Query-Based Threat Graphs for Secure Software Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security development lifecycle (SDL) approaches are overly dependent on the expertise of security SMEs, lack understanding of threat interconnections, struggle with heterogeneous threat data ingestion, and fail to create a comprehensive threat picture due to disparate data sources and formats, leading to non-optimal security control selection and increased costs.

Innovation Solution

A system that ingests heterogeneous threat data from various sources, generates graph-based visualizations to map relationships between datasets, and allows for query-based interactive analytics to identify and implement optimized security controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple heterogeneous threat data sources are ingested to create a comprehensive threat picture, then the completeness and accuracy of threat analysis is improved, but the complexity of data integration and processing increases significantly

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoiddata integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer (unified data model and graph database schema) that mediates between heterogeneous threat data sources and the analysis system. This intermediary standardizes diverse data formats into a common structure, enabling accurate threat analysis without directly handling the complexity of each individual data source format

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The unified data model serves multiple functions simultaneously: it ingests data from various sources (STIX, CVE, CWE, CAPEC, ATT&CK), stores heterogeneous information in a standardized format, enables correlation analysis across different threat intelligence domains, and provides a foundation for security control recommendations. This multi-functional approach reduces overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of time

If security control selection is made based on limited understanding of threat spectrum, then the decision-making speed is improved, but the reliability and suitability of selected controls deteriorates

Engineering Contradiction:
Improvedecision-making timeVSAvoidcontrol selection reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-ingesting and organizing comprehensive threat intelligence data from multiple sources into a unified model before security control selection is needed. This pre-processing creates a ready-to-query knowledge base that enables fast, reliable decisions without requiring deep expert analysis at the moment of selection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graph-based visualization system provides feedback by displaying the relationships and correlations between threats, vulnerabilities, and security controls. This visual feedback helps users understand the threat spectrum and verify the suitability of selected controls, improving reliability while maintaining reasonable decision speed

Inventive Principle:
Principle #23Feedback

3Reliability

If expert knowledge is required for selecting appropriate security controls, then the quality of security decisions is improved, but the productivity and agility of security implementation decreases

Engineering Contradiction:
Improvesecurity decision qualityVSAvoidsecurity implementation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service by providing automated security control recommendations based on the unified threat intelligence model. Users can query the system and receive guidance on appropriate controls without requiring deep security expertise, thereby maintaining decision quality while improving implementation speed and productivity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The unified data model and visualization system act as an intermediary that translates complex threat intelligence into actionable security recommendations. This intermediary bridges the gap between expert-level threat analysis and user-level security control selection, enabling non-experts to make high-quality decisions efficiently

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If comprehensive threat intelligence from multiple sources is collected, then the completeness of threat picture is improved, but the difficulty of data correlation and relationship mapping increases

Engineering Contradiction:
Improvethreat information completenessVSAvoiddata correlation difficulty
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges multiple heterogeneous threat data sources (STIX, CVE, CWE, CAPEC, ATT&CK) into a unified graph-based data model. This combining approach preserves the completeness of information from all sources while simplifying correlation by representing relationships in a standardized graph structure where nodes and edges explicitly define connections between different threat elements

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12393693B2System for query-based interactive risk model analysis for secure software development
Publication Date: 2025.08.19 EMC IP HLDG CO LLC
  • US12393693B2 patent drawing
  • US12393693B2 patent drawing
  • US12393693B2 patent drawing

AI summary

One example method includes receiving a user query that relates to a potential vulnerability of a product, and the product includes hardware and/or software, based on information in the user query, ingesting multiple different datasets from different respective data sources, using data in the datasets to generate a respective graph model corresponding to each dataset, identifying relationships among the datasets, and building, and presenting to a user, a visualization that graphically displays each graph model, and indicates relationships between the datasets, and relationships between the data sources.