Automated Threat Model Generation for Computing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat modeling processes are manual, time-consuming, error-prone, and fail to provide an accurate, holistic view of security threats in computing systems, leading to vulnerabilities and gaps in threat mitigation as systems evolve.

Innovation Solution

A computer-implemented method and system that automatically generates a threat model by analyzing artifacts of a computing system using designated analysis tools, identifying threat model elements, and consolidating them to provide a holistic representation of system security, including components, actors, data flows, boundaries, dependencies, and roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual threat modeling is performed, then security analysis can be conducted, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvesecurity analysis qualityVSAvoidthreat modeling time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual threat modeling processes with an automated computer-implemented system that uses processors to execute instructions for analyzing computing system artifacts. The system automatically generates threat models by processing artifacts through multiple analysis tools, eliminating the need for manual diagramming and analysis while maintaining comprehensive security coverage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically selecting and executing appropriate analysis tools based on artifact types, generating threat models without human intervention. The automated process includes selecting analysis tools, processing artifacts, consolidating results, and generating comprehensive threat models independently.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual threat modeling is performed, then security threats can be identified, but the process is error-prone and lacks consistency

Engineering Contradiction:
Improvethreat identification accuracyVSAvoidmodeling process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual threat modeling with an automated system that consistently applies the same analysis procedures. The computer-implemented process uses standardized instructions and analysis tools to process artifacts, eliminating human error and ensuring consistent, reproducible threat model generation across different systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive threat modeling is performed to provide holistic view, then security coverage is improved, but the complexity of the process increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidthreat modeling process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the threat modeling process into distinct phases: obtaining artifacts, determining artifact types, selecting analysis tools, processing artifacts, consolidating results, and generating threat models. Each phase handles specific tasks independently, making the overall complex process manageable and systematic while achieving comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses a universal approach where multiple analysis tools can process different artifact types through a common framework. The same threat modeling process handles various artifacts (source code, configuration files, documentation) using appropriate specialized tools selected automatically, providing holistic coverage without increasing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If automated analysis tools are used to process artifacts, then productivity is improved, but the system complexity increases

Engineering Contradiction:
Improvethreat modeling efficiencyVSAvoidanalysis system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer that manages the complexity between the user and multiple analysis tools. The system automatically selects appropriate tools based on artifact types and coordinates their execution, shielding users from tool complexity while maintaining high productivity through automated processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240354408A1Automated threat model generation
Publication Date: 2024.10.24 MOONEY III ROBERT J
  • US20240354408A1 patent drawing
  • US20240354408A1 patent drawing
  • US20240354408A1 patent drawing

AI summary

Embodiments of the present invention include computer-implemented methods, systems, and computer program products where program code executing on a processor(s) obtains an artifact of a given computing system. The program code determines a type for the artifact. The program code designates a given analysis tool from a plurality of analysis tools, to process the artifact. The program code processes the artifact by utilizing the given analysis tool, to determine facts of the artifact. The program code determines which facts of the one or more facts comprise elements of a threat model. The program code stores the elements of the threat model and the facts. The program code generates a threat model for the given computing system, based on consolidating the elements of the threat model for the artifact with additional elements of the threat models of additional artifacts.