SYSTEM FOR GENERATING A RISK ASSESSMENT REPORT
A computer system automates threat analysis and risk assessment using a trained algorithm, addressing the inefficiencies of manual methods by reducing execution time and maintaining accuracy.
Patent Information
- Application Number
- DE102025119720
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-21
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The process of threat analysis and risk assessment in cybersecureness is time-consuming and error-prone, typically requiring weeks to complete and relying heavily on human effort.
A computer system utilizing a trained algorithm to automate threat analysis and risk assessment, incorporating modular architecture and standardized interfaces for real-time data input, enabling dynamic risk analysis and automated generation of risk assessment reports.
Significantly reduces the time required for threat analysis and risk assessment while ensuring accuracy through human verification and validation.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method and a computer system for generating a risk assessment report for a technical system.
[0002] Threat Analysis and Risk Assessment (TARA) is a fundamental task in the cybersecurity development lifecycle according to ISO 21434. It is divided into several steps, typically performed by human cybersecurity engineers. This task is therefore time-consuming and error-prone. Depending on the complexity of the system being analyzed, it can take weeks to complete.
[0003] The inventive computer system for generating a risk assessment report for a technical system comprises a generation device for generating the risk assessment report based on data from a subject definition of the technical system using a trained algorithm. The computer system allows these steps to be automated, reducing the time required to perform the threat analysis and risk assessment. Subsequent human interaction remains important to ensure correct inputs for the TARA and to verify the results provided by the algorithm.
[0004] In an advantageous embodiment of the computer system, the system has a modular architecture that allows different sub-steps of the TARA to be executed independently of one another and, if necessary, exchanged. This allows individual modules, such as those for asset identification, determining damage scenarios and impact assessments, or generating attack paths, to be developed, validated, and updated separately without revalidating the entire system. Furthermore, this embodiment provides a standardized interface via which real-time data from a test system (e.g., ECU data) can be imported to create dynamically updated risk analyses based on current telemetry or sensor information.
[0005] In a further advantageous embodiment of the computer system, the computer system comprises an interface via which an object definition with system interfaces, functional descriptions and process flow diagrams is received, so that an automated extraction of structured assets is enabled.
[0006] In a further advantageous embodiment of the computer system, the computer system comprises a module for the dynamic derivation of TARA instructions, which independently generates step-by-step instructions from the object definition in order to carry out asset identification, damage scenario calculation and threat generation in real time.
[0007] In a further advantageous embodiment of the computer system, the computer system comprises a threat engine module that stores a database with predefined regulatory threat models, STRIDE categories and asset-specific attack scenarios and uses them to generate threat scenarios.
[0008] In a further advantageous embodiment of the computer system, the computer system comprises a module for calculating damage scenarios and impact ratings based on multidimensional key figures, in particular for safety, finance, operations and / or data protection, which enables an automatic assessment of the impacts of each individual asset.
[0009] In a further advantageous embodiment of the computer system, the computer system comprises an attack path generation module that derives sequential attack sequences for each threat scenario and stores them in the form of a list, wherein the derivation is based on system-internal interfaces and vulnerability profiles.
[0010] In a further advantageous embodiment of the computer system, the computer system comprises an attack feasibility rating module which, for each attack path, determines the factors of time required, attacker skill, knowledge of the target, window of opportunity and required equipment and calculates therefrom a numerical value which is assigned to a qualitative scale (e.g., very low, low, medium, high).
[0011] In a further advantageous embodiment of the computer system, the computer system comprises an output interface that transmits the generated risk assessment report in structured form to downstream systems for further processing, visualization or document storage.
[0012] In a further advantageous embodiment of the computer system, the computer system comprises a storage system that stores all input and output data of the individual TARA steps, such as in particular assets, damage scenarios, threat scenarios, attack paths and / or feasibility assessments, in an audit-proof manner in order to ensure traceability and reproducibility of the risk assessment.
[0013] The inventive method for generating a risk assessment report for a technical system comprises the step of generating the risk assessment report based on data from an object definition of the technical system using a trained algorithm. The method also enables a significant reduction in execution time for the threat analysis and risk assessment compared to conventional methods.
