Runtime Threat Modeling Using Node Data and Threat Reports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat modeling methods are inadequate for identifying security threats in computing systems due to lack of competency, time, and effort, design changes, and failure to consider runtime aspects such as user context and encryption parameters, especially for legacy features.

Innovation Solution

An automated threat modeling system that performs threat modeling during the unit testing phase using actual system inputs, generating node information, comparing it with a threat database, and providing threat reports and remediation strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual threat modeling methods are used, then security assessment can be performed, but the process lacks competency, time, and effort efficiency

Engineering Contradiction:
Improvethreat modeling efficiencyVSAvoidthreat identification accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system enables automated threat modeling that performs self-assessment of security threats without requiring extensive manual intervention. The automated threat modeler independently executes threat identification by comparing node information against a threat database, thereby improving productivity while maintaining reliability through systematic automated analysis

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical threat modeling processes with an automated computational system. The automated threat modeler substitutes human analysts by systematically comparing node information with threat database entries, achieving both higher productivity and consistent reliability through algorithmic threat identification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If traditional threat modeling is performed during design phase, then initial security assessment is provided, but runtime aspects such as user context and encryption parameters are not considered

Engineering Contradiction:
Improveruntime context considerationVSAvoidthreat modeling timing
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs threat modeling dynamically at runtime rather than statically during design phase. The automated threat modeler continuously monitors and assesses threats based on actual runtime conditions, user context, and encryption parameters, making the security assessment adaptable to changing system states while eliminating time loss through concurrent execution

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary threat identification by comparing node information against a pre-populated threat database before threats can be exploited. This preliminary action occurs during runtime to capture actual system behavior, providing both adaptability to runtime context and timely threat detection without significant time loss

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive threat modeling is performed, then detailed threat identification is achieved, but the process becomes complex and resource-intensive

Engineering Contradiction:
Improvethreat assessment detailVSAvoidthreat modeling system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The threat modeling process is segmented into distinct modular components: node information generation, threat database comparison, and threat report generation. The automated threat modeler processes threats by comparing specific node attributes against categorized threat types, achieving detailed threat assessment while reducing overall system complexity through functional segmentation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different levels of analysis to different aspects of threat modeling. The automated threat modeler focuses computational resources on comparing critical node information (such as encryption parameters and user context) against relevant threat database entries, achieving measurement precision in threat detection while minimizing device complexity by avoiding unnecessary comprehensive analysis of all system attributes

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12566848B2Automated threat modeling
Publication Date: 2026.03.03 DELL PROD LP
  • US12566848B2 patent drawing
  • US12566848B2 patent drawing
  • US12566848B2 patent drawing

AI summary

Techniques described herein relate to a method for performing threat modeling. The method includes obtaining a threat modeling request associated with a process executing on a node of a cluster; in response to the obtaining: generating node information associated with the process; generating a data flow diagram associated with the process using the node information; comparing the node information with a threat database to predict at least one threat associated with the process; generating a threat report based on the at least one threat; providing the threat report and data flow diagram to a user associated with the process; and initiating performance of threat mitigation based on the threat report and the data flow diagram.