Threat Model Evaluation via Structural Validity and Completeness Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat modeling systems fail to evaluate the effectiveness of threat models prior to review by a security expert, lacking structural validity and completeness assessment.

Innovation Solution

A threat modeling application evaluates data flow diagrams to generate validity and completeness factors for each threat type, providing a progress indicator to users, enabling real-time structural validation and descriptive completeness feedback.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat models are manually reviewed by security experts, then the reliability of threat model evaluation is improved, but the productivity and time efficiency deteriorate

Engineering Contradiction:
Improvethreat model evaluation reliabilityVSAvoidthreat model review efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary automated evaluation of threat models before they reach security experts for manual review. The automated system assesses structural validity and descriptive completeness, filtering out obviously defective models and providing preliminary feedback, thereby preparing the threat models in advance and reducing the workload on security experts while maintaining evaluation reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An automated evaluation system acts as an intermediary between threat model creators and security experts. This intermediary performs initial assessments of structural validity and descriptive completeness, providing objective metrics and identifying obvious defects before human review, thus bridging the gap between rapid threat model creation and thorough expert review

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If comprehensive threat model evaluation is performed, then the manufacturing precision of threat model quality is improved, but the device complexity increases

Engineering Contradiction:
Improvethreat model quality assessment precisionVSAvoidevaluation system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The comprehensive evaluation system is segmented into two independent but complementary modules: structural validity assessment and descriptive completeness assessment. Each module focuses on specific evaluation criteria and can be independently implemented and maintained, reducing overall system complexity while achieving comprehensive evaluation precision through the combination of both modules

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated evaluation is implemented, then the productivity of threat model review is improved, but the measurement precision of threat model effectiveness deteriorates

Engineering Contradiction:
Improvethreat model review speedVSAvoidthreat model effectiveness assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The automated evaluation system implements feedback mechanisms that provide detailed results to both threat model creators and security experts. The system feeds back structural validity scores, descriptive completeness metrics, and specific defect identifications, enabling continuous improvement of threat model quality while maintaining high review throughput. This feedback loop compensates for the lack of human judgment in automated systems

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8732838B2Evaluating the effectiveness of a threat model
Publication Date: 2014.05.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8732838B2 patent drawing
  • US8732838B2 patent drawing
  • US8732838B2 patent drawing

AI summary

Evaluating a threat model for structural validity and descriptive completeness. A threat modeling application provides a progress factor or other overall score associated with the structural validity and descriptive completeness of the threat model being evaluated. The structural validity is evaluated based on a data flow diagram associated with the threat model. The descriptive completeness is evaluated by reviewing descriptions of threat types in the threat model. The progress factor encourages modelers to provide effective models to a model reviewer, thus saving time for the model reviewer.