[0014] Embodiments of the invention are explained in more detail with reference to the following figures. Fig. 1 a schematic representation of an object definition; Fig. 2 a schematic representation of an assessment of the damage scenario and an impact; Fig. 3 a schematic representation of an identification of a threat scenario; Fig. 4 a schematic representation of an attack path; and Fig. 5 a schematic representation of an assessment of the attack possibilities.
[0015] Fig. 1 shows a schematic representation of an asset definition (asset identification). A user 100 first provides a list of all relevant system processes by executing the "Provide Asset Processes" activity 101. The same user then provides detailed information on function-related elements, interfaces, and system boundaries using the "Provide Asset Definition" activity 103. The computer system 600 receives these inputs and, in its TARACoPilot module, first executes the "Evaluate Asset Processes" activity 107. Based on this, the "Analyze Asset Definition" activity 109 follows, in which the transferred data is structured and classified. Finally, the computer system generates a structured asset list based on this analysis and returns it to the user via the "Output Asset List" activity 11).The user completes the process by performing the “Evaluate Output” 105 activity, in which he verifies the automatically generated asset list and corrects it if necessary.
[0016] Fig. Figure 2 shows a schematic representation of a damage scenario and impact rating. A user 100, 201 begins by first "providing damage scenarios and processes for impact assessment" 201. They then provide further information on the assets already identified by "providing asset definition" 203. They then make the asset list created in the previous step available to the computer system in the activity "providing list of identified assets" 205. The computer system 600 receives this data and starts the activity "evaluate asset processes" 209 in the TARACoPilot module to examine the interaction of the assets and extract relevant dependencies. In the following activity "analyze asset definition" 211, detailed classifications of the assets and their properties are performed.Based on this, the system performs the "Evaluate List of Identified Assets" activity 213 to review the previously submitted list for potential damage scenarios. Finally, in the "Create Damage Scenarios and Impact Assessment" activity 215, the computer module generates one or more damage scenarios for each identified asset and calculates ratings for the dimensions of security, finance, operations, and data protection. The generated damage scenarios and impact assessments are presented to the user via the "Evaluate Output" activity 207, allowing them to validate and adjust the results.
[0017] Fig. Figure 3 shows a schematic representation of a threat scenario identification (Threat Scenario Identification). A user 100, 301 starts with the activity "Provide Processes for Threat Scenarios" 301, in which they describe predefined or suspected attack processes. They then provide the relevant system data again in "Provide Subject Definition" 305 to fully cover the context. In parallel, the user provides a collection of reference data from a threat database (e.g., STRIDE categories, regulatory requirements) via the activity "Provide Threat Database" 303. In the activity "Provide List of Identified Assets" 307, they provide the system with the information generated in the process of Fig. 1 created asset list. The computer system 600 begins in the TARACoPilot module with the activity "Analyze Threat Scenario Processes" 311, in which it interprets the provided processes and applies them to the system architecture of the asset. Based on these analyses, the activity "Analyze Asset Definition" 315 is performed to further refine the context information. In parallel, the system performs the activity "Analyze Threat Database" 313 to extract available threat profiles and sample values. Subsequently, the activity "Analyze List of Identified Assets" 317 checks which assets are particularly critical with regard to the threat data. Based on this, the activity "Create List of Threat Scenarios" 319 generates one or more threat scenarios for each relevant asset, which are then presented to the user for validation in the activity "Evaluate Output" 309.
[0018] Fig. Figure 4 shows a schematic representation of an attack path. A user 100, 401 begins with the activity "Provide Process Attack Paths" 401, in which they outline already known or suspected attack paths. They then transfer the system boundaries and interfaces relevant for attack modeling via "Provide Subject Definition" 403. Subsequently, in "Provide Identified Threat Scenarios" 405, the user provides the threat scenarios identified in the previous step ( Fig. 3) have been validated. The computer system 600 starts in the TARACoPilot module with the "Analyze Attack Path Processes" activity 409, where it structures and examines the optionally provided attack processes. This is followed by the "Analyze Object Definition" activity 411, in which the system components of the object are classified in detail along the possible path. Subsequently, in the "Analyze List of Identified Threat Scenarios" activity 413, the threat scenarios are compared with the researched system components in order to derive feasible paths. Based on this information, the system generates one or more sequential attack chains for each threat scenario in the "Generate Attack Path List" activity 415, which are then presented to the user in the "Evaluate Output" activity 407.
