AI Cybersecurity Threat Modeling System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat modeling software is time-consuming, prone to errors, and expensive, making it difficult to recognize emerging threats or newly provisioned equipment in complex computer systems, leading to delayed detection of security breaches.

Innovation Solution

A cybersecurity computing system utilizing artificial intelligence models to classify system elements and threats, perform risk analysis, and generate security recommendations, including a system classifier, threat classifier, and threat analyzer, along with a data flow diagram editor and graphical user interface for user input and feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual threat modeling software is used to model data flows between computer system elements, then security risk analysis can be performed, but the process becomes time-consuming, expensive, and error-prone

Engineering Contradiction:
Improvesecurity risk analysis accuracyVSAvoidthreat modeling process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical threat modeling processes with an automated AI-based system. The AI model automatically generates data flow diagrams, identifies security risks, and produces threat models without requiring manual intervention in the tedious modeling steps, thereby reducing time loss while maintaining or improving analysis accuracy through consistent automated application of security frameworks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service threat modeling by automatically processing system architecture descriptions and generating complete threat models. The AI model autonomously performs data flow analysis, identifies security controls, and produces risk assessments without requiring security experts to manually execute each modeling step, significantly reducing the time investment required while maintaining professional-grade analysis quality.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive threat modeling is performed on complex computer systems, then security risks can be identified, but the complexity of the process increases and may miss emerging threats

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidthreat modeling process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AI-based threat modeling system provides universal applicability across diverse computer system architectures and complexity levels. The same automated model handles everything from simple to complex systems uniformly, applying consistent security analysis frameworks without requiring different manual processes for different system types, thereby reducing process complexity while maintaining comprehensive threat detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary automated analysis of system architectures before detailed manual review is needed. By pre-identifying data flows, potential security risks, and control gaps through AI analysis, the system prepares comprehensive threat models in advance, reducing the complexity of subsequent detailed analysis while ensuring no emerging threats are missed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional threat modeling approaches are used, then known security risks can be identified, but emerging threats or newly provisioned equipment may not be recognized until after a breach occurs

Engineering Contradiction:
Improvesecurity breach detectionVSAvoidbreach detection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AI threat modeling system performs preliminary identification of security risks and vulnerabilities before breaches can occur. By automatically analyzing system architectures and identifying potential attack vectors, control weaknesses, and emerging threats in advance, the system enables proactive security improvements rather than reactive responses after breaches, significantly reducing breach detection and response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that continuously update threat models based on new security information, emerging threats, and system changes. This feedback loop ensures that the automated modeling process remains current with the latest security risks and can identify emerging threats as they appear in the threat landscape, improving breach detection reliability while maintaining efficient automated operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11979425B2Cybersecurity threat modeling and analysis
Publication Date: 2024.05.07 THE BOEING CO
  • US11979425B2 patent drawing
  • US11979425B2 patent drawing
  • US11979425B2 patent drawing

AI summary

A computing system is provided that implements a system classifier including a first artificial intelligence model configured to classify each of a plurality of elements a computer system into one or more defined security categories, and a threat classifier including a second artificial intelligence model configured to classify each of a plurality of identified cybersecurity threats into the one or more defined security categories. The computing system further includes a threat analyzer configured to perform an analysis of a risk posed by each cybersecurity threat to each element of the target computer system based at least on the security categories of the classified cybersecurity threats and the security categories of classified elements of the target computer system, and output a security recommendation based on the analysis.