Threat Model Chaining for Enterprise Attack Surface Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional threat modeling methodologies are inadequate for assessing organizational risk, as they focus on individual applications, require security experts, are resource-intensive, and cannot scale to meet the needs of enterprises with multiple software applications, nor can they effectively model application interactions, third-party elements, or communicate risks to non-security experts.

Innovation Solution

The development of threat model chaining and attack simulation systems that utilize databases to store threat model components, threats, and compensating controls, with interfaces for visual representation and user interaction to analyze and mitigate threats across multiple components, allowing for the simulation of attack paths and the effectiveness of compensating controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional threat modeling methodologies are used to analyze individual applications, then security analysis can be performed, but the system cannot scale to meet the needs of enterprises with multiple software applications and cannot model application interactions

Engineering Contradiction:
Improveability to model application interactions and scale to enterprisesVSAvoidcomplexity of threat modeling system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the organization's software portfolio into individual application threat models, each analyzing a single application. These segmented models are then chained together using relationships (calls, shared components, data flow) to create a comprehensive organizational threat model, enabling scalability while maintaining manageable individual units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Individual application threat models are nested within a parent organizational threat model. Each application model contains its own threats, assets, and controls, while the organizational model aggregates these and adds inter-application relationships, creating a hierarchical structure that scales from simple to complex

Inventive Principle:
Principle #7Nested doll (Nesting)

2Measurement precision

If traditional threat modeling requires security subject-matter experts for creation and maintenance, then accurate security analysis can be achieved, but the process becomes resource-intensive and difficult to scale

Engineering Contradiction:
Improveaccuracy of security analysisVSAvoidefficiency of threat modeling process
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables automated threat model generation by ingesting application code, configuration files, and infrastructure descriptions. The automated engine identifies threats, assets, and controls without requiring manual security expert intervention for every model, significantly improving productivity while maintaining accuracy through validation rules

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where automated threat models are validated against security best practices and organizational policies. Security experts review and refine the automated outputs, and their corrections feed back into improving the automation engine's accuracy over time

Inventive Principle:
Principle #23Feedback

3Measurement precision

If traditional threat modeling focuses on individual applications in isolation, then detailed application-level security can be analyzed, but application-application interactions and organizational risk are miscalculated

Engineering Contradiction:
Improveaccuracy of organizational risk assessmentVSAvoidcomplexity of modeling multiple applications
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges individual application threat models by establishing relationships between them through calls, shared components, and data flow. This combining process aggregates threats across applications and identifies organizational-level risks that emerge from interactions, providing accurate organizational risk assessment

Inventive Principle:
Principle #5Merging (Combining)

4Loss of information

If traditional threat modeling methodologies are used, then security threats can be identified, but risks cannot be effectively communicated to non-security experts

Engineering Contradiction:
Improvecommunication of risk informationVSAvoidusability for non-security experts
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system creates visual representations and simplified risk reports that copy the essential security findings into formats understandable by non-security stakeholders. These include executive summaries, visual risk maps, and business-impact-focused reports that translate technical security concepts into business language

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10699008B2Threat model chaining and attack simulation systems and related methods
Publication Date: 2020.06.30 THREATMODELER SOFTWARE INC
  • US10699008B2 patent drawing
  • US10699008B2 patent drawing
  • US10699008B2 patent drawing

AI summary

Threat model chaining methods include providing one or more databases including a threat model components, threats, each threat associated with at least one of the threat model components, and compensating controls, each compensating control associate with one of the threats, providing a diagram interface configured to display a relational diagram defining a first threat model, and configuring the diagram interface to add a component group to the first threat model include in it a second threat model. Attack simulation methods include providing the one or more databases and diagram interface and configuring the diagram interface to visually display attack paths of threats associated with diagrammed threat model components which compromise a selected threat model component. Attack simulation systems include one or more computing devices coupled with one or more databases configured to store and interrelate threats, threat model components, and compensating controls, and allow diagramming and defining of threat models.