[0019] Fig. Figure 5 shows a schematic representation of an attack feasibility rating. A user 100, 501 initiates the step "Provide Feasibility Assessment Processes" 501, in which they define rules and parameters (such as time expenditure, expertise, tools) for the feasibility of attack paths. Subsequently, in the activity "Provide Subject Definition" 503, they again provide all relevant system information to complete the context for the feasibility assessment. The user then provides the list of the identified attack paths in "Provide Identified Attack Paths" 505. Fig.4 generated attack paths are available. The computer system 600 begins in the TARACoPilot module with the activity "Analyze Feasibility Assessment Processes" 509, in which it evaluates the structured rules and parameters from the user specifications. Subsequently, the resources and knowledge required for the attacks are examined in detail in the activity "Analyze Object Definition" 511. Building on this, the system executes the activity "Analyze List of Identified Attack Paths" 513, in which each attack path is evaluated according to the attack potential method (factors: required time, expertise, knowledge of the target, window of opportunity, equipment). Finally, in the activity "Generate List of Attack Possibilities" 515, the computer system generates a qualitative rating (e.g., very low, low, medium, high) for each attack path, which is provided to the user via "Evaluate Output" 507.
[0020] All features explained and shown in connection with individual embodiments of the invention can be provided in different combinations in the subject matter according to the invention in order to simultaneously realize their advantageous effects.
[0021] All method steps can be implemented by devices suitable for performing the respective method step. All functions performed by physical features can be a method step of a method.
Claims
[1] A computer system for generating a risk assessment report for a technical system, comprising: - a generating device for generating the risk assessment report based on data of an object definition of the technical system by a trained algorithm. [2] The computer system of claim 1, wherein the computer system comprises an interface for receiving an object definition including system interfaces, functional descriptions, and process flow diagrams to enable automated extraction of structured assets. [3] A computer system according to claim 1 or 2, wherein the computer system comprises a module for dynamically deriving TARA instructions that autonomously generates step-by-step instructions from the object definition to perform asset identification, damage scenario calculation and threat generation in real time. [4] A computer system according to any one of the preceding claims, wherein the computer system comprises a threat engine module that stores a database of predefined regulatory threat models, STRIDE categories and asset-specific attack scenarios and uses them to generate threat scenarios. [5] Computer system according to one of the preceding claims, wherein the computer system comprises a module for calculating damage scenarios and impact ratings based on multidimensional key figures, in particular for security, finance, operations and / or data protection, thereby enabling an automatic assessment of the impacts of each individual asset. [6] A computer system according to any one of the preceding claims, wherein the computer system comprises an attack path generation module that derives sequential attack sequences for each threat scenario and stores them in the form of a list, the derivation being based on system-internal interfaces and vulnerability profiles. [7] A computer system according to any one of the preceding claims, wherein the computer system comprises an attack feasibility rating module which determines, for each attack path, the factors of time required, attacker skill, knowledge of the target, window of opportunity and required equipment and calculates therefrom a numerical value which is assigned to a qualitative scale. [8] Computer system according to one of the preceding claims, wherein the computer system comprises an output interface which transmits the generated risk assessment report in structured form to downstream systems for further processing, visualization or document storage. [9] Computer system according to one of the preceding claims, wherein the computer system comprises a storage system which stores all input and output data of the individual TARA steps, such as in particular assets, damage scenarios, threat scenarios, attack paths and / or feasibility assessments, in an audit-proof manner in order to ensure traceability and reproducibility of the risk assessment. [10] A method for generating a risk assessment report for a technical system, comprising the step of: - Generation of the risk assessment report based on data of an object definition of the technical system by a trained algorithm.
Citation Information
Patent Citations
Digital platform for the automated assessment and evaluation of construction and assembly risks and related procedures.
CH717964A2
SYSTEMS AND METHODS FOR ANALYSING PARTIAL ATTACK PATHWAYS
DE102024119046A1
TECHNIQUES FOR DETERMINING CORRECTNESS AND / OR GENERATING AN ASSESSMENT OF THE RISK OF CYBER ATTACKS ON A SYSTEM
DE102024205232A1
Adaptive system for network and security management
WO2023235408A1
Data security grouping and ranking
WO2025058795A1