Automated Threat Model Generation for Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security reviews for software applications and services are largely manual, labor-intensive, and rely on accurate developer input, making them time-consuming and prone to errors in identifying potential threats and mitigations.

Innovation Solution

An automated system generates a machine-readable threat model using a template associated with an application or service, leveraging ontological statements and Description Logic to identify components, relationships, and potential threats, and providing a graphical representation for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security review methods are used, then security analysis can be performed with simple tools, but the process becomes labor-intensive and time-consuming

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidsecurity review duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical security review processes with an automated computer-based system that uses natural language processing, graph generation, and machine learning algorithms to perform security threat identification and analysis automatically, eliminating the need for manual labor while maintaining or improving accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary automated processing layer between the security review request and the final analysis results. This intermediary system uses natural language processing to extract entities and relationships, generates graph representations, and applies security rules to produce comprehensive threat assessments, thereby reducing both time and manual effort

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated threat modeling is implemented, then productivity and efficiency are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity review throughputVSAvoidautomated system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the automated security review system into distinct modular components: natural language processing module for entity extraction, graph generation module for relationship modeling, threat identification module for vulnerability detection, and report generation module for results presentation. This segmentation enables independent development, testing, and maintenance of each component while achieving high overall productivity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal automated security review platform that can handle multiple types of security analyses, different input formats, various threat models, and diverse output requirements through a single integrated system, thereby improving productivity across multiple security review scenarios without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive threat analysis is performed, then security coverage is improved, but the amount of data processing and potential errors increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata processing accuracy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the automated system continuously validates extracted entities and relationships against the generated graph structure, cross-checks threat identifications against security rules and policies, and iteratively refines analysis results. This feedback loop ensures comprehensive security coverage while maintaining data processing accuracy through automated validation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary data validation, entity verification, and relationship verification before conducting the main threat analysis. By pre-processing and validating input data, the system ensures that comprehensive threat analysis is performed on accurate, verified information, thereby improving both security coverage and data processing accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11128653B1Automatically generating a machine-readable threat model using a template associated with an application or service
Publication Date: 2021.09.21 AMAZON TECH INC
  • US11128653B1 patent drawing
  • US11128653B1 patent drawing
  • US11128653B1 patent drawing

AI summary

In some embodiments, a system is provided, and computer-executable instructions cause the system to: obtain a file with instructions for provisioning resources of a service by referencing types of compute resources and including instructions for generating a customized resource of a first type; determine that the file references a first type of compute resources; retrieve threat modeling information associated with the first type of resource, including information identifying a first potential threat; generate a graph with nodes representing the first type of resource, the customized resource, and the first potential threat, and an edge connecting the first node and the second node with a predicate indicative of the relationship them; generate an ontology statement that relate the customized resource and first type of resource; and provide a plurality of ontology statements representing the graph to a reasoner to perform at least a portion of a security review without user intervention.