Crowdsourced Threat Modeling via Knowledge Graph Ontology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional threat modeling systems are limited by their inability to share knowledge across application domains, leading to duplicative efforts, inconsistent quality, and a lack of aggregated views of risk concentration, which reduces the value of threat modeling as a risk discovery and management framework.

Innovation Solution

The implementation of a crowdsourced threat modeling system that utilizes a threat model knowledge graph to capture and represent user contributions semantically, enabling automated inference and integration of data across different domains through a standardized ontology, and providing automated recommendations for improving threat model quality and aggregation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional threat modeling systems are used with independent application domain teams, then each team can create threat models for their specific domain, but knowledge cannot be shared across domains leading to duplicative efforts and inconsistent quality

Engineering Contradiction:
Improvethreat model quality consistencyVSAvoidknowledge sharing across domains
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a universal knowledge graph data model that serves multiple application domains simultaneously. The standardized ontology and data structures enable the same threat modeling framework to be applied across different domains (financial services, healthcare, retail, etc.), allowing knowledge to be shared and reused universally while maintaining domain-specific relevance through configurable parameters and relationships.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a centralized threat modeling system with a knowledge graph as an intermediary between independent domain teams. This intermediary captures, stores, and manages threat modeling knowledge in a standardized format, enabling automatic sharing and reuse across domains while maintaining data consistency and quality through centralized control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If separate threat models are created for each application domain by domain-specific teams, then domain expertise is utilized, but significant time and cost are spent on duplicative activity due to absence of knowledge sharing

Engineering Contradiction:
Improvethreat model creation efficiencyVSAvoidduplicative effort time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining standardized ontologies, data models, and threat modeling frameworks in the knowledge graph before domain-specific applications are created. These pre-established structures enable domain teams to quickly populate and customize threat models without starting from scratch, significantly reducing duplicative effort and accelerating threat model creation across multiple domains.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables copying and reuse of threat modeling knowledge across domains through the standardized knowledge graph structure. Threat models, patterns, and insights captured in one domain can be copied, adapted, and applied to other domains by leveraging the universal data model and ontology, eliminating the need to recreate similar threat models independently in each domain.

Inventive Principle:
Principle #26Copying

3Loss of information

If conventional threat modeling systems are used, then individual threat models can be created, but aggregated views of risk concentration across domains cannot be provided reducing overall value

Engineering Contradiction:
Improveaggregated risk viewVSAvoidsystem integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges individual domain-specific threat models into a unified aggregated view through the knowledge graph. By combining multiple threat models using the standardized ontology and relationships, the system automatically generates consolidated risk assessments that show risk concentration patterns across domains, enabling organization-wide risk visibility without requiring complex manual integration processes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11956269B2Methods and systems for integrating crowd sourced threat modeling contributions into threat modeling systems
Publication Date: 2024.04.09 CAPITAL ONE SERVICES LLC
  • US11956269B2 patent drawing
  • US11956269B2 patent drawing
  • US11956269B2 patent drawing

AI summary

The methods and systems relate to improvements to threat modeling systems through the use of crowdsourcing. Specifically, the methods and systems relate to generating recommendations based on crowdsourced threat modeling contributions. For example, the methods and systems automate the threat modeling process by leveraging data in order to drive consistent and measurable quality of threat models and enable threat models to provide aggregated views of risk concentration at any altitude.