target user; performing data summarization on the modeling use data based on the data collection page to generate modeling requirement information.

3. The method of claim 1, wherein, the step of performing key content analysis processing on the modeling requirement information to obtain modeling key data comprises: obtaining a content analysis engine of the modeling analysis mode and a data processing structure of the content analysis engine; performing interference content cleaning on the modeling requirement information to generate modeling requirement data; performing structure comparison between the modeling requirement data and the data processing structure to generate a structure comparison result; adjusting the modeling requirement data based on the structure comparison result and the data processing structure to generate to-be-analyzed data; performing key content analysis on the to-be-analyzed data based on the content analysis engine to obtain modeling key data.

4. The method of claim 1, wherein, the step of creating an application security threat model based on the model page requirement and the modeling key data comprises: determining a scenario creation label based on the model page requirement; performing display scenario selection in a preset scenario library based on the scenario creation label to generate a model display result; obtaining a model security database; performing tool selection in the model security database based on the modeling key data to generate a model use tool; Based on the model display result and the model usage tool, a security threat model is created.

5. The method of claim 1, wherein, After the application security threat model is created based on the model page requirement and the modeling key data, the method further includes: Based on the model page requirement and the modeling key data, a model introduction label is generated; Based on the modeling key data, a model applicable label is generated; Based on the model introduction label and the model applicable label, model recommendation information is generated; The model recommendation information is bound with the application security threat model to generate a model binding result; The model binding result is stored in a preset storage database.

6. The method of claim 5, wherein, After the model binding result is stored in the preset storage database, the method further includes: User demand information is obtained; The user demand information is analyzed to obtain user demand labels; The user demand labels are matched with the model binding results in the preset storage database to generate a matching result; Based on the matching result, an existing model is selected to obtain a to-be-used security threat model.

7. An application security threat modeling analysis apparatus, comprising: The method includes: A modeling information determination module is configured to determine modeling selection information of a target user based on a modeling analysis instruction of the target user in response to the modeling analysis instruction; An analysis mode determination module is configured to determine a modeling analysis mode of the target user based on the modeling selection information; A demand information generation module is configured to collect modeling usage data based on the modeling analysis mode to generate modeling demand information; A key data analysis module is configured to perform key content analysis processing on the modeling demand information to obtain modeling key data; A page requirement acquisition module is configured to acquire model page requirements of the target user; A security model creation module is configured to create an application security threat model based on the model page requirements and the modeling key data; The analysis mode determination module is specifically configured to perform label identification on the modeling selection information to determine a modeling analysis label; A label processing scheme corresponding to the modeling analysis label and a user identity of the target user are acquired; It is determined whether the modeling analysis label is applicable to the target user based on the user identity; If the modeling analysis label is applicable to the target user, the modeling analysis label and the modeling selection information are identified by type based on the label processing scheme to obtain a label type; The modeling analysis mode of the target user is determined based on the modeling analysis label and the label type; If the modeling analysis label is not applicable to the target user, a recommended analysis label is generated based on a preset recommendation scheme and the user identity, and the recommended analysis label is sent to a client of the target user; Based on the confirmation information and the modeling analysis label, the modeling analysis mode of the target user is determined in response to confirmation information of the target user.

8. An electronic device, comprising: The electronic device includes a processor coupled with a memory; The processor is configured to execute a computer program stored in the memory, so that the electronic device performs the method of any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer program or instructions, when executed on a computer, cause the computer to perform the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Modeling method and device of network security threat model, equipment and medium

    CN115913732A

  • Business modeling guiding method and system, electronic equipment and storage medium

    CN119292683A