Threat Model Chaining for Enterprise Attack Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional threat modeling methodologies are inadequate for assessing organizational risk, as they focus on individual applications, require security experts, are resource-intensive, and cannot scale to meet the needs of enterprises with multiple software applications, nor can they effectively model application interactions, third-party elements, or communicate risks to non-experts.

Innovation Solution

The threat model chaining method involves storing and associating threat model components, threats, and compensating controls in a database, displaying them in a relational diagram, and allowing users to visualize attack paths and toggle compensating controls to mitigate threats, enabling a comprehensive threat modeling process that can be understood by non-security experts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional threat modeling methodologies are used to analyze individual applications, then security analysis can be performed, but the methodology cannot scale to meet the needs of enterprises with multiple software applications

Engineering Contradiction:
Improvethreat modeling analysis capabilityVSAvoidscalability to enterprise level
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the threat modeling process into reusable components including data flow diagrams, threat models, and compensating controls that can be independently developed and then assembled to analyze entire enterprise systems. This allows individual application analysis to be broken into modular units that scale across multiple applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal threat modeling components and templates that can be applied across different applications and enterprise contexts. These reusable elements enable the same methodology to serve both individual application analysis and enterprise-wide security assessment, achieving scalability without sacrificing analytical depth.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional threat modeling methodologies are used, then security analysis can be performed, but they require security subject-matter experts for creation, use, and maintenance

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidusability by non-experts
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automated threat model generation and analysis features that reduce dependence on security experts. The system can automatically create threat models from data flow diagrams, identify vulnerabilities, and suggest compensating controls, enabling non-experts to perform reliable security analysis with minimal expert intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces structured templates, standardized components, and guided workflows as intermediaries between security experts and non-expert users. These tools encapsulate expert knowledge in reusable formats that guide non-experts through the threat modeling process, maintaining analysis reliability while improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional threat modeling methodologies are used, then individual application vulnerabilities can be identified, but they cannot effectively model application interactions or third-party elements

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidcapability to model complex system interactions
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent employs nested threat models where individual application threat models are contained within broader enterprise-wide threat models. This hierarchical structure allows precise analysis of individual applications while simultaneously capturing interactions between applications and third-party elements, as each nested level contributes to the overall system understanding.

Inventive Principle:
Principle #7Nested doll (Nesting)

4Reliability

If traditional threat modeling methodologies are used, then security analysis can be performed, but they are resource-intensive to build and maintain

Engineering Contradiction:
Improvesecurity assessment qualityVSAvoidresources required
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent emphasizes creating threat models and compensating controls during the early stages of software development, before full implementation and deployment. This preliminary action allows security analysis to be performed when changes are easier and less costly, reducing the resources needed for later maintenance while maintaining high security assessment quality.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10200399B2Threat model chaining and attack simulation systems and methods
Publication Date: 2019.02.05 THREATMODELER SOFTWARE INC
  • US10200399B2 patent drawing
  • US10200399B2 patent drawing
  • US10200399B2 patent drawing

AI summary

Attack simulation systems include a computing device coupled with a database, the device displaying input interfaces configured to store a plurality of threat model components, threats, and compensating controls in the database, and associate each stored threat with at least one stored component and associate each stored control with at least one of the stored threats through the database. A diagram interface is configured to diagram a system, application, or process, the diagram including some of the stored components and controls, to define a first threat model, and is further configured to display attack paths of all stored threats associated with the diagrammed components which compromise a selected component. Attack simulation methods include defining threat models and displaying attack paths using system interfaces. Threat model chaining methods include adding a component group to a first threat model to include therein a second threat model associated with a predefined component group.